================
@@ -1897,7 +1897,33 @@ def CrossTURemarks : DiagGroup<"ctu-remarks">;
 
 def CTADMaybeUnsupported : DiagGroup<"ctad-maybe-unsupported">;
 
-def FortifySource : DiagGroup<"fortify-source", [FormatOverflow, 
FormatTruncation]>;
+def FortifySource : DiagGroup<"fortify-source", [FormatOverflow, 
FormatTruncation]> {
+  code Documentation = [{
+Warns at compile time when calls to standard C library or POSIX functions have
+provably out-of-bounds destination buffers or invalid constant arguments,
+modeled after `_FORTIFY_SOURCE` compile-time checks.
+
+This diagnostic group is enabled by default and checks:
+
+1. **Destination buffer overflows**: Diagnoses when a write operation will
+   always overflow the destination buffer, or when an explicit size argument
+   exceeds the known size of the destination buffer:
+   - `<string.h>` / `<strings.h>`: `memcpy`, `memmove`, `memset`, `mempcpy`,
+     `bcopy`, `bzero`, `strcpy`, `stpcpy`, `strcat`, `strncpy`, `stpncpy`,
+     `strncat`, `strlcpy`, `strlcat` (and their `__builtin_` variants).
+   - `<stdio.h>`: `sprintf`, `snprintf`, `vsnprintf`, `scanf`, `fscanf`,
+     `sscanf` (also controlled by `-Wformat-overflow` and
+     `-Wformat-truncation`).
----------------
venk-ks wrote:

Done—updated the warning flag references (`-Wformat-overflow`, 
`-Wformat-truncation`, `-Wbuiltin-memcpy-chk-size`, and `-Wstringop-overread`) 
to use MyST `` {ref}`...` `` links.

https://github.com/llvm/llvm-project/pull/224111
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits

Reply via email to