5 ms·
You make it sound like people don't implement static analyzers from scratch for every static language out there. Static analysis is not obsoleted by using a "st
by nikic 11y ago
You make it sound like people don't implement static analyzers from scratch for every static language out there. Static analysis is not obsoleted by using a "static" language. You can't even say that static analysis is easier in a static language (the problems you deal with are just different).
Every language with a non-trivial number of users tends to have a couple (or maybe couple dozen) different static analyzers of varying quality. This is one of the PHP static analyzers.
- munin 11y ago> You make it sound like people don't implement static analyzers from scratch for every static language out there. Yes, except those static analyzers are the compilers for those languages and the rules that define crappy programs are in the type system, not in ad-hoc specifications of patterns to identify for static analyzers...
- nikic 11y agoStatic analyzers for different languages detect different types of errors. A static analyzer for PHP may try to find type mismatches. For statically typed languages that's obviously not relevant, as the compiler already handles it. On the other hand, a static analyzer for C may try to find use-after-free bugs. For PHP that in return is not relevant, as the compiler/runtime handles it already. While some compilers do ship with static analysis components (e.g. Clang), static analyzers are usually distinct from compilers. Doesn't matter it for static or dynamic languages.
- munin 11y agoType checking is static analysis. Languages like C have crappy type systems, so the type checking static analysis is also crappy. This is a property of the type system, not the universe...
- csixty4 11y ago> Yes, except those static analyzers are the compilers for those languages The first linting tool was made in 1979 for C programs and I remember ads for PC-Lint in the back of programming magazines all the time growing up. Static analysis tools catch more than just datatype errors. They look for patterns that identity common logic errors as well. PC-Lint used to cost a couple hundred dollars, and people were plenty willing to pay that much for extra peace of mind.
- munin 11y agoWhat if your type system was rich enough that a "datatype error" was a logic error?
- squeaky-clean 11y agoThat can't prevent every logic error. Here's[0] something I remember reading that really impressed me with static analysis tools. Running PVS-Studio against the Unreal 4 Engine (which is entirely C++). It was able to detect a surprising number of logic errors, probably just caused by as tired programmer, or copy-pasting too quickly. For example in the function below, it was able to spot that the last 2 clauses of that comparison are identical. The programmer meant to use a '+' instead of '-' in the last one. I don't think you could have a type system that would disallow this logic error. (If it is possible, please prove me wrong, because that sounds awesome). static bool PositionIsInside(....) { return Position.X >= Control.Center.X - BoxSize.X * 0.5f && Position.X <= Control.Center.X + BoxSize.X * 0.5f && Position.Y >= Control.Center.Y - BoxSize.Y * 0.5f && Position.Y >= Control.Center.Y - BoxSize.Y * 0.5f; } [0] http://www.viva64.com/en/b/0249/ http://www.viva64.com/en/b/0249/