RFR: 8361868: [GCC static analyzer] complains about missing calloc - NULL checks in p11_util.c

Thomas Stuefe stuefe at openjdk.org
Thu Jul 17 10:32:52 UTC 2025


On Tue, 15 Jul 2025 14:23:19 GMT, Matthias Baesken <mbaesken at openjdk.org> wrote:

> When using the GCC -fanalyzer flag (see https://developers.redhat.com/articles/2022/04/12/state-static-analysis-gcc-12-compiler# ) , we get some complaints about missing calloc return value checks for NULL (we check at some code locations but in p11_util.c we do not do it).

+1

-------------

Marked as reviewed by stuefe (Reviewer).

PR Review: https://git.openjdk.org/jdk/pull/26319#pullrequestreview-3028934222


More information about the security-dev mailing list