https://github.com/venk-ks updated 
https://github.com/llvm/llvm-project/pull/224111

>From 5145a0390082283071641bd6571913c17f4cd55e Mon Sep 17 00:00:00 2001
From: Venkatesh Srinivasan <[email protected]>
Date: Wed, 16 Sep 2026 18:35:57 +0000
Subject: [PATCH 1/2] [Clang][Docs] Add documentation for -Wfortify-source

Document the -Wfortify-source diagnostic group in DiagnosticGroups.td covering 
all currently checked library functions.

Part of #142230

Assisted-by: Gemini
---
 clang/include/clang/Basic/DiagnosticGroups.td | 30 ++++++++++++++++++-
 1 file changed, 29 insertions(+), 1 deletion(-)

diff --git a/clang/include/clang/Basic/DiagnosticGroups.td 
b/clang/include/clang/Basic/DiagnosticGroups.td
index 1da7698944b24..5f53deead39c6 100644
--- a/clang/include/clang/Basic/DiagnosticGroups.td
+++ b/clang/include/clang/Basic/DiagnosticGroups.td
@@ -1897,7 +1897,35 @@ def CrossTURemarks : DiagGroup<"ctu-remarks">;
 
 def CTADMaybeUnsupported : DiagGroup<"ctad-maybe-unsupported">;
 
-def FortifySource : DiagGroup<"fortify-source", [FormatOverflow, 
FormatTruncation]>;
+def FortifySource : DiagGroup<"fortify-source", [FormatOverflow, 
FormatTruncation]> {
+  code Documentation = [{
+Warns at compile time when calls to standard C library or POSIX functions have
+provably out-of-bounds destination buffers or invalid constant arguments,
+modeled after 
[`_FORTIFY_SOURCE`](https://www.gnu.org/software/libc/manual/html_node/Source-Fortification.html)
+compile-time checks.
+
+This diagnostic group checks:
+
+1. **Destination buffer overflows and format truncation**: Diagnoses when a
+   write operation will always overflow the destination buffer, when an
+   explicit size argument exceeds the known size of the destination buffer, or
+   when formatted output will always be truncated:
+   - `<string.h>` / `<strings.h>`: `memcpy`, `memmove`, `memset`, `mempcpy`,
+     `bcopy`, `bzero`, `strcpy`, `stpcpy`, `strcat`, `strncpy`, `stpncpy`,
+     `strncat`, `strlcpy`, `strlcat` (and their `__builtin_` variants).
+   - `<stdio.h>`: `sprintf`, `snprintf`, `vsnprintf` (format overflow and
+     truncation also controlled by {ref}`-Wformat-overflow` and
+     {ref}`-Wformat-truncation`), and `scanf`, `fscanf`, `sscanf`.
+
+2. **Invalid constant arguments**:
+   - `<sys/stat.h>`: `umask` when called with constant mode bits outside `0777`
+     that are silently ignored.
+
+Note: Related bounds checks for most `__builtin___*_chk` functions and source 
buffer
+overreads in memory functions (such as `memcpy` and `memcmp`) are controlled
+separately by {ref}`-Wbuiltin-memcpy-chk-size` and {ref}`-Wstringop-overread`.
+  }];
+}
 
 def OverflowBehaviorAttributeIgnored
     : DiagGroup<"overflow-behavior-attribute-ignored">;

>From b6db8d0e23b535d4617d97229db0a738a468f262 Mon Sep 17 00:00:00 2001
From: Venkatesh Srinivasan <[email protected]>
Date: Fri, 25 Sep 2026 18:06:05 +0000
Subject: [PATCH 2/2] [Clang][Docs] Fix _FORTIFY_SOURCE manual link in
 DiagnosticGroups.td

---
 clang/include/clang/Basic/DiagnosticGroups.td | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/clang/include/clang/Basic/DiagnosticGroups.td 
b/clang/include/clang/Basic/DiagnosticGroups.td
index 5f53deead39c6..a21321f748cf4 100644
--- a/clang/include/clang/Basic/DiagnosticGroups.td
+++ b/clang/include/clang/Basic/DiagnosticGroups.td
@@ -1901,7 +1901,7 @@ def FortifySource : DiagGroup<"fortify-source", 
[FormatOverflow, FormatTruncatio
   code Documentation = [{
 Warns at compile time when calls to standard C library or POSIX functions have
 provably out-of-bounds destination buffers or invalid constant arguments,
-modeled after 
[`_FORTIFY_SOURCE`](https://www.gnu.org/software/libc/manual/html_node/Source-Fortification.html)
+modeled after 
[`_FORTIFY_SOURCE`](https://sourceware.org/glibc/manual/latest/html_node/Source-Fortification.html)
 compile-time checks.
 
 This diagnostic group checks:

_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits

Reply via email to