mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Dan Carpenter <error27@gmail.com>
To: LKML <linux-kernel@vger.kernel.org>,
	smatch-discuss <smatch-discuss@lists.sf.net>
Subject: smatch 1.51 released
Date: Tue, 10 Mar 2009 15:39:46 +0300	[thread overview]
Message-ID: <a63d67fe0903100539r6ca3d789m4be81239eba2bf3b@mail.gmail.com> (raw)

Smatch follows the kernel naming scheme so odd numbers are devel
releases.  The .51 means over half finished.

Smatch is available from:  http://repo.or.cz/w/smatch.git/

This is a reimplementation that doesn't use gcc code.  The check are
written in C instead of Perl.  It's still fairly simple to write
tests.  It's a bazillion times better than the original in almost
every way.  Unfortunately it still sucks a little.  There is a
shocking high percent of false positives.

To test the whole kernel use:
make -k CHECK=/path/to/smatch C=y bzImage | tee warns.txt

To test a single file use the smatch_scripts/kchecker script.
kchecker drivers/acpi/acpica/nsxfobj.c

The output is labeled either error, warn, or info.  So "grep -w error:
warns.txt"  Most of the "info" stuff is for the
smatch_scripts/find_null_params.sh script.  Even though it's labeled
"info", grepping for "info: ignoring unreachable code." sometimes
turns up bugs.

Smatch works by tracking the flow of code.
int a;  <- state is uninitialized.
if (b) {
       a = foo();  <- state is initialized.
       if (a) {
              bar(a);  <- state is non zero.
       }
}
baz(a);  <- state is undefined.  possibly uninitialized, zero, or non-zero

It also understands some simple implications.  For example the
following code doesn't generate an error.
	ab = kzalloc();
	if (NULL == ab) {
		ret = -1;
		goto foo;
	}
   ...
foo:
	if (ret) {
		return;
	}
	ab->a = 1;  // <-- This is not an error.

There are a couple functions that use a lot of memory to check.  If
you have a gig of memory you should be ok.  If it crashes use
"kchecker --valgrind" to generate a stack dump and mail that to me.

If you can't figure out why an error gets generated it's probably a
bug.  Use "kchecker --debug" to try figure out what went wrong.

regards,
dan carpenter

             reply	other threads:[~2009-03-10 12:39 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-03-10 12:39 Dan Carpenter [this message]
2009-03-10 14:17 ` Dan Carpenter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=a63d67fe0903100539r6ca3d789m4be81239eba2bf3b@mail.gmail.com \
    --to=error27@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=smatch-discuss@lists.sf.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®