{"thread":{"id":"17596","subject":"Git's static analysis","startedAt":"2009-02-05T21:40:04Z","lastAt":"2009-02-06T06:11:36Z","messageCount":3,"participants":["Pieter de Bie","Junio C Hamano","Robin Rosenberg"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"103399","messageId":"1233870004-63540-1-git-send-email-pdebie@ai.rug.nl","threadId":"17596","inReplyTo":null,"subject":"Git's static analysis","fromName":"Pieter de Bie","fromEmail":"pdebie@ai.rug.nl","sentAt":"2009-02-05T21:40:04Z","receivedAt":"2009-02-05T21:40:04Z","isPatch":false,"sender":{"key":"pdebie@ai.rug.nl","avatar":null},"body":"Hi all,\n\nI played around a bit with the 'Clang' static analyser, and tried to run git's\nsource code through it. It comes up with a few possible errors, so I thought\nyou might find it interesting. I took a quick glance, and it also seems to\nhave a few false positives, but it might still be worth to take a look.\n\nThe results can be found here:\n\n\thttp://frim.frim.nl/git-analyse/\n\n- Pieter\n"},{"id":"103414","messageId":"7v63jo9xbg.fsf@gitster.siamese.dyndns.org","threadId":"17596","inReplyTo":"1233870004-63540-1-git-send-email-pdebie@ai.rug.nl","subject":"Re: Git's static analysis","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2009-02-06T01:19:15Z","receivedAt":"2009-02-06T01:19:15Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Pieter de Bie <pdebie@ai.rug.nl> writes:\n\n> I played around a bit with the 'Clang' static analyser, and tried to run git's\n> source code through it. It comes up with a few possible errors, so I thought\n> you might find it interesting. I took a quick glance, and it also seems to\n> have a few false positives, but it might still be worth to take a look.\n>\n> The results can be found here:\n>\n> \thttp://frim.frim.nl/git-analyse/\n\nHmm, I took a quick look at a few, and they looked nonsense, but perhaps I\nam misreading things.\n\nFor example:\n\n    http://frim.frim.nl/git-analyse/report-uxXiUR.html#EndPath\n\nI am assuming that we follow the control flow of the labelled comments, so\nI followed along from [1] to [7] and then saw these:\n\n    [8] loop condition is false, execution continues on line 1492\n    1483:   for (i = 0; i < array->nr; i++) {\n                ...\n            }\n\n    [9] taking false branch\n    1492:   if (array->nr <= i)\n                return NULL;\n\n    [10] dereference of null pointer.\n    1495:   c->object.flags |= ...\n\nThe thing is, if [8] exits, \"i < array->nr\" is not true anymore, and there\nis no way you can take false branch of  \"if (array->nr <= i)\" in the\nimmediately next step [9]. and reach point [10].\n\nSo it is either that the tool does not know how \"for\" and \"if\" statement\nworks in C language, or I am completely misunderstanding what the in-line\ncomments are trying to tell me.\n"},{"id":"103431","messageId":"200902060711.37191.robin.rosenberg.lists@dewire.com","threadId":"17596","inReplyTo":"7v63jo9xbg.fsf@gitster.siamese.dyndns.org","subject":"Re: Git's static analysis","fromName":"Robin Rosenberg","fromEmail":"robin.rosenberg.lists@dewire.com","sentAt":"2009-02-06T06:11:36Z","receivedAt":"2009-02-06T06:11:36Z","isPatch":false,"sender":{"key":"robin.rosenberg@dewire.com","avatar":"https://avatars.githubusercontent.com/u/46357?v=4"},"body":"fredag 06 februari 2009 02:19:15 skrev Junio C Hamano:\n> Pieter de Bie <pdebie@ai.rug.nl> writes:\n> \n> > I played around a bit with the 'Clang' static analyser, and tried to run git's\n> > source code through it. It comes up with a few possible errors, so I thought\n> > you might find it interesting. I took a quick glance, and it also seems to\n> > have a few false positives, but it might still be worth to take a look.\n> >\n> > The results can be found here:\n> >\n> > \thttp://frim.frim.nl/git-analyse/\n> \n> Hmm, I took a quick look at a few, and they looked nonsense, but perhaps I\n> am misreading things.\n> \n> For example:\n> \n>     http://frim.frim.nl/git-analyse/report-uxXiUR.html#EndPath\n> \n> I am assuming that we follow the control flow of the labelled comments, so\n> I followed along from [1] to [7] and then saw these:\n> \n>     [8] loop condition is false, execution continues on line 1492\n>     1483:   for (i = 0; i < array->nr; i++) {\n>                 ...\n>             }\n> \n>     [9] taking false branch\n>     1492:   if (array->nr <= i)\n>                 return NULL;\n> \n>     [10] dereference of null pointer.\n>     1495:   c->object.flags |= ...\n\n> \n> The thing is, if [8] exits, \"i < array->nr\" is not true anymore, and there\n> is no way you can take false branch of  \"if (array->nr <= i)\" in the\n> immediately next step [9]. and reach point [10].\n\nThe code assumes can c become null in the loop [if (!c) continue]. If that\nis the last iteration it comes out of the loop with c == NULL and array->nr >=i,\nthus not returning. \n\nI have to dig through history until may 2008 to find this version of this code  so\nthe analysis seems a bit obsolete. The loop was rewritten in 4603ec0f960e.\n\n-- robin\n"}]}