C++: Use the IR for cpp/return-stack-allocated-memory.
#7682
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This query is a perfect query for the IR. Without really thinking too hard about it I was able to remove all the false positives from our tests for this query 🎉.
I changed the behavior of the query to not report 'may' flow, but only 'must' flow. This removes the possibility of FPs from complex path conditions which we cannot reason about.
This has no influence on Samate since Samate has a very low number of tests for this CWE. It does find a bunch of good results on LGTM, though (I've provided a link in the internal issue).