[analyzer] New checker for detecting usages of unsafe I/O functions
authorKristof Umann <dkszelethus@gmail.com>
Mon, 11 Feb 2019 13:46:43 +0000 (13:46 +0000)
committerKristof Umann <dkszelethus@gmail.com>
Mon, 11 Feb 2019 13:46:43 +0000 (13:46 +0000)
commit8d239996392ca19efe868432fc521cfd4a8a40d7
treed92d5a814f4a34abaf863547a6c2f429004a31f3
parent07834061205152cb9f7240ea8c5d8170ec9af98c
[analyzer] New checker for detecting usages of unsafe I/O functions

There are certain unsafe or deprecated (since C11) buffer handling
functions which should be avoided in safety critical code. They
could cause buffer overflows. A new checker,
'security.insecureAPI.DeprecatedOrUnsafeBufferHandling' warns for
every occurrence of such functions (unsafe or deprecated printf,
scanf family, and other buffer handling functions, which now have
a secure variant).

Patch by Dániel Kolozsvári!

Differential Revision: https://reviews.llvm.org/D35068

llvm-svn: 353698
clang/docs/analyzer/checkers.rst
clang/include/clang/StaticAnalyzer/Checkers/Checkers.td
clang/lib/StaticAnalyzer/Checkers/CheckSecuritySyntaxOnly.cpp
clang/test/Analysis/security-syntax-checks.m