Skip to content

C++: Improve logic for perfect forwarding - #22654

Draft
MathiasVP wants to merge 25 commits into
github:mainfrom
MathiasVP:fix-forward-interpretation
Draft

MathiasVP wants to merge 25 commits into
github:mainfrom
MathiasVP:fix-forward-interpretation

Conversation

@MathiasVP

Copy link
Copy Markdown
Contributor

In #22532 we added support for specifying whether a modelled function forward all its arguments. However, we implemented very some naive logic for identifying the constructor to invoke when given a type and a set of argument types. This PR fixes that by modelling (to the best of my abilities) the conversion rules and type matching of C++ to correctly map a list of arguments to a constructor.

We use a flow-based approach where we check if a sequence of steps can flow from a "source" (an argument type) to a "sink" (a constructor parameter type) using 0 or more steps (type conversions).

Unsurprisingly, C++ rules make this rather complicated. There are a few missing results still (related to how CV qualifiers are being treated), and spurious results (related to how overload resolution ranks conversions) but I'd prefer to leave those for as future work.

There are many commits since I worked tirelessly to ensure that each commit can be reviewed in isolation. Please thank me by reviewing it commit-by-commit! 😅

@github-actions github-actions Bot added the C++ label Sep 22, 2026
Comment thread cpp/ql/lib/semmle/code/cpp/dataflow/ExternalFlow.qll Dismissed
@MathiasVP
MathiasVP force-pushed the fix-forward-interpretation branch from 3602750 to 0f32801 Compare September 22, 2026 18:19

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants