4 ms·
Yes, PVS-Studio is very good and useful for avoiding bugs. No, companies don't really care about avoiding bugs. No one at Samsung will risk delaying the releas
by virtualized 9y ago
Yes, PVS-Studio is very good and useful for avoiding bugs.
No, companies don't really care about avoiding bugs. No one at Samsung will risk delaying the release of the next plastic crap product by fixing any problems. Why would they? Defects will even encourage customers to buy a new device because they are used to getting no bug fix updates. This is the worst possible company for Viva64 to go to.
It seems like C++ developers either don't give a shit about code quality or they do, and don't make many mistakes anymore. Either way there is little demand for a static analyzer. It won't get easier for Viva64 in the future. A few years ago, Compilers and IDEs started providing similar warnings as PVS-Studio, although not quite as sophisticated yet. Code-level testing begins to be a thing in proprietary software. Clang offers valgrind-like sanitizers for different classes of bugs that even PVS-Studio cannot detect.
TIL that Viva64 has over 20 employees. The passive-aggressive blog posts always made it look like one or two people running PVS-Studio as a side project or so. I read those posts regularly, but I don't remember them announcing any new features or improvements in PVS-Studio itself. Why do I have to pay annually if they don't spend the money on improving the product?
I am not even sure if PVS-Studio is worth the money. They don't have prices on the web site and defend their business decisions in the FAQ (https://www.viva64.com/en/order-faq/ https://www.viva64.com/en/order-faq/) in a very unprofessional way. After reading that it feels like I might get ripped off.
- com2kid 9y agoI've worked on consumer electronics, code quality is up to the technical leads. Asserts had to be fixed, warnings as errors, and all memory problems were to be fixed, full stop. We had crash dump reporting in place, more than 10 hits and the issue got investigated and fixed. Some software teams take pride in their work, it is unfortunate consumers don't have an easy way to ID those teams when buying a product.
- adekok 9y ago> I am not even sure if PVS-Studio is worth the money. They don't have prices on the web site A lot of companies don't do that. Last I checked, Coverity was the same. And likely 6 figures for large code bases. At this point, for commercial project, I'd just use clang analyzer and cppcheck. Then, use the clang address sanitizer when running tests. That's likely better than what people do now. And, ensure that builds are clean with no errors. :( Most projects have thousands of warnings when compiling. That just can't be good.
- AndreyKarpov 9y ago> I read those posts regularly, but I don't remember them announcing any new features or improvements in PVS-Studio itself. PVS-Studio Release History: https://www.viva64.com/en/m/0010/ https://www.viva64.com/en/m/0010/ PVS-Studio project - 10 years of failures and successes: https://www.viva64.com/en/b/0465/ https://www.viva64.com/en/b/0465/ How PVS-Studio does the bug search: methods and technologies: https://www.viva64.com/en/b/0466/ https://www.viva64.com/en/b/0466/
- virtualized 9y agoThat's a changelog. I don't mean once-a-year posts that no one reads because they are too long. I mean regular, valuable information about the product.
- AndreyKarpov 9y agoI think you do not follow our articles carefully :). We have a lot of diverse publications in the our blog: https://www.viva64.com/en/b/ https://www.viva64.com/en/b/ Including, describing the product. For example: PVS-Studio as a plugin for SonarQube - https://www.viva64.com/en/b/0513/ https://www.viva64.com/en/b/0513/ Support of Visual Studio 2017 and Roslyn 2.0 in PVS-Studio: sometimes it's not that easy to use ready-made solutions as it may seem - https://www.viva64.com/en/b/0503/ https://www.viva64.com/en/b/0503/ The way static analyzers fight against false positives, and why they do it - https://www.viva64.com/en/b/0488/ https://www.viva64.com/en/b/0488/ Why I Dislike Synthetic Tests - https://www.viva64.com/en/b/0471/ https://www.viva64.com/en/b/0471/ Integrating PVS-Studio into Eclipse CDT (Linux) - https://www.viva64.com/en/b/0458/ https://www.viva64.com/en/b/0458/ Integrating PVS-Studio into Anjuta DevStudio (Linux) - https://www.viva64.com/en/b/0459/ https://www.viva64.com/en/b/0459/ Issues we faced when renewing PVS-Studio user interface - https://www.viva64.com/en/b/0450/ https://www.viva64.com/en/b/0450/ and so on I can also offer a presentation: PVS-Studio static code analyzer for C, C++ and C# (2017) - https://youtu.be/kmqF130pQW8 https://youtu.be/kmqF130pQW8
- blevin 9y ago> It seems like C++ developers either don't give a shit about code quality or they do, and don't make many mistakes anymore. Either way there is little demand for a static analyzer Well, this is like claiming that authors writing in English don't care about grammar. There's too many people doing too many different things with the language -- from texting LOLs to writing academic research -- to generalize. But speaking from experience with one ~5M line industrial C++ codebase continually developed since the 90's, we care enough about quality to have a whole set of measures, automated and cultural, to support it. We've looked at static analyzers several times but none of the evals have found issues worth the price. It turned up things like a static expression to compute a bitmask where the same flag was being listed multiple times. Which is nice, but made it feel more like a lint tool in terms of differential value added for us. If we didn't have things like valgrind memcheck on continuous integration, it might be a different story.
- AndreyKarpov 9y ago> They don't have prices on the web site This is standard practice. PVS-Studio is a B2B solution. There are many details to be discussed. For individual developers we propose the following: "How to use PVS-Studio for Free" - https://www.viva64.com/en/b/0457/ https://www.viva64.com/en/b/0457/ And "Handing out PVS-Studio Analyzer Licenses to Security Experts" - https://www.viva64.com/en/b/0510/ https://www.viva64.com/en/b/0510/
- virtualized 9y ago"How to use PVS-Studio for Free" is ridiculous. "Handing out PVS-Studio Analyzer Licenses to Security Experts" - sorry, tl;dr
- stinos 9y agoIt seems like C++ developers either don't give a shit about code quality or they do, and don't make many mistakes anymore I wish. That last part should rather be: "and don't make a lot of mistakes anymore". Even the gurus out there are not completely without mistakes. As for the first group you refer to: what might look like not giving a shit, is often actually simply a lack of understanding/training it seems. As in: not actively not giving a shit but rather simply not knowing they are doing it wrong.