aaditya8979 wrote: @steakhal Thank you so much for taking the time to review this!
On InlinePolicy: PopulateInlinePolicy governs which CallEvents the ExprEngine will attempt to inline versus fall back to conservative evaluation. When a call is not inlined (e.g. due to exceeding MaxInlinableDepth or matching never-inline heuristics), the engine falls back to defaultEvalCall, which triggers invalidateRegions to conservatively wipe all accessible memory from the RegionStore. For self-recursive calls specifically, this means perfectly valid pointer arguments get their Direct bindings destroyed and replaced with Default derived symbols, causing false state bifurcations. On why ExprMutationAnalyzer over a linear scan: ExprMutationAnalyzer performs a full AST walk of the function body, correctly handling aliasing, assignments through references, and compound expressions. A naive linear scan of the parameter's DeclRefExpr usage would miss mutations through pointer arithmetic or nested sub-expressions. Using the existing, battle-tested ExprMutationAnalyzer gives us correctness guarantees without reimplementing mutation tracking logic. Happy to iterate on any of these points or provide additional test cases if you feel coverage is insufficient! https://github.com/llvm/llvm-project/pull/228234 _______________________________________________ cfe-commits mailing list [email protected] https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits
