2 ms·
Static analysis tools are great for simple bugs. However, most compiler tools already fix these simple bugs. If there is a class of bugs not addressed by a comp
by chimtim 11y ago
Static analysis tools are great for simple bugs. However, most compiler tools already fix these simple bugs. If there is a class of bugs not addressed by a compiler, most developers have a script to catch these. It may not find the harder to detect bugs (such as those arising out of nested calls), but it gets the job done. The complex tools pushed out by the static analysis guys usually has a high false positive rate that at first becomes annoying to use and later is completely ignored.
As for more complex bugs, most developers are aware these bugs exist but do not want to fix them immediately. The reason is on many occasions, these bugs represent some bigger problem in the code base that requires significant re-factoring. And applying the quick fix as suggested by the code analysis tool simply buries these problems instead of fixing them the right way.
- AndreyKarpov 11y agoYes, static analyzers mostly catch simple bugs. But it doesn't really matter if a bug is simple or complicated. You see, programmers believe they never make or make very few simple bugs: http://www.viva64.com/en/b/0116/ http://www.viva64.com/en/b/0116/ But they are wrong. They do make quite a lot of them. Here's, for instance, a bug database we have collected and keep updating: http://www.viva64.com/en/examples/ http://www.viva64.com/en/examples/. Moreover, some bugs can take quite a while to find, despite being simple. Here's a nice example: The conclusion is: the bug we had wasted about 50 hours to track was detected at once with the first run of the analyzer and fixed in less than an hour! Source: http://www.viva64.com/en/b/0221/ http://www.viva64.com/en/b/0221/ True, false positives aren't good, but they are not that much trouble. Static analysis tools provide numbers of means to suppress them. At least, we in PVS-Studio do have a lot of false positive suppression mechanisms. But it's a long story, so you'd better refer to the documentation.