Code change influence range evaluation method, device and system and medium
By performing call chain analysis and code change analysis on the target project, a project call chain diagram is generated, which solves the problems of low coverage, low accuracy and high R&D cost in the existing technology, provides an intuitive analysis report, and improves the comprehensiveness and accuracy of code change impact assessment.
Patent Information
- Application Number
- CN202510799849.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-10-31
AI Technical Summary
Existing technologies for assessing the impact of code changes suffer from problems such as low coverage, low accuracy, poor intuitiveness, and high R&D costs.
By performing call chain analysis on the target project to generate a project call chain diagram, and combining it with code change analysis, the changed functions and their affected call chains are identified. An analysis report is generated by using a combination of static and dynamic call chain analysis methods.
It achieves comprehensive and accurate analysis of the impact of code changes, provides intuitive analysis reports, reduces R&D costs, and improves work efficiency.
Smart Images

Figure CN120872303A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of software development, and more particularly to a method, apparatus, system, and medium for assessing the impact of code changes. Background Technology
[0002] Code changes are a constant presence in the iterative development of a software system. Without code changes, the software system would gradually lose its vitality and value. However, as the software system continuously changes and iterates, the amount of code also increases, and the risk of each iteration gradually rises. Therefore, avoiding the software risks caused by iterative changes becomes particularly important. Currently, some publicly available solutions include the following:
[0003] Static code analysis tools analyze source code to assess the potential impact of code changes. They typically do not rely on the code being run and are primarily used to analyze critical syntactic errors in the code.
[0004] Dynamic analysis and automated testing use probe technology to dynamically trace code during runtime, analyze code calls, and then automated testing tools help assess the actual impact of code changes on the system.
[0005] Code dependency analysis tools use static code analysis to obtain the call relationships between modules, thereby determining whether a code change will affect other modules or functions.
[0006] Version control and change logs analyze the history of the version control system to assess the scope of code changes and identify which files or modules may be affected.
[0007] In the process of developing this invention, the applicant discovered at least the following problems in the prior art:
[0008] Existing technologies suffer from problems such as low coverage, low accuracy, poor intuitiveness, and high R&D costs. Summary of the Invention
[0009] This invention provides a method, apparatus, system, and medium for assessing the impact of code changes, in order to address the problems of low coverage, low accuracy, poor intuitiveness, and high R&D costs in existing technologies.
[0010] To achieve the above objectives, firstly, such as Figure 1 As shown, this embodiment of the invention provides a method for assessing the impact of code changes, including:
[0011] Perform call chain analysis on the target project to obtain at least one function call relationship, and generate a project call chain diagram from the at least one function call relationship;
[0012] Perform code change analysis on the target project to identify at least one function that has undergone code changes;
[0013] For each function that has undergone code changes, at least one call chain containing the function with the code changes is retrieved from the project call chain graph as the corresponding affected call chain, and an analysis report is generated based on all affected call chains; wherein, the affected call chain is the call chain from the external API interface of the target project to the changed function;
[0014] The target project includes multiple source code files, each containing functions; the project call chain diagram indicates the call relationship between each function in the target project and its respective called functions.
[0015] Secondly, embodiments of the present invention provide an impact assessment device for code changes, comprising:
[0016] The project call chain diagram generation unit is used to perform call chain analysis on the target project to obtain at least one function call relationship, and generate a project call chain diagram from the at least one function call relationship;
[0017] The function change determination unit is used to perform code change analysis on the target project and determine at least one function that has undergone code change;
[0018] The analysis report generation unit is used to, for each function that has undergone code changes, retrieve at least one call chain in the project call chain graph where the function with code changes is located, as the corresponding affected call chain, and generate an analysis report based on all affected call chains; wherein, the affected call chain is the call chain from the external API interface of the target project to the function with changes;
[0019] The target project includes multiple source code files, each containing functions; the project call chain diagram indicates the call relationship between each function in the target project and its respective called functions.
[0020] Thirdly, embodiments of the present invention provide a code change impact assessment system, characterized in that it includes: a code change impact assessment device as described above, a copy server, an online server, and a project code repository.
[0021] Fourthly, embodiments of the present invention provide a readable storage medium storing program code for implementing the method as described in any of the preceding methods.
[0022] The above technical solution offers the following advantages: By analyzing the call chain, function call relationships are discovered, and a project call chain diagram is generated, thus obtaining the complete function call relationships of the target project. Combined with code change analysis of the target project, the call chains affected by the changed functions can be determined, ensuring the comprehensiveness and accuracy of the change impact analysis. The affected call chains are provided to developers in the form of reports, making the analysis more intuitive. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a flowchart of a method for assessing the impact of code changes, one of the embodiments of the present invention;
[0025] Figure 2 This is a schematic diagram of the architecture of a code change impact assessment device according to one embodiment of the present invention;
[0026] Figure 3 This is a schematic diagram of the architecture of a code change impact assessment system, one of the embodiments of the present invention;
[0027] Figure 4 This is another flowchart of a code change impact assessment method according to one embodiment of the present invention;
[0028] Figure 5 This is a call chain diagram corresponding to the call relationship of example code in one embodiment of the present invention. Detailed Implementation
[0029] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0030] On the one hand, such as Figure 1 As shown, this embodiment of the invention provides a method for assessing the impact of code changes, including:
[0031] Step S10: Perform call chain analysis on the target project to obtain at least one function call relationship, and generate a project call chain diagram from the at least one function call relationship;
[0032] Step S11: Perform code change analysis on the target project to identify at least one function that has undergone code changes;
[0033] Step S12: For each function that has undergone code changes, retrieve at least one call chain in the project call chain graph where the function with the code changes is located, as the corresponding affected call chain, and generate an analysis report based on all affected call chains; wherein, the affected call chain is the call chain from the external API interface of the target project to the changed function;
[0034] The target project includes multiple source code files, each containing functions; the project call chain diagram indicates the call relationship between each function in the target project and its respective called functions.
[0035] The static call chain analysis is used to analyze the function call relationships explicitly recorded in the source code of the code file;
[0036] Dynamic call chain analysis is used to analyze the call relationships between functions at runtime.
[0037] In some embodiments, call chain analysis is used to discover the call relationships between functions within the target project and generate a project call chain diagram. This project call chain diagram can be used to query the call relationships between functions in the target project, such as the functions that call the function and the functions that the function calls. Furthermore, based on the parent-child relationships between nodes in the project call chain diagram, the call chain can be traversed from the changed function all the way to the outermost external API interface of the target project, thereby obtaining a function call chain containing the changed function. This can automatically, accurately, and quickly determine which part of the target project is affected by the changed function.
[0038] The embodiments of this invention have the following technical effects: By analyzing the call chain, function call relationships are discovered, and a project call chain diagram is generated, thereby obtaining the complete function call relationships of the target project. Combined with code change analysis of the target project, the call chain affected by the changed functions can be determined, ensuring the comprehensiveness and accuracy of the change impact analysis. The affected call chains are provided to developers in the form of reports, making it more intuitive.
[0039] Furthermore, the step of performing call chain analysis on the target project to obtain at least one function call relationship, and generating a project call chain graph from the at least one function call relationship, specifically includes:
[0040] Obtain source code files for static call chain analysis from the project code repository of the target project, perform static call chain analysis on the target project based on the obtained source code files to obtain at least one function call relationship, and generate a project call chain graph from the at least one function call relationship;
[0041] And / or,
[0042] Traffic replay is performed on a pre-deployed replica server of the target project. Based on the traffic replay, dynamic call chain analysis is performed on the target project to obtain at least one function call relationship. The at least one function call relationship is then used to generate a project call chain graph.
[0043] In some embodiments, static call chain analysis can discover explicit or static function call relationships in the source code. The source code used for static call chain analysis can be pulled from the project code repository, thus eliminating the need to directly analyze the source code on the online server. For example:
[0044]
[0045]
[0046] During static call analysis, by matching the format or markers that constitute the function definition, the start and end of the function definition can be identified from the source code file, as well as which called functions exist inside each function. In the example above, through static analysis, it can be determined that FuncA calls FuncB, and FuncB calls FuncC.
[0047] Static call analysis can reveal explicit or static function call relationships in the source code, but it cannot determine dynamic call relationships, such as function calls using function pointers as formal parameters, or dynamic method calls in PHP using magic methods (such as call(), callStatic()), mutable method calls (such as $methodName()), and dynamic class loading (such as class_exists()). For example, FuncC dynamically calls FuncD through $methodName(). The above dynamic method calls will bypass static resolution, leading to missing call chains or misjudgments.
[0048] By replaying traffic on a pre-deployed replica server of the target project, dynamic call chain analysis is performed on the target project to obtain function call relationships. This allows the discovery of dynamic call relationships between functions that can only be determined at runtime. Specifically, the (static and dynamic) call relationships between functions recorded in logs or debugging information during traffic replay can be used to obtain dynamic call relationships that can only be determined at runtime. The function call relationships obtained from the dynamic call chain analysis are then used to generate a project call chain graph.
[0049] When only statically called functions are of interest, static call analysis can be performed alone; similarly, when only dynamic calls are of interest, dynamic call analysis can be performed alone. Preferably, combining static and dynamic call chain analysis ensures the integrity of function call relationships in the graph database. Code change analysis is performed on the target project to identify the changed functions. Specifically, the code before and after the change in the target project is compared to determine the changed functions. In the project call chain graph, the call chain from the target project's external API interface to the changed functions is identified, thus determining the affected call chains and generating a corresponding report.
[0050] The embodiments of this invention have the following technical effects: Static or dynamic call relationships can be efficiently discovered through static or dynamic call chain analysis, or a combination of both, thereby obtaining the complete function call relationships of the target project and ensuring the comprehensiveness and accuracy of change impact analysis. The discovered function call relationships are used to generate a project call chain graph for efficient traversal of the call chains affected by the changed functions. Furthermore, the source code for static call chain analysis comes from the project code repository, and dynamic call chain analysis uses a copy server; neither involves access to the online server and does not affect the online server's external service provision, allowing for parallel and independent operation with the online service. The affected call chains are provided to developers in report form, providing a more intuitive understanding.
[0051] Further, the step of obtaining source code files for static call chain analysis from the target project's code repository, performing static call chain analysis on the target project based on the obtained source code files to obtain at least one function call relationship, and generating a project call chain graph from the at least one function call relationship includes:
[0052] Obtain the latest version of the source code file of the target project from the main branch of the target project's project code repository;
[0053] For each function in the source code file within the preset range set in the latest version source code file, examine the source code of the function to determine each called function within the function, and obtain the calling relationship between the function and each called function;
[0054] A directed edge is established between each function and each of its called functions to obtain the project call chain graph, where each node in the project call chain graph corresponds to a unique function.
[0055] In some embodiments, for each function in a preset range of source code files set in the latest version source code file, the source code of the function is examined to determine each called function within the function, and the calling relationship between the function and each called function is obtained, specifically including:
[0056] For each PHP file in the latest version of the source code files, the source code of the PHP file is split according to PHP tags; PHP tags include: class start and end marks, method (function) start and end marks, file start and end marks, and variable tags, etc.
[0057] The system matches PHP tags line by line, filtering out assignment operators, annotations, comments, string syntax, etc., and retaining only the tags corresponding to namespaces, classes, and functions. It also writes key information such as the file path and line number where the function is declared into the project call chain diagram, generates a node in the project call chain diagram as the node corresponding to the function, and sets the namespace name + class name + function name corresponding to the function as the unique identifier of the node corresponding to the function.
[0058] For the called function (called function) found and matched in the function, firstly, based on the unique identifier of the node in the project call chain graph, it is checked whether the called function already exists in the project call chain graph. If the called function already has a corresponding node in the project call chain graph, then a directed edge is established between the node corresponding to the function and the node corresponding to the called function, as the directed edge of the call relationship between the function and the called function. If the called function does not have a corresponding node in the project call chain graph, then a node corresponding to the called function is created in the project call chain graph, and then a directed edge is established between the node corresponding to the function and the node corresponding to the called function.
[0059] Perform the above steps on each PHP file in the latest version of the source code until all PHP files have been analyzed. Once the project call chain diagram is complete, the project call chain diagram will be established.
[0060] Furthermore, before generating the project call chain graph from the at least one function call relationship by performing static call chain analysis on the target project based on the obtained source code file, the method further includes:
[0061] In response to submitting an update to the main branch of the target project's code repository, all files in the latest version of the source code files in the main branch of the target project's code repository are set as the preset range of source code files, and static call chain analysis of the target project is automatically triggered; or,
[0062] In response to the operation of setting the preset range of source code files in the main branch of the project code repository of the target project, a static call chain analysis of the target project is triggered.
[0063] In some embodiments, an automatic mode can be implemented, triggering static call chain analysis based on changes to the project code repository. For example, by configuring a CI / CD process (Continuous Integration / Continuous Delivery or Continuous Deployment) in the project code repository, a re-analysis of the project's call chain is triggered when a new code branch is committed to the main branch. Alternatively, a manual mode can be configured, for example, by using a script to perform call chain analysis on a specified branch of the target project. Specific configuration details include, but are not limited to: setting environment variables, specifying the project repository address, specifying the branch name of the project development branch, specifying the report sending email address, and transmitting the information to the monitoring system.
[0064] The embodiments of the present invention have the following technical effects: By configuring the CI / CD process in the project code repository, static call chain analysis is automatically triggered after committing updates or merging branches according to the CI / CD process, thus achieving automation without human intervention, reducing procedural tasks, allowing developers to focus more on improving project functions, reducing labor costs, and improving work efficiency, while retaining the manual mode to facilitate developers to perform change analysis at any time.
[0065] Furthermore, the target project is a PHP-based project;
[0066] The step of replaying traffic on a pre-deployed replica server of the target project, performing dynamic call chain analysis on the target project based on the traffic replay to obtain at least one function call relationship, and generating a project call chain graph from the at least one function call relationship includes:
[0067] Enable the tracing function of the Xdebug debugger for PHP programs on the replica server;
[0068] Obtain online access logs from the online server used to provide online business services, and obtain access requests received by the online server from the online access logs;
[0069] The access request is sent to the replica server to trigger the trace function to generate a trace file for the access request.
[0070] For each trace file, analyze at least one call hierarchy relationship between each function recorded in the trace file and each called function within the function, establish directed edges for the call relationship between each function and each called function, and obtain the project call chain graph, where each node in the project call chain graph corresponds to a unique function;
[0071] The replica server pre-deploys an image corresponding to the latest version of the source code file of the target project in the main branch of the project code repository.
[0072] In some embodiments, the following is an example of a trace file:
[0073]
[0074] Trace files express the function call process recorded by Xdebug's trace function at runtime through the compacted hierarchy formed by the "->" mark. As shown in the example, main calls functionA, functionA calls functionB, thus driving the call chain main->functionA->functionB.
[0075] Before dynamic call chain analysis, the Xdebug tracing function of PHP on the replica server is first enabled. Online access logs are retrieved from the online server, and access requests received by the online server are extracted from these logs. These access requests are then sent to the replica server to call the entry point of the project function, achieving traffic replay. During traffic replay, the tracing function records the function call process to a trace file. For each trace file, the at least one call hierarchy relationship between each function recorded in the trace file and each called function within that function is analyzed. Directed edges are established between each function and each called function, resulting in the project call chain graph. Each node in the project call chain graph corresponds to a unique function, specifically including:
[0076] For each trace file, analyze the indentation level line by line, and use regular expressions to match the call level, namespace name, class name, function name, file path, and line number corresponding to each function in the trace file;
[0077] Based on the unique identifier consisting of the namespace name, class name, and function name of each function at each level, determine whether there is a corresponding node in the project call chain graph for each function at each level.
[0078] For functions that do not have a corresponding node in the project call chain graph, the file path and line number information corresponding to the function are written into the project call chain graph to generate the node corresponding to the function, and the unique identifier consisting of the namespace name, class name and function name corresponding to the function is used as the unique identifier of the node corresponding to the function.
[0079] Based on the call hierarchy of each function in the trace file, the call relationship between each function is determined. Based on the call relationship between each function, directed edges are created between the nodes corresponding to each function in the graph database as directed edges for the call relationship between the function and the called function.
[0080] The embodiments of this invention have the following technical effects: By enabling the PHP Xdebug tracing function on the replica server, dynamic function calls can be traced without affecting the online server, thereby solving the problem that static call chain analysis cannot discover dynamic function call relationships. Furthermore, through online replay, the call process on the online server can be simulated to the greatest extent, enabling more timely detection of online issues and accurate comprehensive coverage of the online call process. The embodiments of this invention do not use probes because probes monitor at a coarser granularity than Xdebug; Xdebug can reach the function level, while most probes can only reach the transaction level.
[0081] Furthermore, the step of performing code change analysis on the target project to identify at least one function that has undergone code changes includes:
[0082] Using a code difference comparison tool, the latest version source code file and the second newest version source code file in the main branch of the target project's code repository are compared to determine the files in the latest version source code file that have undergone code changes relative to the second newest version source code file, and the corresponding line ranges in which the code changes have occurred.
[0083] For each file where code changes have occurred, the function containing the corresponding line range where the code changes have occurred is identified by recognizing the function start and end markers.
[0084] In some embodiments, the code difference comparison tool can be a built-in difference comparison tool of the project code repository, such as git diff, or other third-party source code or text comparison tools. After determining the scope of the code changes, the start and end markers of the functions can be used to determine whether the changes occur within the scope of the corresponding functions. If they do, it means that the corresponding function has been changed; otherwise, no change has occurred, thus identifying the function that has been changed.
[0085] Furthermore, for each function that has undergone code changes, at least one call chain containing the function with the code changes is retrieved from the project call chain graph as the corresponding affected call chain, and an analysis report is generated based on all affected call chains, including:
[0086] For each function that has undergone code changes, the function with the changed code is located in the project call chain graph, and the directed edges pointing to the function with the changed code are traversed upwards until at least one highest parent of the project call chain graph is reached; the highest parent is the external API interface of the target project.
[0087] At least one call chain from the at least one highest parent to the function whose code has been changed is defined as the affected call chain corresponding to the function whose code has been changed;
[0088] The analysis report is generated by plotting all affected call chains.
[0089] In some embodiments, the modified function is located in the project call chain graph. Based on the directed edges between functions and called functions already established in the project call chain graph, a reverse upward traversal is performed. This allows all parent functions that directly or indirectly call the modified function to be traversed. The call chain from the highest parent function to the modified function is then plotted as a directed graph, serving as an analysis report. This report visually shows the call chain affected by the modified function. Since the highest parent function typically corresponds to the target project's external request interface, the business requests affected by the modified function can be identified. This facilitates developers and testers in conducting targeted and comprehensive testing of the business affected by the change, minimizing the testing scope and improving operational efficiency.
[0090] Secondly, such as Figure 2 As shown, an embodiment of the present invention provides an impact assessment device for code changes, comprising:
[0091] The project call chain diagram generation unit 200 is used to perform call chain analysis on the target project to obtain at least one function call relationship, and generate a project call chain diagram from the at least one function call relationship;
[0092] The function change determination unit is used to perform code change analysis on the target project and determine at least one function that has undergone code change;
[0093] The analysis report generation unit 201 is used to retrieve at least one call chain in the project call chain graph for each function that has undergone code changes, as the corresponding affected call chain, and generate an analysis report based on all affected call chains; wherein, the affected call chain is the call chain from the external API interface of the target project to the changed function;
[0094] The target project includes multiple source code files, each containing functions; the project call chain diagram indicates the call relationship between each function in the target project and its respective called functions.
[0095] Furthermore, the project call chain diagram generation unit 200 includes:
[0096] A static call chain generation module is used to obtain source code files for static call chain analysis from the target project's code repository, perform static call chain analysis on the target project based on the obtained source code files to obtain at least one function call relationship, and generate a project call chain graph from the at least one function call relationship; and / or,
[0097] The dynamic call chain generation module is used to perform traffic replay on a pre-deployed replica server of the target project, perform dynamic call chain analysis on the target project based on the traffic replay to obtain at least one function call relationship, and generate a project call chain graph from the at least one function call relationship.
[0098] Furthermore, the static call chain generation module includes:
[0099] The source code acquisition module is used to obtain the latest version of the source code file of the target project from the main branch of the project code repository of the target project;
[0100] The static call relationship determination module is used to examine the source code of each function in the source code file within a preset range set in the latest version source code file to determine each called function within the function, and obtain the call relationship between the function and each called function.
[0101] The first call chain graph generation module is used to establish directed edges for the call relationship between each function and each of the functions called by the function, so as to obtain the project call chain graph, wherein each node in the project call chain graph corresponds to a unique function.
[0102] Furthermore, the static call chain generation module also includes:
[0103] The first static analysis triggering module is used to respond to an update submission to the main branch of the target project's project code repository, setting all files of the latest version source code files in the main branch of the target project's project code repository as the preset range of source code files, and automatically triggering the source code acquisition module to trigger static call chain analysis of the target project; or,
[0104] The second static analysis trigger module is used to trigger the source code acquisition module to trigger static call chain analysis of the target project in response to the operation of setting the preset range of source code files in the main branch of the project code repository.
[0105] Furthermore, the target project is a PHP-based project;
[0106] The dynamic call chain generation module includes:
[0107] The tracing function enabling module is used to enable the tracing function of the Xdebug debugger for PHP programs on the replica server;
[0108] The access request acquisition module is used to acquire online access logs from the online server that provides online business services, and to acquire access requests received by the online server from the online access logs.
[0109] The access request execution module is used to initiate the access request to the replica server to trigger the trace function to generate a trace file for the access request.
[0110] The dynamic call relationship determination module is used to analyze, for each trace file, at least one call hierarchy relationship between each function recorded in the trace file and each called function called within the function;
[0111] The second call chain graph generation module is used to establish directed edges for the call relationship between each function and each of the functions called by the function, so as to obtain the project call chain graph, wherein each node in the project call chain graph corresponds to a unique function;
[0112] The replica server pre-deploys an image corresponding to the latest version of the source code file of the target project in the main branch of the project code repository.
[0113] Furthermore, the change function determination unit includes:
[0114] The difference comparison module is used to compare the latest version source code file and the second newest version source code file in the main branch of the project code repository of the target project using a code difference comparison tool, and to determine the files in the latest version source code file that have code changes relative to the second newest version source code file and the corresponding range of lines in which code changes have occurred.
[0115] The function change determination module is used to identify the function containing the line range of the code change in each file by recognizing the function start and end markers.
[0116] Furthermore, the analysis report generation unit includes:
[0117] The function traversal module is used to locate the function with code changes in the project call chain graph for each function with code changes, and traverse upwards according to the directed edges pointing to the function with code changes until at least one highest parent in the project call chain graph; the highest parent is the external API interface of the target project;
[0118] An affected call chain determination module is used to identify at least one call chain from the at least one highest parent to the function whose code has been changed as the affected call chain corresponding to the function whose code has been changed.
[0119] The analysis report generation module is used to plot all affected call chains and generate the analysis report.
[0120] The embodiments of the present invention are device-type embodiments that correspond one-to-one with the foregoing method embodiments. The embodiments of the present invention can be understood based on the foregoing method embodiments, and will not be repeated here.
[0121] Thirdly, such as Figure 3 As shown, this embodiment of the invention provides a code change impact assessment system, including: a code change impact assessment device 300 as described above, a replica server 301, an online server 302, and a project code repository 303. The code deployed on the online server 302 can be an older version than the code version in the project code repository 303 or the same version as the code version on the replica server 301.
[0122] The embodiments of the present invention are embodiments of the code change impact assessment system constituted by the foregoing device embodiments. The embodiments of the present invention can be understood based on the foregoing device embodiments, and will not be repeated here.
[0123] Fourthly, embodiments of the present invention provide a readable storage medium storing program code for implementing the method as described in any of the preceding descriptions.
[0124] The technical solutions of the present invention will be described in detail below with reference to specific application examples. For technical details not described in the implementation process, please refer to the relevant descriptions above.
[0125] The inventors discovered that, in terms of coverage and accuracy, static code analysis and code dependency analysis can typically only identify static dependencies between code segments, failing to identify runtime dependencies. This results in insufficient coverage, leading to incomplete and inaccurate dependency relationship displays. Regarding intuitiveness, version control and change logs can only assess the modules and functions affected by current file changes, unable to identify other modules and functions that call the affected modules. In terms of development costs, while dynamic analysis and automated testing can achieve full coverage of the chain through exhaustive enumeration, the manual writing of automated tests significantly increases development manpower costs, hindering rapid system iteration. Furthermore, the accuracy of test cases can also affect code accuracy.
[0126] This invention summarizes and combines the above-mentioned solutions, providing a more comprehensive, accurate, and intuitive solution with lower development costs, thus improving the ability of testing and development teams to perceive code changes. This invention can be automated according to fixed standards and processes, reducing the risk of errors and omissions, and lowering human resource costs. This invention can be deployed in isolation from business systems, thereby improving the usability of code change impact assessment, automatically updating the call chain relationships between project modules, and facilitating impact assessment coverage after code iteration. It automatically identifies affected modules and further matches them with relevant call entry points, automatically generating impact assessment reports, facilitating analysis and supplementation of test cases by testing and development personnel, and improving development and testing efficiency. In summary, this tool can easily complete the impact assessment of PHP code changes, and has broad practical significance for development and test coverage work.
[0127] Some embodiments provide a method, apparatus, system, and medium for assessing the impact of code changes. When applying these embodiments to a PHP code project, the embodiments of the present invention provide a method, apparatus, system, and medium for assessing the impact of PHP code changes. Figure 4 As shown, the specific implementation of the code change impact scope assessment in this embodiment of the invention is as follows:
[0128] Step 1: Generate the project call chain diagram
[0129] The first step in working on a code modification impact assessment system is to establish a call chain diagram, which can be done automatically or manually.
[0130] 1. Automatic mode: The CI / CD process, i.e., Continuous Integration / Continuous Delivery or Continuous Integration / Continuous Deployment, is configured in the project code repository. When a new code branch is committed to the main branch, a re-analysis of the project call chain is triggered.
[0131] 2. Manual mode: Perform call chain analysis on specified projects and branches using scripts.
[0132] Set environment variables, specify the project repository address, specify the branch name of the project development branch, and specify the email address to send reports to.
[0133] Transmit the information to the monitoring system.
[0134] Call chain analysis can take two forms: static and dynamic.
[0135] 1. Working principle of static analysis:
[0136] a. Split the source code in the PHP file according to PHP tags. PHP tags include: class, method, file start and end marks, variable tags, etc.
[0137] b. Match PHP tags line by line, filter out assignment operators, annotations, comments, string syntax, etc., and keep only namespace, class, function and other tags. Write the file path, line number and other key information of the function declaration into the graph database as a node of the graph database, and set the namespace + class + function as the unique identifier of this node.
[0138] c. For the called function found and matched within the function database, first check if the called function already exists in the graph database based on the unique identifier of each node. If it exists, a directed edge is created between the calling node and the called node. If it does not exist, the called node is created in the graph database first, and then the directed edge between the calling node and the called node is created. All functions in the current file are directly written to the database. Partial information of the called function is written first, and then the information of the called function is completed in the graph database after traversing the definition and declaration files where the called function is located.
[0139] d. Perform the above steps for each PHP file until all PHP files in the project have been analyzed, at which point the project's call chain diagram will be established.
[0140] 2. Working principle of dynamic analysis:
[0141] a. Enable the Xdebug trace feature in PHP.
[0142] b. Call the entry point for the project function.
[0143] c. Analyze the trace file line by line, using regular expressions to match the call level, class and object, function, file path, and line number. Use the class and object plus function as the unique identifier for a node in the graph database and write it into the graph database as a node.
[0144] d. Bind the relationship between the current level node and the parent level node, and establish a directed edge from the parent level node to the current level node.
[0145] e. Repeat the above steps for each trace file to complete the establishment of the project's call chain.
[0146]
[0147] Step 2: Code Change Analysis
[0148] Code change analysis supports both manual and automatic modes:
[0149] 1. Manual: Specify the source branch (development branch) and the destination branch (main branch) for full project analysis, or add a specified file path to analyze only specified files.
[0150] 2. Automatic: Automatically triggered by CI / CD when a branch or merge request is submitted, analyzing all change files in the project.
[0151] How code change analysis works:
[0152] 1. Use `git diff` to find all files and lines affected by code changes, and locate the lines of code that were modified.
[0153] 2. Through static analysis, identify the affected functions, classes, and objects by analyzing the affected files and lines of code. Locate the modified function within the changed lines of code. Determine if the modified line falls within the function's defined scope.
[0154] Step 3: Call Link Analysis and Report Generation
[0155] The classes, objects, and functions analyzed in the second step are used to find all related highest-level parent nodes in the graph database and generate an analysis report.
[0156] Analysis report delivery method: Email
[0157] Step 4: Update the project call chain
[0158] Once the code merge request is merged, the first step of generating the project call chain diagram is automatically triggered to update the project call chain.
[0159] For example, consider the following code snippet:
[0160] P1.php file:
[0161]
[0162] P2.php file:
[0163]
[0164] Called.php file:
[0165]
[0166]
[0167] Through static call chain analysis and dynamic call chain analysis, we can obtain, for example... Figure 5 The call relationship is shown.
[0168] The embodiments of this invention have the following technical effects: They utilize a combination of static and dynamic code analysis to analyze and cover project code, effectively improving call chain coverage; they use a graph database to visualize the project's call chain, making it more intuitive; they can perform impact assessment and report generation for each code commit, and automatically update the project's call chain graph after merging the main branch. This improves code coverage and accuracy: by using both static and dynamic analysis according to fixed standards and patterns, it increases support for dynamic code methods, resulting in more comprehensive code coverage. It enhances real-time performance: it supports automatic triggering of analysis and report generation after code commit, generating a completely new analysis report for each commit. It reduces maintenance costs: only a one-time configuration of the CI / CD process is required, followed by fully automated execution, reducing the cost of manual intervention and writing test cases.
[0169] It should be understood that the specific order or hierarchy of steps in the disclosed process is an example of an exemplary method. Based on design preferences, it should be understood that the specific order or hierarchy of steps in the process may be rearranged without departing from the scope of this disclosure. The appended method claims provide elements of various steps in an exemplary order and are not intended to limit the scope to the specific order or hierarchy described.
[0170] In the above detailed description, various features are combined together in a single embodiment to simplify this disclosure. This approach to disclosure should not be construed as reflecting an intention that embodiments of the claimed subject matter require more features than are explicitly stated in each claim. Rather, as reflected in the appended claims, the invention is presented with fewer features than all of the features of the single disclosed embodiment. Therefore, the appended claims are hereby explicitly incorporated into the detailed description, wherein each claim stands alone as a preferred embodiment of the invention.
[0171] The disclosed embodiments have been described above to enable any person skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be applied to other embodiments without departing from the spirit and scope of this disclosure. Therefore, this disclosure is not limited to the embodiments given herein, but is consistent with the broadest scope of the principles and novel features disclosed in this application.
[0172] The foregoing description includes examples of one or more embodiments. It is certainly impossible to describe all possible combinations of components or methods in order to describe the above embodiments, but those skilled in the art will recognize that further combinations and arrangements of the various embodiments are possible. Therefore, the embodiments described herein are intended to cover all such changes, modifications, and variations falling within the scope of the appended claims. Furthermore, the term "comprising" as used in the specification or claims is used in a manner similar to the term "including." Additionally, the use of any term "or" in the specification of the claims is intended to mean "non-exclusive or."
[0173] Those skilled in the art will also understand that the various illustrative logical blocks, units, and steps listed in the embodiments of the present invention can be implemented by electronic hardware, computer software, or a combination of both. To clearly demonstrate the interchangeability of hardware and software, the functions of the various illustrative components, units, and steps described above have been generally described. Whether such functionality is implemented through hardware or software depends on the specific application and the overall system design requirements. Those skilled in the art can implement the described functions using various methods for each specific application, but such implementation should not be construed as exceeding the scope of protection of the embodiments of the present invention.
[0174] The various illustrative logic blocks or units described in the embodiments of this invention can be implemented or operate the described functions using a general-purpose processor, digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof. The general-purpose processor can be a microprocessor; alternatively, it can be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented using a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other similar configuration.
[0175] The steps of the methods or algorithms described in the embodiments of this invention can be directly embedded in hardware, a software module executed by a processor, or a combination of both. The software module can be stored in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium can be connected to the processor so that the processor can read information from and write information to the storage medium. Optionally, the storage medium can also be integrated into the processor. The processor and storage medium can be housed in an ASIC, which can be housed in a user terminal. Optionally, the processor and storage medium can also be housed in different components of the user terminal.
[0176] In one or more exemplary designs, the functions described in the embodiments of the present invention can be implemented in hardware, software, firmware, or any combination of these three. If implemented in software, these functions can be stored on a computer-readable medium or transmitted on a computer-readable medium in the form of one or more instructions or code. Computer-readable media include computer storage media and communication media that facilitate the transfer of computer programs from one place to another. Storage media can be any available media that can be accessed by a general-purpose or special-purpose computer. For example, such computer-readable media can include, but is not limited to, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store program code in the form of instructions or data structures and other forms that can be read by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor. Furthermore, any connection can be suitably defined as a computer-readable medium, for example, if the software is transmitted from a website, server or other remote resource via a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL) or wirelessly, such as infrared, wireless and microwave, it is also included in the defined computer-readable medium. The disks and discs mentioned include compressed disks, laser discs, optical discs, DVDs, floppy disks, and Blu-ray discs. Disks typically copy data magnetically, while disks typically copy data optically using lasers. Combinations of the above can also be contained in computer-readable media.
[0177] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for assessing the impact of code changes, characterized in that, include: Perform call chain analysis on the target project to obtain at least one function call relationship, and generate a project call chain diagram from the at least one function call relationship; Perform code change analysis on the target project to identify at least one function that has undergone code changes; For each function that has undergone code changes, at least one call chain containing the function with the code changes is retrieved from the project call chain graph as the corresponding affected call chain, and an analysis report is generated based on all affected call chains; wherein, the affected call chain is the call chain from the external API interface of the target project to the changed function; The target project includes multiple source code files, each containing functions; the project call chain diagram indicates the call relationship between each function in the target project and its respective called functions.
2. The method for assessing the impact scope of code changes as described in claim 1, characterized in that, The step of performing call chain analysis on the target project to obtain at least one function call relationship, and generating a project call chain graph from the at least one function call relationship, specifically includes: Obtain source code files for static call chain analysis from the target project's code repository; perform static call chain analysis on the target project based on the obtained source code files to obtain at least one function call relationship; and generate a project call chain graph from the at least one function call relationship; and / or, Traffic replay is performed on a pre-deployed replica server of the target project. Based on the traffic replay, dynamic call chain analysis is performed on the target project to obtain at least one function call relationship. The at least one function call relationship is then used to generate a project call chain graph.
3. The method for assessing the impact scope of code changes as described in claim 2, characterized in that, The process of obtaining source code files for static call chain analysis from the target project's code repository, performing static call chain analysis on the target project based on the obtained source code files to obtain at least one function call relationship, and generating a project call chain graph from the at least one function call relationship includes: Obtain the latest version of the source code file of the target project from the main branch of the target project's project code repository; For each function in the source code file within the preset range set in the latest version source code file, examine the source code of the function to determine each called function within the function, and obtain the calling relationship between the function and each called function; A directed edge is established between each function and each of its called functions to obtain the project call chain graph, where each node in the project call chain graph corresponds to a unique function.
4. The method for assessing the impact scope of code changes as described in claim 2, characterized in that, Before generating a project call chain graph from the at least one function call relationship by performing static call chain analysis on the target project based on the obtained source code file, the method further includes: In response to submitting an update to the main branch of the target project's code repository, all files in the latest version of the source code files in the main branch of the target project's code repository are set as the preset range of source code files, and static call chain analysis of the target project is automatically triggered; or, In response to the operation of setting the preset range of source code files in the main branch of the project code repository of the target project, a static call chain analysis of the target project is triggered.
5. The method for assessing the impact scope of code changes as described in claim 2, characterized in that, The target project is a PHP-based project. The step of replaying traffic on a pre-deployed replica server of the target project, performing dynamic call chain analysis on the target project based on the traffic replay to obtain at least one function call relationship, and generating a project call chain graph from the at least one function call relationship includes: Enable the tracing function of the Xdebug debugger for PHP programs on the replica server; Obtain online access logs from the online server used to provide online business services, and obtain access requests received by the online server from the online access logs; The access request is sent to the replica server to trigger the trace function to generate a trace file for the access request. For each trace file, analyze at least one call hierarchy relationship between each function recorded in the trace file and each called function within the function, establish directed edges for the call relationship between each function and each called function, and obtain the project call chain graph, where each node in the project call chain graph corresponds to a unique function; The replica server pre-deploys an image corresponding to the latest version of the source code file of the target project in the main branch of the project code repository.
6. The method for assessing the impact scope of code changes as described in claim 1, characterized in that, The step of performing code change analysis on the target project to identify at least one function that has undergone code changes includes: Using a code difference comparison tool, the latest version source code file and the second newest version source code file in the main branch of the target project's code repository are compared to determine the files in the latest version source code file that have undergone code changes relative to the second newest version source code file, and the corresponding line ranges in which the code changes have occurred. For each file where code changes have occurred, the function containing the corresponding line range where the code changes have occurred is identified by recognizing the function start and end markers.
7. The method for assessing the impact scope of code changes as described in claim 1, characterized in that, For each function that has undergone code changes, at least one call chain containing the function with the code changes is retrieved from the project call chain graph as the corresponding affected call chain, and an analysis report is generated based on all affected call chains, including: For each function that has undergone code changes, the function with the changed code is located in the project call chain graph, and the directed edges pointing to the function with the changed code are traversed upwards until at least one highest parent of the project call chain graph is reached; the highest parent is the external API interface of the target project. At least one call chain from the at least one highest parent to the function whose code has been changed is defined as the affected call chain corresponding to the function whose code has been changed; The analysis report is generated by plotting all affected call chains.
8. An impact assessment device for code changes, characterized in that, include: The project call chain diagram generation unit is used to perform call chain analysis on the target project to obtain at least one function call relationship, and generate a project call chain diagram from the at least one function call relationship; The function change determination unit is used to perform code change analysis on the target project and determine at least one function that has undergone code change; The analysis report generation unit is used to, for each function that has undergone code changes, retrieve at least one call chain in the project call chain graph where the function with code changes is located, as the corresponding affected call chain, and generate an analysis report based on all affected call chains; wherein, the affected call chain is the call chain from the external API interface of the target project to the function with changes; The target project includes multiple source code files, each containing functions; the project call chain diagram indicates the call relationship between each function in the target project and its respective called functions.
9. An impact assessment system for code changes, characterized in that, include: The impact assessment device for code changes, the copy server, the online server, and the project code repository as described in claim 8.
10. A readable storage medium, characterized in that, It stores program code for implementing the method as described in any one of claims 1-7.