* smatch 1.51 released
@ 2009-03-10 12:39 Dan Carpenter
2009-03-10 14:17 ` Dan Carpenter
0 siblings, 1 reply; 2+ messages in thread
From: Dan Carpenter @ 2009-03-10 12:39 UTC (permalink / raw)
To: LKML, smatch-discuss
Smatch follows the kernel naming scheme so odd numbers are devel
releases. The .51 means over half finished.
Smatch is available from: http://repo.or.cz/w/smatch.git/
This is a reimplementation that doesn't use gcc code. The check are
written in C instead of Perl. It's still fairly simple to write
tests. It's a bazillion times better than the original in almost
every way. Unfortunately it still sucks a little. There is a
shocking high percent of false positives.
To test the whole kernel use:
make -k CHECK=/path/to/smatch C=y bzImage | tee warns.txt
To test a single file use the smatch_scripts/kchecker script.
kchecker drivers/acpi/acpica/nsxfobj.c
The output is labeled either error, warn, or info. So "grep -w error:
warns.txt" Most of the "info" stuff is for the
smatch_scripts/find_null_params.sh script. Even though it's labeled
"info", grepping for "info: ignoring unreachable code." sometimes
turns up bugs.
Smatch works by tracking the flow of code.
int a; <- state is uninitialized.
if (b) {
a = foo(); <- state is initialized.
if (a) {
bar(a); <- state is non zero.
}
}
baz(a); <- state is undefined. possibly uninitialized, zero, or non-zero
It also understands some simple implications. For example the
following code doesn't generate an error.
ab = kzalloc();
if (NULL == ab) {
ret = -1;
goto foo;
}
...
foo:
if (ret) {
return;
}
ab->a = 1; // <-- This is not an error.
There are a couple functions that use a lot of memory to check. If
you have a gig of memory you should be ok. If it crashes use
"kchecker --valgrind" to generate a stack dump and mail that to me.
If you can't figure out why an error gets generated it's probably a
bug. Use "kchecker --debug" to try figure out what went wrong.
regards,
dan carpenter
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: smatch 1.51 released
2009-03-10 12:39 smatch 1.51 released Dan Carpenter
@ 2009-03-10 14:17 ` Dan Carpenter
0 siblings, 0 replies; 2+ messages in thread
From: Dan Carpenter @ 2009-03-10 14:17 UTC (permalink / raw)
To: LKML, smatch-discuss
On 3/10/09, Dan Carpenter <error27@gmail.com> wrote:
> Smatch follows the kernel naming scheme so odd numbers are devel
> releases. The .51 means over half finished.
>
> Smatch is available from: http://repo.or.cz/w/smatch.git/
>
Sorry, a couple people complained that I didn't actually say what smatch was.
It's an static analysis type error checker. It finds different bugs
than sparse. It's more like the stanford checker or maybe Microsoft's
PREfix. It can find more complicated bugs than coccinelle but it
can't fix them automatically. One key selling point is how simple it
is to write checks.
The error messages look like this:
drivers/scsi/pcmcia/nsp_cs.c +1725 nsp_cs_config(19) info: ignoring
unreachable code.
The 1725 is the line number. nsp_cs_config(19) is the function and
line number within the function.
Most of the error messages are false positives honestly, but some are real.
regards,
dan carpenter
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2009-03-10 14:17 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2009-03-10 12:39 smatch 1.51 released Dan Carpenter
2009-03-10 14:17 ` Dan Carpenter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®