aaditya8979 wrote:

@steakhal  Thank you so much for taking the time to review this!

On InlinePolicy: PopulateInlinePolicy governs which CallEvents the ExprEngine 
will attempt to inline versus fall back to conservative evaluation. When a call 
is not inlined (e.g. due to exceeding MaxInlinableDepth or matching 
never-inline heuristics), the engine falls back to defaultEvalCall, which 
triggers invalidateRegions to conservatively wipe all accessible memory from 
the RegionStore. For self-recursive calls specifically, this means perfectly 
valid pointer arguments get their Direct bindings destroyed and replaced with 
Default derived symbols, causing false state bifurcations.

On why ExprMutationAnalyzer over a linear scan: ExprMutationAnalyzer performs a 
full AST walk of the function body, correctly handling aliasing, assignments 
through references, and compound expressions. A naive linear scan of the 
parameter's DeclRefExpr usage would miss mutations through pointer arithmetic 
or nested sub-expressions. Using the existing, battle-tested 
ExprMutationAnalyzer gives us correctness guarantees without reimplementing 
mutation tracking logic.

Happy to iterate on any of these points or provide additional test cases if you 
feel coverage is insufficient!

https://github.com/llvm/llvm-project/pull/228234
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits

Reply via email to