Fix #15006: FP invalidFree with new array - #8880
ludviggunne wants to merge 4 commits into
Conversation
abed6c6 to
018d27e
Compare
018d27e to
061ab75
Compare
| [&](const ValueFlow::Value &value) { | ||
| if (!value.isSymbolicValue() || !value.isKnown() || value.intvalue != 0 || !value.tokvalue) | ||
| return false; | ||
| return value.tokvalue->str() == "new"; |
There was a problem hiding this comment.
This is an AI review take it with a grain of salt. Please feel free to reject it by clicking on Resolve
The new version fixes the char *q = p - 1; false negative, thanks. But since only new is accepted now, the same false positive is still there for malloc()/free():
void f(void) {
char *p = malloc(10);
++p;
free(p - 1); // invalidFree, same as on main
}Accepting allocation functions here (Token::simpleMatch(value.tokvalue, "(") && mSettings.library.getAllocFuncInfo(value.tokvalue->previous())) is not enough on its own. I tried it, and p - 1 gets no symbolic value at all for malloc, only possible 0 from the failed-allocation path. So this probably needs more valueflow work. If that is out of scope here, maybe add the malloc case as a TODO_ASSERT_EQUALS test, or open a follow-up ticket, so it isn't forgotten.
No description provided.