Skip to content

Fix #15006: FP invalidFree with new array - #8880

Open
ludviggunne wants to merge 4 commits into
cppcheck-opensource:mainfrom
ludviggunne:15006-preinc-delete
Open

ludviggunne wants to merge 4 commits into
cppcheck-opensource:mainfrom
ludviggunne:15006-preinc-delete

Conversation

@ludviggunne

Copy link
Copy Markdown
Collaborator

No description provided.

@ludviggunne
ludviggunne force-pushed the 15006-preinc-delete branch 2 times, most recently from abed6c6 to 018d27e Compare September 21, 2026 08:21
Comment thread lib/checkother.cpp
Comment thread lib/checkother.cpp
[&](const ValueFlow::Value &value) {
if (!value.isSymbolicValue() || !value.isKnown() || value.intvalue != 0 || !value.tokvalue)
return false;
return value.tokvalue->str() == "new";

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an AI review take it with a grain of salt. Please feel free to reject it by clicking on Resolve

The new version fixes the char *q = p - 1; false negative, thanks. But since only new is accepted now, the same false positive is still there for malloc()/free():

void f(void) {
    char *p = malloc(10);
    ++p;
    free(p - 1);   // invalidFree, same as on main
}

Accepting allocation functions here (Token::simpleMatch(value.tokvalue, "(") && mSettings.library.getAllocFuncInfo(value.tokvalue->previous())) is not enough on its own. I tried it, and p - 1 gets no symbolic value at all for malloc, only possible 0 from the failed-allocation path. So this probably needs more valueflow work. If that is out of scope here, maybe add the malloc case as a TODO_ASSERT_EQUALS test, or open a follow-up ticket, so it isn't forgotten.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants