Fix #15034 FN arrayIndexOutOfBounds (ternary in subfunction) - #8856
chrchr-github wants to merge 6 commits into
Conversation
|
|
||
| // The struct Fred has two functions, a constructor and a destructor | ||
| ASSERT_EQUALS(2U, fredScope->functionList.size()); | ||
| ASSERT_EQUALS(2U, fredScope->functionList.size()); // cppcheck-suppress nullPointer // see ticket #9747 |
There was a problem hiding this comment.
This is an AI review. Take it with a grain of salt and feel free to reject it by resolving the comment.
I confirmed that this suppression is needed because of the PR. With selfcheck's options (--check-level=exhaustive --library=cppcheck-lib ...), the merge base gives no warning here, while this PR gives Possible null pointer dereference: fredScope. It is a false positive, since assert_() throws when the condition fails. The cause is that the removed "condition depends on only one variable" guard in setTokenValue() used to drop the nullptr from (it == db->scopeList.end()) ? nullptr : &*it, because the condition contains a function call. So user code with the same "ternary + throwing check" pattern will now also hit #9747.
To get a feel for how often that happens, I compared warnings for the merge base and the PR on lib/, cli/, test/cfg/, samples/, testsymboldatabase.cpp and testvalueflow.cpp (normal check level, style/warning/portability/performance, inconclusive). Both gave exactly the same 2407 warnings, so it doesn't look widespread. Some correlated-ternary probes such as d = (a > b) ? 0 : a - b; if (a > b) return 0; return 10 / d; also stayed silent. Just mentioning it so the trade-off is a conscious one.
No description provided.