================
@@ -503,8 +503,8 @@ static const Expr *getSubExprInSizeOfExpr(const Expr &E) {
// Providing that `Ptr` is a pointer and `Size` is an unsigned-integral
// expression, returns true iff they follow one of the following safe
// patterns:
-// 1. Ptr is `DRE.data()` and Size is `DRE.size()`, where DRE is a hardened
-// container or view;
+// 1. Ptr is `DRE.data()` and Size is `DRE.size()` (or `DRE.size_bytes()` for
+// char pointers), called on the same container or view object `DRE`;
----------------
pl98 wrote:
`[[clang::unsafe_buffer_usage("container")]]` is attached to the
constructor/factory being called (e.g., `MakeSpan`), not to the container `DRE`
on which `.data()` and `.size()` are called.
Because of that, restricting duck typing to
`[[clang::unsafe_buffer_usage("container")]]` callees wouldn't prevent a
project-local type `x` from matching `MakeSpan(x.data(), x.size())`. It would
only cause `std::span(v.data(), v.size())` to still warn on non-std library
containers `v` while `MakeSpan(v.data(), v.size())` does not. Keeping
`std::span` and annotated constructors consistent here seems preferable, but
please let me know what you think.
https://github.com/llvm/llvm-project/pull/227108
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits