https://github.com/zwuis commented:
> I can imagine a checker extension that checks if the destination buffer is
> larger than limiter size specified in the format string.
> e.g.
> ```
> char buffer[10]
> scanf("%99s",buffer) //warn unsafe string
> ```
> So for now I would leave the checker name as is
> (bugprone-unsafe-format-string) to allow extensibility for other cases.
Makes sense to me.
New question, but not blocking this PR: IIUC we will not support another style
of format string (`std::format_to`). Is there a better check name? Something
like bugprone-unsafe-c-format-string?
https://github.com/llvm/llvm-project/pull/168691
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits