3 ms·
> Some build system patches + Clang's static analyzer + codechecker seems to be the most promising combination since that would not only be able to cross transl
by yaantc 4y ago
> Some build system patches + Clang's static analyzer + codechecker seems to be the most promising combination since that would not only be able to cross translation unit analysis, but also be able to do differential reporting so only new reports are visible, but I still need to figure out all of the details. Also, I suspect the end result will be far less useful in practice than it sounds because of just how long the analysis takes. We would need a way to do incremental analysis like we can do incremental builds for it to be truly useful, and I currently do not have an answer for incremental analysis, although I suspect maybe something could be done in CodeChecker based on filesystem time stamps.
I use CodeChecker with ClangSA, CTU enabled and with Z3 for refutation. The
code base is smaller so incremental checking is less a concern to me.
Still, we had a look. CC allows taking a list of files, and updating those
files analysis only while keeping the existing results for other non listed
files.
But unless something has changed this partial analysis just do what it's
told, analyzing only the files given on the CLI. With CTU this may miss
side effects: a modified file may impact other files using its function for
example. It's possible to use CC own CTU info to derive these dependencies
and extend the list of files.
Then there are modified header files, with the usual inclusion
dependencies.
So if it's not provided "out of the box", it should be possible to have a
layer on top taking a list of changed files, extending it with both CTU and
header dependencies, and passing the extended list to CC for a safe update.