From patchwork Tue Jan 6 19:10:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddhesh Poyarekar X-Patchwork-Id: 127459 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [127.0.0.1]) by sourceware.org (Postfix) with ESMTP id 6C67D4BA2E1F for ; Tue, 6 Jan 2026 19:11:50 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 6C67D4BA2E1F Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=gotplt.org header.i=@gotplt.org header.a=rsa-sha256 header.s=dreamhost header.b=QiKAjLsZ X-Original-To: gcc-patches@gcc.gnu.org Delivered-To: gcc-patches@gcc.gnu.org Received: from olivedrab.birch.relay.mailchannels.net (olivedrab.birch.relay.mailchannels.net [23.83.209.135]) by sourceware.org (Postfix) with ESMTPS id F3B764BA2E1F for ; Tue, 6 Jan 2026 19:11:05 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org F3B764BA2E1F Authentication-Results: sourceware.org; dmarc=none (p=none dis=none) header.from=gotplt.org Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gotplt.org ARC-Filter: OpenARC Filter v1.0.0 sourceware.org F3B764BA2E1F Authentication-Results: server2.sourceware.org; arc=pass smtp.remote-ip=23.83.209.135 ARC-Seal: i=2; a=rsa-sha256; d=sourceware.org; s=key; t=1767726666; cv=pass; b=Rui6GZqW/mblEC4fX4o5w4gBvCaQNgiUhWlUwiu0xzTba/nKULvFyPpGdqi3Wv+BBP9T+VngIjqFthn1jwDvYYmim+Szry5zR6Mvg+AYC+bKtI6fRHq/fs+IPgzHO3dDTF6XWI6t4jPn7vtfBTlhnBp6CDN/QNbA+QndXFayjIc= ARC-Message-Signature: i=2; a=rsa-sha256; d=sourceware.org; s=key; t=1767726666; c=relaxed/simple; bh=byI1pzdEiSB7l6JY+RP1xc6iQwl7Ix/Yyq9GaB0xVkE=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=PDv4D/JzoSNr4bvKZe+IDZw8UMnC2j0URg/HSxSibTx/sOIedLCfZADkEVBGnYoG/xe+cCB8FTRUCkZdeK7i8eGpGHNYNNWsZmCBq5/jvW/cBBjfs8WlZNjVZssATpU0aDHpMZ4vkSGNy8H5RlYKsotScE4ZYj2n8wHTGMDjAuw= ARC-Authentication-Results: i=2; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org F3B764BA2E1F X-Sender-Id: dreamhost|x-authsender|siddhesh@gotplt.org Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id ED06978314A; Tue, 06 Jan 2026 19:11:04 +0000 (UTC) Received: from pdx1-sub0-mail-a261.dreamhost.com (100-112-114-238.trex-nlb.outbound.svc.cluster.local [100.112.114.238]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id 3E3DC783173; Tue, 06 Jan 2026 19:11:03 +0000 (UTC) ARC-Seal: i=1; a=rsa-sha256; d=mailchannels.net; s=arc-2022; cv=none; t=1767726664; b=sE+fzIbofBh/3rS+gsoi3RNrV4gq2yCceWWGH2B5zT5l8ePQmkUJXx5ljRqoTGfUtA5XVI JgIFkd1IWOmJCsgwePwzi4TtkSaelSajyI4iYrDSO+V84vZs52x+UQ2J681Le2zh9xNC+J +OzVtnsAATQ4wjq1GoTCShuaLyc5ypI1wXQBp4x9vSCjqOqLPVqycTcYU7Y0HpIS7VK+M8 Qj8FCOHPntqjyBYZt0e8xVredwPRMyjArb2Ya/gxLHaocMlRZdUUJWH6hbSPhAyhvx/qj8 yRbpTM9qFWkFdfzA/y9NlFy/bt2nsGElSZ3ey9LvE/4PMUwWpSq0meYjhXs2vg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=mailchannels.net; s=arc-2022; t=1767726664; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding:dkim-signature; bh=CkNg+EHrE9r6qMkkRjw4lgPuYdP5M1vdYBK6ELctMJA=; b=lXyaDnbwet/IEw/TwdghrC5eYVVLg1p1qYvQMVMWVBRWGslUpAeW2stho9JqjcPKZziMh5 c0Ta1+j6DF1BpuXxxrbMwlPiRtym2fJeXFthhWiGLdrRgLvF2reVWeTiyBDsyfo3BAXIUo UB8/qL7Vsk+ZoiojRSZ+Nmg73JhDf9GRkm2PrQtPHqRVKITnRH7tn5OZdI9oYf6vb10LRB 0x5oslLf05glYV27SxIxRVVWhMRuwK7hGVuYqBrRKPYzjiGQQMWeJ2/Z8zLrS9AMUNH5ur b6DfThBHJHOU0GCbCK2nKENCtUygERKbfE+Hb+PYERqwLj5+wqc1ABlgO2p1ZA== ARC-Authentication-Results: i=1; rspamd-85db7f4c96-ltccx; auth=pass smtp.auth=dreamhost smtp.mailfrom=siddhesh@gotplt.org X-Sender-Id: dreamhost|x-authsender|siddhesh@gotplt.org X-MC-Relay: Neutral X-MailChannels-SenderId: dreamhost|x-authsender|siddhesh@gotplt.org X-MailChannels-Auth-Id: dreamhost X-Reaction-Eight: 6530f25158bbe1a1_1767726664498_1977481952 X-MC-Loop-Signature: 1767726664498:168861119 X-MC-Ingress-Time: 1767726664498 Received: from pdx1-sub0-mail-a261.dreamhost.com (pop.dreamhost.com [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.112.114.238 (trex/7.1.3); Tue, 06 Jan 2026 19:11:04 +0000 Received: from devel (unknown [38.23.181.90]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: siddhesh@gotplt.org) by pdx1-sub0-mail-a261.dreamhost.com (Postfix) with ESMTPSA id 4dm13V4kxwz104n; Tue, 6 Jan 2026 11:11:02 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gotplt.org; s=dreamhost; t=1767726662; bh=CkNg+EHrE9r6qMkkRjw4lgPuYdP5M1vdYBK6ELctMJA=; h=From:To:Cc:Subject:Date:Content-Transfer-Encoding; b=QiKAjLsZEWhDRsp0YDIJAAvy8/xEmiXS9ee/X7fSsiMEqO0Z60I+JCfS2gsl3InKr 7ecdJ2A7BTXj1KGZsoX8ps9D5lwbiX8TeIgD4y2U7FZI8n/GM/jQRh8OltSu/Ewx9q jTG0XCpzu/7NFApgOey1uOT3PYq6bZ09uELIlx3ksRlhlnDN36hqHz2sJQn/DwCDQz uyzbh34FVLTIDq0iQ8tREgIK68RbkEKLn6z1Jqdn2WI0+xdaZrBO7vt15h9dAOoH3a NuMLK1m2IwAEQm0DLbfM6vsS/5CMXvY23MK3v0Pse7ZtpOruIjgwNMVnTXaWXdpvIm AUSOZlEXF6HZA== From: Siddhesh Poyarekar To: gcc-patches@gcc.gnu.org Cc: andrew.pinski@oss.qualcomm.com Subject: [PATCH] warn_access: Limit waccess2 to dangling pointer checks [PR 123374] Date: Tue, 6 Jan 2026 14:10:47 -0500 Message-ID: <20260106191047.3385622-1-siddhesh@gotplt.org> X-Mailer: git-send-email 2.52.0 MIME-Version: 1.0 X-Spam-Status: No, score=-3035.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H4, RCVD_IN_MSPIKE_WL, RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP, URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: gcc-patches@gcc.gnu.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gcc-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gcc-patches-bounces~patchwork=sourceware.org@gcc.gnu.org The second pass of warn_access (waccess2) was added to implement dangling pointer checks but it implicitly ran the early checks too, which issues false warnings on code that has not been fully optimized. Limit this second run to only dangling pointer checks for call statements. This does not break any of the existing warning tests, so it didn't seem to add any actual value for the additional run anyway. gcc/ChangeLog: PR tree-optimization/123374 * gimple-ssa-warn-access.cc (pass_waccess::set_pass_param): Add a second parameter. (pass_waccess::check_call): Skip access checks for waccess2. (pass_waccess::execute): Drop initialization of M_CHECK_DANGLING_P. * passes.def: Adjust. gcc/testsuite/ChangeLog: PR tree-optimization/123374 * g++.dg/warn/pr123374.cc: New test. Signed-off-by: Siddhesh Poyarekar --- Testing: - Bootstrapped and tested on x86_64, no new failures - Bootstrap for config=ubsan in progress - Build and tested i686, no new failures. gcc/gimple-ssa-warn-access.cc | 38 +++++++++++++++++---------- gcc/passes.def | 6 ++--- gcc/testsuite/g++.dg/warn/pr123374.cc | 29 ++++++++++++++++++++ 3 files changed, 56 insertions(+), 17 deletions(-) create mode 100644 gcc/testsuite/g++.dg/warn/pr123374.cc diff --git a/gcc/gimple-ssa-warn-access.cc b/gcc/gimple-ssa-warn-access.cc index 44e62475cfa..df34da2bf96 100644 --- a/gcc/gimple-ssa-warn-access.cc +++ b/gcc/gimple-ssa-warn-access.cc @@ -2246,11 +2246,21 @@ pass_waccess::~pass_waccess () } void -pass_waccess::set_pass_param (unsigned int n, bool early) +pass_waccess::set_pass_param (unsigned int n, bool param) { - gcc_assert (n == 0); - - m_early_checks_p = early; + /* Check for dangling pointers in the earliest runs of the pass. + The latest point -Wdangling-pointer should run is just before + loop unrolling which introduces uses after clobbers. Most cases + can be detected without optimization; cases where the address of + the local variable is passed to and then returned from a user- + defined function before its lifetime ends and the returned pointer + becomes dangling depend on inlining. */ + if (n == 0) + m_early_checks_p = param; + else if (n == 1) + m_check_dangling_p = param; + else + __builtin_unreachable (); } /* Return true when any checks performed by the pass are enabled. */ @@ -4380,6 +4390,16 @@ pass_waccess::check_call (gcall *stmt) && gimple_call_internal_fn (stmt) == IFN_ASAN_MARK) return; + if (m_check_dangling_p) + { + check_call_dangling (stmt); + + /* Don't do any other checks when doing dangling pointer checks the + second time. */ + if (!m_early_checks_p) + return; + } + if (gimple_call_builtin_p (stmt, BUILT_IN_NORMAL)) check_builtin (stmt); @@ -4397,7 +4417,6 @@ pass_waccess::check_call (gcall *stmt) } check_call_access (stmt); - check_call_dangling (stmt); if (m_early_checks_p) return; @@ -4800,15 +4819,6 @@ pass_waccess::execute (function *fun) m_ptr_qry.rvals = enable_ranger (fun); m_func = fun; - /* Check for dangling pointers in the earliest run of the pass. - The latest point -Wdangling-pointer should run is just before - loop unrolling which introduces uses after clobbers. Most cases - can be detected without optimization; cases where the address of - the local variable is passed to and then returned from a user- - defined function before its lifetime ends and the returned pointer - becomes dangling depend on inlining. */ - m_check_dangling_p = m_early_checks_p; - auto_bitmap bb_uids_set (&bitmap_default_obstack); m_bb_uids_set = bb_uids_set; diff --git a/gcc/passes.def b/gcc/passes.def index 54b56b3c0c8..4586d2cf6ad 100644 --- a/gcc/passes.def +++ b/gcc/passes.def @@ -61,7 +61,7 @@ along with GCC; see the file COPYING3. If not see NEXT_PASS (pass_warn_printf); NEXT_PASS (pass_warn_nonnull_compare); NEXT_PASS (pass_early_warn_uninitialized); - NEXT_PASS (pass_warn_access, /*early=*/true); + NEXT_PASS (pass_warn_access, /*early=*/true, /*check_dangling=*/true); NEXT_PASS (pass_ubsan); NEXT_PASS (pass_nothrow); NEXT_PASS (pass_rebuild_cgraph_edges); @@ -216,7 +216,7 @@ along with GCC; see the file COPYING3. If not see NEXT_PASS (pass_object_sizes); NEXT_PASS (pass_post_ipa_warn); /* Must run before loop unrolling. */ - NEXT_PASS (pass_warn_access, /*early=*/true); + NEXT_PASS (pass_warn_access, /*early=*/false, /*check_dangling=*/true); /* Profile count may overflow as a result of inlinining very large loop nests. This pass should run before any late pass that makes use of profile. */ @@ -451,7 +451,7 @@ along with GCC; see the file COPYING3. If not see NEXT_PASS (pass_gimple_isel); NEXT_PASS (pass_harden_conditional_branches); NEXT_PASS (pass_harden_compares); - NEXT_PASS (pass_warn_access, /*early=*/false); + NEXT_PASS (pass_warn_access, /*early=*/false, /*check_dangling=*/false); NEXT_PASS (pass_cleanup_cfg_post_optimizing); NEXT_PASS (pass_warn_function_noreturn); diff --git a/gcc/testsuite/g++.dg/warn/pr123374.cc b/gcc/testsuite/g++.dg/warn/pr123374.cc new file mode 100644 index 00000000000..cf777672aa7 --- /dev/null +++ b/gcc/testsuite/g++.dg/warn/pr123374.cc @@ -0,0 +1,29 @@ +long ext_f (void *, unsigned long) + __attribute__ ((__access__ (__write_only__, 1, 2))); + +long f (void *b, unsigned long n) +{ + unsigned long sz = __builtin_dynamic_object_size(b, 0); + + return (__builtin_constant_p (sz) && sz == -1UL) ? ext_f (b, n) : 0; +} + + +void test (unsigned limit, long init_off) +{ + char buf[4096]; + unsigned long off = 0; + + while (off == 0) + off += init_off; + + while (off < limit) + { + long n = f (buf + off, sizeof (buf) - off); + + if (n <= 0) + continue; + + off += n; + } +}