================
@@ -503,8 +503,8 @@ static const Expr *getSubExprInSizeOfExpr(const Expr &E) {
 // Providing that `Ptr` is a pointer and `Size` is an unsigned-integral
 // expression, returns true iff they follow one of the following safe
 // patterns:
-//  1. Ptr is `DRE.data()` and Size is `DRE.size()`, where DRE is a hardened
-//     container or view;
+//  1. Ptr is `DRE.data()` and Size is `DRE.size()` (or `DRE.size_bytes()` for
+//     char pointers), called on the same container or view object `DRE`;
----------------
pl98 wrote:

`[[clang::unsafe_buffer_usage("container")]]` is attached to the 
constructor/factory being called (e.g., `MakeSpan`), not to the container `DRE` 
on which `.data()` and `.size()` are called.

Because of that, restricting duck typing to 
`[[clang::unsafe_buffer_usage("container")]]` callees wouldn't prevent a 
project-local type `x` from matching `MakeSpan(x.data(), x.size())`. It would 
only cause `std::span(v.data(), v.size())` to still warn on non-std library 
containers `v` while `MakeSpan(v.data(), v.size())` does not. Keeping 
`std::span` and annotated constructors consistent here seems preferable, but 
please let me know what you think.

https://github.com/llvm/llvm-project/pull/227108
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits

Reply via email to