@@ -453,6 +453,11 @@ sm_state_map::on_svalue_purge (const state_machine &sm,
to_remove.safe_push (dst_sid);
}
+ else if ((*iter).second.m_origin.as_int () >= first_unused_sid.as_int ())
+ {
+ /* If the origin svalue is being purged, then reset it to null. */
+ (*iter).second.m_origin = svalue_id::null ();
+ }
}
int i;
new file mode 100644
@@ -0,0 +1,25 @@
+typedef __SIZE_TYPE__ size_t;
+
+int idx;
+void *fp;
+
+size_t
+fread (void *, size_t, size_t, void *);
+
+void
+ql (void)
+{
+ int n1[1];
+
+ fread (n1, sizeof (n1[0]), 1, fp); /* { dg-message "'n1' gets an unchecked value here" } */
+ idx = n1[0]; /* { dg-message "'idx' has an unchecked value here (from 'n1')" */
+}
+
+int arr[10];
+
+int
+pl (void)
+{
+ ql ();
+ return arr[idx]; /* { dg-warning "use of tainted value 'idx' in array lookup without bounds checking" } */
+}