HNHacker News
TopNewBestAskShowJobs

AndreyKarpov

4,144 karma · joined February 11, 2011

Andrey Karpov. DevRel. Andrey Karpov is a co-founder of PVS-Studio — the company that is developing the PVS-Studio static code analyzer. The tool is designed for early detection of errors and potential vulnerabilities in C, C++, C#, and Java projects.

Andrey is the author of many publications devoted to writing quality C++ code.

Articles published in the company's blog: https://pvs-studio.com/en/blog/posts/?author=andrey-karpov

submissionscomments
AndreyKarpov··on 30 years ago, Doom was released
30 years of DOOM: new code, new bugs - https://pvs-studio.com/en/blog/posts/cpp/1087/
AndreyKarpov··on .NET 8
What's new in .NET 8? - https://pvs-studio.com/en/blog/posts/csharp/1080/
AndreyKarpov··on Collecting the Best C++ Practices
Please list your style guide recommendations
AndreyKarpov··on What's New in C# 11
What's new in C# 11: overview - https://pvs-studio.com/en/blog/posts/csharp/1002/
AndreyKarpov··on LLVM 13.0
Detecting errors in the LLVM release 13.0.0 - https://pvs-studio.com/en/blog/posts/cpp/0871/
AndreyKarpov··on Everybody makes mistakes when writing comparison functions
I agree, it’s a bit of one-sided point of view. It’s only about the code quality. The cryptography analysis is beyond static analysis tools’ capabilities. Static analysis is more high-level study.
AndreyKarpov··on Everybody makes mistakes when writing comparison functions
Integration of a static analyzer into an existing project may be hard. Especially if the project is big and old. In fact, it’s not as scary as it seems to be. There are ways to do it as easy as possible: How to introduce a static code analyzer in a legacy project and not to discourage the team - https://pvs-studio.com/en/blog/posts/0743/
AndreyKarpov··on Everybody makes mistakes when writing comparison functions
The main specific is that it’s one of the most common errors. People don’t check comparison functions, but those functions have errors. You can read more here: https://pvs-studio.com/en/blog/posts/cpp/0509/
AndreyKarpov··on Everybody makes mistakes when writing comparison functions
Unfortunately, I don't fully understand your comment. PVS-Studio has a variety of diagnostics. However, such simple errors still exist. By the way, PVS-Studio found errors in IntelliJ IDEA as well :) - https://pvs-studio.com/en/blog/posts/java/0603/
AndreyKarpov··on What computer and software is used by the Falcon 9? (2015)
> The flight software is written in C/C++

I wish we could check the source code using the PVS-Studio analyzer to see what we can find out there :). It would be more interesting than these standard articles on project checks.

AndreyKarpov··on How Can Developers Help Fight Coronavirus?
How Can Developers Help Fight Coronavirus - Continuation: https://www.viva64.com/en/b/0717/
AndreyKarpov··on VVVVVV’s source code is now public, 10 year anniversary jam happening now
The PVS-Studio Team couldn't get past the source code of this game: https://www.viva64.com/en/b/0707/
AndreyKarpov··on Use PVS-Studio to get students familiar with code analysis tools
https://habr.com/en/company/pvs-studio/blog/470069/
AndreyKarpov··on macOS Catalina
A Collection of Examples of 64-bit Errors in Real Programs: https://www.viva64.com/en/a/0065/
AndreyKarpov··on Announcing .NET Core 3.0 Preview 8
Checking the .NET Core Libraries Source Code by the PVS-Studio Static Analyzer - https://www.viva64.com/en/b/0656/
AndreyKarpov··on Best Copy-Paste Algorithms for C and C++. Haiku OS Cookbook
And "How to shoot yourself in the foot in C and C++. Haiku OS Cookbook" - https://www.viva64.com/en/b/0644/
AndreyKarpov··on Counting Bugs in Windows Calculator
The last check was in 2016: https://www.viva64.com/en/b/0446/ . Yes, it was few years ago because we were not interested in writing the same articles again and again. There are a lot of other interesting projects in the world: https://www.viva64.com/en/inspections/ . I also want to note that you assume that Clang was worse than PVS-Studio long time ago but now it can catch up. To that, I will say that all these years we’ve been working on analyzer development :). By the way, here is where you can read about the way it works: "Technologies used in the PVS-Studio code analyzer for finding bugs and potential vulnerabilities" - https://www.viva64.com/en/b/0592/
AndreyKarpov··on Counting Bugs in Windows Calculator
PVS-Studio vs Compilers:

Clang: https://www.viva64.com/en/b/0108/ , https://www.viva64.com/en/b/0155/ , https://www.viva64.com/en/b/0446/

GCC: https://www.viva64.com/en/b/0425/

AndreyKarpov··on In January, the EU Starts Running Bug Bounties on Free and Open Source Software
PVS-Studio and Bug Bounties on Free and Open Source Software: https://medium.com/@karpov2007/pvs-studio-and-bug-bounties-o...
AndreyKarpov··on Insert PVS-Studio Comment
Link: https://marketplace.visualstudio.com/items?itemName=Vladysla...
AndreyKarpov··on Gentlemen, we must do something about the memset function in C++ programs
hat's wrong with "Gentlemen"? I wrote this just to attract attention.

https://en.wiktionary.org/wiki/gentlemen

AndreyKarpov··on Gentlemen, we must do something about the memset function in C++ programs
There is no reason for warning. The parameter has int type.
AndreyKarpov··on The Last Line Effect
Continue

The Evil within the Comparison Functions - https://www.viva64.com/en/b/0509/

Annotation. Perhaps, readers remember my article titled "Last line effect". It describes a pattern I've once noticed: in most cases programmers make an error in the last line of similar text blocks. Now I want to tell you about a new interesting observation. It turns out that programmers tend to make mistakes in functions comparing two objects. This statement looks implausible; however, I'll show you a great number of examples of errors that may be shocking to a reader. So, here is a new research, it will be quite amusing and scary.

AndreyKarpov··on 27000 errors in the Tizen operating system
Tizen: Summing Up - https://www.viva64.com/en/b/0522/
AndreyKarpov··on 27000 errors in the Tizen operating system
Continue. Exploring Microoptimizations Using Tizen Code as an Example - https://www.viva64.com/en/b/0520/
AndreyKarpov··on 27000 errors in the Tizen operating system
This is not the way you think and it is not nice to mislead people. It all depends on the project.

I've heard people who said that Coverity gives many false positives and Cppcheck gives few. I've heard the opposite, that it is impossible to use Cppcheck because of the huge number of false positives, but Coverity is doing great. I heard that Coverity gives more false positives than PVS-Studio. And vice versa. And so on and so forth. What is the reason for such differences?

Projects have their certain styles of writing and different kinds of macros. These are macros and peculiarities of style that become the main source of false positives. This is why the first impression of using the analyzers of code depends on luck, and not on the coolness of the analyzer. If the analyzer doesn’t like a self-made my_assert() it will issue 10000 false positives.

So there is no point in talking abstractly about the number of false positives. Yes, you can not get lucky and there can be a lot of false positives. However, the static code analyzers allow you to configure them. In articles I have showed many times that the simplest configuration of the analyzer can greatly reduce the number of false positives. Example: https://www.viva64.com/en/b/0496/#ID0ENNAC

AndreyKarpov··on 27000 errors in the Tizen operating system
I think you do not follow our articles carefully :). We have a lot of diverse publications in the our blog: https://www.viva64.com/en/b/

Including, describing the product. For example:

PVS-Studio as a plugin for SonarQube - https://www.viva64.com/en/b/0513/

Support of Visual Studio 2017 and Roslyn 2.0 in PVS-Studio: sometimes it's not that easy to use ready-made solutions as it may seem - https://www.viva64.com/en/b/0503/

The way static analyzers fight against false positives, and why they do it - https://www.viva64.com/en/b/0488/

Why I Dislike Synthetic Tests - https://www.viva64.com/en/b/0471/

Integrating PVS-Studio into Eclipse CDT (Linux) - https://www.viva64.com/en/b/0458/

Integrating PVS-Studio into Anjuta DevStudio (Linux) - https://www.viva64.com/en/b/0459/

Issues we faced when renewing PVS-Studio user interface - https://www.viva64.com/en/b/0450/

and so on

I can also offer a presentation: PVS-Studio static code analyzer for C, C++ and C# (2017) - https://youtu.be/kmqF130pQW8

AndreyKarpov··on 27000 errors in the Tizen operating system
The reason for this is described in the article "How to find 56 potential vulnerabilities in FreeBSD code in one evening": https://www.viva64.com/en/b/0496/#ID0ENNAC . There it is told that this is not scary and the analyzer settings can be customized.
AndreyKarpov··on 27000 errors in the Tizen operating system
> If they're not building with -Wall -Wextra -Werror, are they really going to make use of PVS-Studio's output?

This is very likely. Do not forget that the static analyzer is not just a warning. This is also the infrastructure.

For example, PVS-Studio is:

- Saving and loading analysis results allow doing overnight checks - during the night the analyzer does the scanning and provides you with the results in the morning.

- Interactive filtering of the analysis results (the log file) in the PVS-Studio window: by the diagnostic number, file name, the keyword in the text of the diagnostic.

- BlameNotifier utility. The tool allows you to send e-mail notifications to the developers about bugs that PVS-Studio found during a night run.

- Mass Suppression - ability to suppress all old messages raised for the legacy code, so that the analyzer reports 0 warnings. You can always go back to the suppressed messages later. This feature allows you to seamlessly integrate PVS-Studio into your development process and focus on errors found in new code only. Details: https://www.viva64.com/en/m/0032/

- Relative paths in report files to view them on different machines.

- CLMonitoring feature allows analyzing the projects that have no Visual Studio files (.sln/.vcxproj); in case the CLMonitoring functionality is not enough, there is a possibility to integrate PVS-Studio in a Makefile-based build system manually.

- pvs-studio-analyzer - a utility similar to CLMonitoring, but working under Linux.

- Possibility to exclude files from the analysis by name, folder or mask; to run the analysis on the files modified during the last N days.

- Integration with SonarQube. It is an open source platform, designed for continuous analysis and measurement of code quality.

- and so on

AndreyKarpov··on 27000 errors in the Tizen operating system
> They don't have prices on the web site

This is standard practice. PVS-Studio is a B2B solution. There are many details to be discussed.

For individual developers we propose the following: "How to use PVS-Studio for Free" - https://www.viva64.com/en/b/0457/

And "Handing out PVS-Studio Analyzer Licenses to Security Experts" - https://www.viva64.com/en/b/0510/

Page 1 of 5Next →