Menu

FALSE NEGATIVE: `zerodiv` misses zero written through an out-parameter

Rodri
2 days ago
1 day ago
  • Rodri

    Rodri - 2 days ago

    Hi, I found a false negative in Cppcheck 2.21.0 and 2.22 dev when a helper writes zero through a pointer before the pointed-to value is used as a divisor.

    Affected tool

    Cppcheck 2.21.0; also reproduced with Cppcheck 2.22 dev

    Affected checker

    Cppcheck CheckOther::checkZeroDivision (zerodiv / zerodivcond)

    Minimal reproducer

    void set_zero(int *value) {
      *value = 0;
    }
    
    int test() {
      int value;
      set_zero(&value);
      return 1 / value;
    }
    

    Reproduction command

    cppcheck --version
    cppcheck --enable=warning --std=c++17 --checkers-report=checkers.txt --template='{file}:{line}:{column}: [{id}] {message}' cppcheck-zerodiv-fn-out-parameter.cpp
    

    Current behavior

    Cppcheck produces neither a zerodiv nor a zerodivcond diagnostic. The checker report lists CheckOther::checkZeroDivision as active.

    Expected behavior

    Cppcheck should report line 8 because set_zero(&value) stores zero in value before the division.

     
  • CHR

    CHR - 1 day ago
     

Log in to post a comment.