================
@@ -3351,6 +3351,62 @@ remove the const qualifier from the original declaration
or use a mutable copy.
alpha.cplusplus
^^^^^^^^^^^^^^^
+.. _alpha-cplusplus-DanglingPtrDeref:
+
+alpha.cplusplus.DanglingPtrDeref (C++)
+""""""""""""""""""""""""""""""""""""""
+Check for dereferences of pointers that refer to an object whose
+lifetime has already ended. Such a pointer is dangling. The checker
+reports it when it is dereferenced and when it is passed to a function.
+
+Each object is reported at most once on an execution path. If the same dangling
+pointer is used several times then only the first use is reported.
+
+.. code-block:: cpp
+
+ void test_deref() {
+ int *ptr = 0;
+ {
+ int num = 5;
+ ptr = #
+ } // note: 'num' is destroyed here
+ *ptr = 6; // warn: use of 'num' after its lifetime ended
+ }
+
+ void test_in_scope() {
+ int num = 5;
+ int *ptr = #
+ {
+ *ptr = 6; // no warning, 'num' is still in scope
+ }
+ }
+
+End-of-lifetime information is not included in the CFG by default. Without it
+the checker does not report anything and no error is emitted by the analyzer.
+Use the ``-analyzer-config cfg-lifetime=true`` option to include it.
----------------
Xazax-hun wrote:
Does this mean this checker would not emit warnings without this option? I
think we do not need to mention the CFG, users might not know what that is. We
can just say this option is a prerequisite for this warning. That being said, I
think we should consider turning cfg lifetimes on by default! This is probably
a prerequisite to move this checker out of alpha.
https://github.com/llvm/llvm-project/pull/216688
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits