5 ms·
> But I feel like I'm looking at a laundry list of mostly minor, tiny issues, that are a "solved problem" in the form of existing warnings. I'm not aware of w
by DennisMoore 11y ago
> But I feel like I'm looking at a laundry list of mostly minor, tiny issues, that are a "solved problem" in the form of existing warnings.
I'm not aware of warnings for uninitialized variables in constructors. Can you clue me in how to get these on in Visual Studio? I'm using a third party tool that can detect uninitialized scalars only and would love to have the extra scanning.
- MaulingMonkey 11y agoSadly Visual Studio's compiler has no warning I'm aware of. Using /sdl will forcibly initialize all your members however - I guess Microsoft's approach to the problem is that fixing it for you is better than giving you ignore-able warnings. There are third party tools - such as cppcheck - which should catch uninitialized members however. I generally also compile with clang, which catches a lot of additional stuff for me. And here's a random John Carmack link noting some of the static analysis tools out there: http://www.gamasutra.com/view/news/128836/InDepth_Static_Code_Analysis.php http://www.gamasutra.com/view/news/128836/InDepth_Static_Cod... I've been playing around with clang's Address Sanitizer all day as well, catching buffer overflows and underflows left and right in a janky old codebase I was suddenly thrust into recently...
- DennisMoore 11y agoWe are (slowly...) doing the same thing across our codebase. The tool we use -- PVS-Studio -- just introduced checking for uninit'd scalars so we are grinding those down and doing eyeball checks in the ctors, but I was hoping for a more reliable method for the latter portion. Thanks for /SDL! This looks like it may be very promising: http://blogs.microsoft.com/cybertrust/2012/06/06/warnings-sdl-and-improving-uninitialized-variable-detection/ http://blogs.microsoft.com/cybertrust/2012/06/06/warnings-sd... At the very least that would help remove random behavior at the cost of speed (if I understand correctly). I'll have to sleep on /SDL and do some perf testing come Monday. I had really wanted to use /analyze (https://msdn.microsoft.com/en-us/library/d3bbz7tz%28v=VS.100%29.aspx https://msdn.microsoft.com/en-us/library/d3bbz7tz%28v=VS.100...) but it crashes! D: Unfortunately, I'm rooted in Windows SDK and I don't think clang supports that. The Microsoft Application Verifier has some run-time memory checks, so I'm not totally unarmed. I looked at PC-lint doesn't have complete support for C++11 yet and I'm worried about the rate of false positives. I had not heard of cppcheck, so I'll have to give that go since it looks free. Thanks for the info!