GCC now has this elaborate (kind of beautiful) way of highlighting a path through your code which leads to a potential oopsie like use after free.
`-fno-omit-frame-pointer` has been useful for profiling using perf.
GCC now has this elaborate (kind of beautiful) way of highlighting a path through your code which leads to a potential oopsie like use after free.
`-fno-omit-frame-pointer` has been useful for profiling using perf.
If you're on Mac with Xcode, the static analyzer and the sanitizers ASAN, UBSAN and TSAN are simple UI checkboxes.
scan-build makeThat being said, codechecker is not that great in terms of it's interface. Over all, it really needs to be implemented in a GUI application as there are many many fine tuning flags you can set with the clang analyzer (as well as potential for parallelization) that either cant be taken advantage of, or is too cumbersome to use codechecker to do.
https://codechecker.readthedocs.io/en/latest/analyzer/user_g...
I noticed that codechecker can also ingest results from many different tools other than Clang:
https://codechecker.readthedocs.io/en/latest/supported_code_...
The article mentions the address sanitizer keeps track of allocations and their sizes. I wrote my own allocator, how do I integrate it with the sanitizer? I added malloc attributes to all allocation functions but they don't seem to do anything.
In those functions, you need to implement the sanitizer yourself, and have it panic if it detects an invalid access (address sanitizers are usually implemented with shadow memory). You'll have to give your sanitizer enough shadow memory during initialization, and also add your own alloc/free sanitizer callbacks to your allocator (so the sanitizer knows when things are allocated/freed).
I have an example [1] that implements a basic ASAN and UBSAN in a kernel (it's written in D, but could be easily adapted to C or C++). Hopefully it's helpful!
[1]: https://github.com/zyedidia/multiplix/blob/master/kernel/san...
https://mcuoneclipse.com/2021/05/31/finding-memory-bugs-with...
https://interrupt.memfault.com/blog/ubsan-trap
I've tested the UBSan, it worked with some limitations but helped me catch some old hidden bugs.
if (4 < x) {
if (x < y) {
if (y == 0) {
// Unreachable since the above three conditions cannot
// all be true at the same time (without multithreading).
}
}
}
For a more detailed explanation, see [2]. (Also the inspiration for the above example.)[1] https://en.m.wikipedia.org/wiki/Transitive_relation
[2] https://github.com/gcc-mirror/gcc/commit/50ddbd0282e06614b29...
clang --analyze $(SRC_WITHOUT_SQLITE) $(shell cat compile_flags.txt | tr '\n' ' ') -I$(shell pg_config --includedir) -Xanalyzer -analyzer-output=text -Xanalyzer -analyzer-checker=core,deadcode,nullability,optin,osx,security,unix,valist -Xanalyzer -analyzer-disable-checker -Xanalyzer security.insecureAPI.DeprecatedOrUnsafeBufferHandling