New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bounds checking bounds-safe interfaces in unchecked scopes #1169
Conversation
LValuesAssignedChecked contains AbstractSets representing lvalues expressions that have unchecked pointer type that were assigned a checked pointer during the current top-level statement (if the statement is in an unchecked scope). AbstractSets in LValuesAssignedChecked should have their bounds validated after checking the current statement.
…so it results in a warning
…ith declared bounds
…unds-safe interface
…into bounds-checking-unchecked-scope
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM (there's just one minor comment)! Thank you!
p += i; | ||
|
||
// The type of the RHS expression p + r is int *, so a checked pointer is not | ||
// assigned to p here. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It looks like the code that the comment on lines 841 and 842 is referring to is missing (not sure).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The comment on lines 841 and 842 is referring to the code on line 843, since the type of the RHS expression p - (_Array_ptr<int>)q
is int *
.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The comment has a typo, so I'll update the comment - thanks for catching this!
…into bounds-checking-unchecked-scope
Fixes #1158
This PR updates the bounds checking behavior for lvalue expressions with bounds-safe interfaces in unchecked scopes.
If:
S
is in an unchecked scope, and:e
has unchecked pointer type (its bounds were declared using a bounds-safe interface), and:S
does not contain an assignmente = e1
wheree1
is a checked pointer, then:The bounds of
e
are not validated after checkingS
.