Static Code Analysis Method, Analysis Device, Electronic Device, and Readable Storage Medium
By statically analyzing the program source code, analyzing the target package and generating method objects, the problems of code omissions and high cost of manual analysis are solved, and efficient and accurate code analysis is achieved.
Patent Information
- Application Number
- CN202110674752.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-17
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2041-06-17
AI Technical Summary
The existing technology is prone to code omissions when performing program source code analysis, and manual analysis requires understanding of the program language, which is relatively expensive to learn.
By obtaining the target package and analyzing requirements, parsing the package to obtain the method object, and performing static analysis of the method object based on the analysis requirements. Use a policy chain and multiple method parsers to identify and parse method statements, generate a method class syntax tree, and serialize the method object.
It effectively overcomes the problem that manual or dynamic code analysis is prone to code omissions, reduces the need to understand programming languages, reduces learning costs, and makes static code analysis more efficient and accurate.
Smart Images

Figure CN113377377B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the fields of computer technology and finance, and more particularly, to a static code analysis method, a static code analysis device, an electronic device, a computer-readable storage medium, and a computer program product. Background Art
[0002] As the program usage time extends, the source code of the program tends to become more and more massive, and the call situations between programs are also more complex.
[0003] In the process of implementing the concept of the present disclosure, the inventors found that both manual or dynamic code analysis are prone to code omissions, and manual code analysis requires a certain understanding of the programming language, with a relatively high learning cost. Summary of the Invention
[0004] In view of this, the present disclosure provides a static code analysis method, a static code analysis device, an electronic device, a computer-readable storage medium, and a computer program product.
[0005] One aspect of the present disclosure provides a static code analysis method, including:
[0006] Obtain a target program package and an analysis requirement, wherein the target program package includes at least one method data block, and the method data block includes at least one line of method statements for implementing a syntax function;
[0007] Parse the target program package to obtain at least one method object; and
[0008] Analyze the at least one method object based on the analysis requirement.
[0009] According to an embodiment of the present disclosure, parsing the target program package to obtain at least one method object includes:
[0010] For each method data block, use a policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree; and
[0011] Serialize the at least one method class syntax tree to obtain the method object.
[0012] According to an embodiment of the present disclosure, the policy chain includes a plurality of method parsers respectively established for each syntax function;
[0013] Wherein, using the policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree includes:
[0014] For each line of method statements, successively use the multiple above-mentioned method parsers to identify the above-mentioned method statements; and
[0015] Use the method parser that successfully identifies the above-mentioned method statements to parse the above-mentioned method statements to generate a method class syntax tree.
[0016] According to an embodiment of the present disclosure, the static code analysis method further includes:
[0017] In the case where the above-mentioned multiple method parsers cannot identify the above-mentioned method statements, construct a new method parser based on the above-mentioned method statements; and
[0018] Add the above-mentioned new method parser to the above-mentioned policy chain.
[0019] According to an embodiment of the present disclosure, the above-mentioned analysis of the above-mentioned at least one method object based on the above-mentioned analysis requirements includes:
[0020] Based on the above-mentioned analysis requirements, determine the target syntax function and judgment rules;
[0021] According to the above-mentioned target syntax function, obtain at least one line of target statements from the above-mentioned at least one method object; and
[0022] Based on the above-mentioned judgment rules, judge whether the above-mentioned at least one line of target statements is correct to complete the analysis of the above-mentioned at least one method object.
[0023] According to an embodiment of the present disclosure, the above-mentioned obtaining at least one line of target statements from the above-mentioned at least one method object according to the above-mentioned target syntax function includes:
[0024] Parse the above-mentioned at least one method object to obtain at least one function linked list;
[0025] According to the above-mentioned target syntax function, obtain the function name corresponding to the above-mentioned target syntax function from the data dictionary; and
[0026] Extract the statements containing the above-mentioned function name from the above-mentioned at least one function linked list to obtain at least one line of target statements of the above-mentioned at least one method object.
[0027] According to an embodiment of the present disclosure, the above-mentioned judging whether the above-mentioned at least one line of target statements is correct based on the above-mentioned judgment rules includes:
[0028] According to the above-mentioned target syntax function, obtain at least one judgment keyword corresponding to the above-mentioned target syntax function from the data dictionary;
[0029] For each line of target statements, extract the statement attributes of the above-mentioned target statements according to the above-mentioned at least one judgment keyword; and
[0030] Based on the above judgment rules, determine whether the statement attribute of the above target statement is correct to determine whether the above target statement is correct.
[0031] According to an embodiment of the present disclosure, the above target program package includes an EGL program package.
[0032] Another aspect of the present disclosure provides a static code analysis device, including:
[0033] An acquisition module, configured to acquire a target program package and an analysis requirement, where the target program package includes at least one method data block, and the method data block includes at least one line of method statements for implementing a syntax function;
[0034] A parsing module, configured to parse the above target program package to obtain at least one method object; and
[0035] An analysis module, configured to analyze the at least one method object based on the above analysis requirement.
[0036] Another aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more instructions, where when the one or more instructions are executed by the one or more processors, the one or more processors implement the method as described above.
[0037] Another aspect of the present disclosure provides a computer-readable storage medium storing computer-executable instructions, and the instructions are used to implement the method as described above when executed.
[0038] Another aspect of the present disclosure provides a computer program product, and the computer program product includes computer-executable instructions, and the instructions are used to implement the method as described above when executed.
[0039] According to an embodiment of the present disclosure, by means of the technical means of parsing a target program package into method objects and analyzing the method objects based on an analysis requirement, at least partially, the technical problems that both manual or dynamic code analysis are prone to code omissions, and manual code analysis requires a certain understanding of the program language and has a high learning cost are overcome. Furthermore, the technical effect of converting the analysis requirement in logical form into a static analysis rule method is achieved, so that only the correctness of the logic needs to be judged, and the learning cost is reduced. Description of the Drawings
[0040] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above and other objects, features, and advantages of the present disclosure will become clearer. In the drawings:
[0041] Figure 1Schematically shows an exemplary system architecture to which a static code analysis method according to an embodiment of the present disclosure can be applied;
[0042] Figure 2 Schematically shows a flowchart of a static code analysis method according to an embodiment of the present disclosure;
[0043] Figure 3 Schematically shows a flowchart of a method for analyzing a method object according to another embodiment of the present disclosure;
[0044] Figure 4 Schematically shows a flowchart of a method for obtaining a target statement according to another embodiment of the present disclosure;
[0045] Figure 5 Schematically shows a usage diagram of a static code analysis method according to an embodiment of the present disclosure;
[0046] Figure 6 Schematically shows a block diagram of a static code analysis device according to an embodiment of the present disclosure; and
[0047] Figure 7 Schematically shows a block diagram of an electronic device suitable for implementing a static code analysis method according to an embodiment of the present disclosure. Detailed implementation manners
[0048] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is obvious that one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.
[0049] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0050] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0051] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning that those skilled in the art usually understand this expression (for example, "a system having at least one of A, B, and C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). In the case of using expressions such as "at least one of A, B, or C, etc.", generally, it should be interpreted according to the meaning that those skilled in the art usually understand this expression (for example, "a system having at least one of A, B, or C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). Static code analysis is a software verification activity. In its verification process, it does not require the execution of code, but rather realizes the purpose of quality, reliability, and security verification by analyzing whether the logic of the source code is correct, and identifies defects and vulnerabilities in the system. Therefore, different from dynamic code analysis, static analysis does not incur the overhead of test case writing and code detection configuration.
[0052] However, none of the static code analysis tools in the related art support the static code analysis of the EGL language. Therefore, the static code analysis of EGL programs relies on manual code inspection to complete. Since the source code of EGL programs is often extremely large, with frequent call hierarchies between programs and a large variety of involved syntax types, a large amount of human effort is required to complete it through manual means. Moreover, the method of manual code inspection is also prone to errors and cannot guarantee the effectiveness of static code analysis.
[0053] In view of this, embodiments of the present disclosure provide a static code analysis method, a static code analysis device, an electronic device, a computer-readable storage medium, and a computer program product. The method includes a process of obtaining a target program package and analysis requirements, a process of parsing the target program package, and a process of analyzing multiple serialized objects.
[0054] It should be noted that the static code analysis method and device provided by the present disclosure can be used in the financial field. For example, it can be a bank, and can also be used in any field other than the financial field, such as a hospital. Therefore, the application fields of the static code analysis method and device provided by the present disclosure are not limited.
[0055] Figure 1 Schematically shows an exemplary system architecture 100 to which the static code analysis method according to an embodiment of the present disclosure can be applied. It should be noted that Figure 1 The shown is only an example of the system architecture to which the embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments, or scenarios.
[0056] like Figure 1 As shown, the system architecture 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired and / or wireless communication links, etc.
[0057] Users can use terminal devices 101, 102, 103 to interact with server 105 through network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, 103, such as code analysis applications, web browser applications, search applications, instant messaging tools, email clients and / or social platform software, etc. (only as examples).
[0058] The terminal devices 101 , 102 , and 103 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.
[0059] The server 105 may be a server that provides various services, such as a background management server (only an example) that provides support for websites browsed by users using the terminal devices 101, 102, and 103. The background management server may analyze and process the received data such as user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.
[0060] It should be noted that the static code analysis method provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the static code analysis system provided in the embodiment of the present disclosure can generally be set in the server 105. The static code analysis method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Accordingly, the static code analysis system provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105.
[0061] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.
[0062] Figure 2 The flowchart of the static code analysis method according to the embodiment of the present disclosure is schematically shown.
[0063] As Figure 2 shown, the method may include operations S201 to S203.
[0064] In operation S201, obtain a target program package and analysis requirements. Among them, the target program package includes at least one method data block, and the method data block includes at least one line of method statements, and the method statements are used to implement a syntax function.
[0065] In operation S202, parse the target program package to obtain at least one method object.
[0066] In operation S203, analyze at least one method object based on the analysis requirements.
[0067] According to an embodiment of the present disclosure, the method statements may include, but are not limited to, assignment statements and flow control statements. The syntax functions may include, but are not limited to, program definition, data structure definition, method definition, and expression definition, etc.
[0068] According to an embodiment of the present disclosure, analysis rules are established according to the analysis requirements of various syntax scenarios. The analysis rules can be written independently by users or developers. The analysis rules may include judgments on assignment variable overflow, logical expression always being true or false, dead loops and abnormal transfers in flow control. Each judgment rule in the analysis requirements is a judgment for a certain syntax.
[0069] According to an embodiment of the present disclosure, when performing engineering verification, it is not necessarily necessary to build an actual working environment, and the verification work is verified through static code. There are more checks on specification-related issues. For example, whether there is a setting for assigning values to key variables in the program; some parameters that should not be judged, such as area codes not allowed to be judged in banks; validity period values, simply written as 99991231. In special cases, the program in production may have phenomena such as dead loops and error reports. At this time, all loops need to be checked. Since there are some inefficiencies in the code, for example, inefficiencies caused by programming habits such as using while loops in loops, it is necessary to judge whether there are problems in the loop body.
[0070] Determine the analysis scope according to the analysis requirements, and find the method objects that need to be analyzed. For example, if an analysis is performed on whether a value is true, the analysis scope can be determined as the statements with the syntax function of assignment among all method objects.
[0071] According to an embodiment of the present disclosure, static analysis rules can be established, for example, from the name of the grammatical function, the target attribute, and the judgment rule. For example, for the assignment statement, a == 0, the name of the grammatical function is evaluation, the target attributes are a and 0, and the judgment rule is whether the operator is ==. Specifically, in an instance, first lock the name CodeEvaluation, the target attributes value, type, and alAssignment, and determine whether alOperation is correct.
[0072] According to an embodiment of the present disclosure, the method object can be a Function object.
[0073] According to an embodiment of the present disclosure, parsing each method data block of the target program package line by line can obtain one or more method objects. During the parsing process, the parsed grammatical information is saved in the corresponding method object, and the grammatical information in the method object can be verified according to requirements.
[0074] According to an embodiment of the present disclosure, for example, when determining whether there is an overflow, the variable type, assignment length, etc. of the method data block can be parsed, so as to facilitate determining whether there is an overflow according to the analysis requirements. Among them, determining whether there is an overflow can obtain its critical value according to the variable type, and determine whether there is an overflow according to whether the assigned variable is within the range of the critical value.
[0075] According to an embodiment of the present disclosure, by means of the technical means of parsing the target program package into method objects and analyzing the method objects based on the analysis requirements, at least partially overcome the technical problems that both manual or dynamic code analysis are prone to code omissions, and manual code analysis requires a certain understanding of the programming language and has a high learning cost. Furthermore, it achieves the technical effect of converting the analysis requirements in logical form into static analysis rules, so that only the correctness of the logic needs to be judged, reducing the learning cost.
[0076] According to an embodiment of the present disclosure, parsing the target program package to obtain at least one method object may include the following operations.
[0077] For each method data block, use the policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree. Serialize at least one method class syntax tree to obtain a method object.
[0078] According to an embodiment of the present disclosure, the syntax tree may include a Function syntax tree, an Evaluation syntax tree, an Expression syntax tree, a Flow-control syntax tree, a Function-call syntax tree, and an EGL-call syntax tree, etc. Among them, the method class syntax tree may include a Function syntax tree.
[0079] According to an embodiment of the present disclosure, a method object may include a Function object.
[0080] According to an embodiment of the present disclosure, a policy chain may include, but is not limited to, a Function-define parser, an Evaluation parser, an Expression parser, a Flow-control parser, a Function-call parser, etc.
[0081] According to an embodiment of the present disclosure, each line of methods included in each method data block is traversed and parsed using the policy chain to obtain a plurality of method class syntax trees. The method class syntax trees are serialized to obtain method objects corresponding to the method data blocks.
[0082] According to an embodiment of the present disclosure, the policy chain includes a plurality of method parsers respectively established for each syntax function. Among them, using the policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree may include the following operations.
[0083] For each line of method statements, a plurality of method parsers are sequentially used to identify the method statements. The method parser that successfully identifies the method statements is used to parse the method statements to generate a method class syntax tree.
[0084] According to an embodiment of the present disclosure, the method parser may include different method parsers generated corresponding to the classification of the policy chain.
[0085] According to an embodiment of the present disclosure, each line of method statements in the method data block is sequentially identified using a plurality of method parsers, and in the case of successful identification, a corresponding method class syntax tree is generated.
[0086] According to an embodiment of the present disclosure, the static code analysis method may further include the following operations.
[0087] In the case where the method statements cannot be identified by any of the plurality of method parsers, a new method parser is constructed based on the method statements. The new method parser is added to the policy chain.
[0088] According to an embodiment of the present disclosure, during the process of using a plurality of method parsers to identify method statements and in the case of unsuccessful identification, a new method parser is constructed based on the method statements, and the constructed new method parser is added to the policy chain.
[0089] Figure 3 A method flow chart for analyzing a method object according to another embodiment of the present disclosure is schematically shown.
[0090] According to an embodiment of the present disclosure, as Figure 3As shown, based on the analysis requirements, analyzing at least one method object may include operations S301 to S303.
[0091] In operation S301, based on the analysis requirements, determine the target syntax function and the judgment rule.
[0092] In operation S302, according to the target syntax function, obtain at least one line of target statements from at least one method object.
[0093] In operation S303, based on the judgment rule, determine whether at least one line of target statements is correct to complete the analysis of at least one method object.
[0094] According to an embodiment of the present disclosure, for example, during the analysis process, in the case where some expressions need to be always true or always false, there is information about the expression in the loop object in the method object. The target syntax statement containing the variable in the statement where the expression is located can be extracted according to the target syntax function, and the operator of the target syntax statement is judged based on the judgment rule to determine whether the expression is always true or false.
[0095] Figure 4 Schematically shows a method flowchart for obtaining target statements according to another embodiment of the present disclosure.
[0096] According to an embodiment of the present disclosure, as Figure 4 shown, obtaining at least one line of target statements from at least one method object according to the target syntax function may include operations S401 to S403.
[0097] In operation S401, parse at least one method object to obtain at least one function linked list.
[0098] In operation S402, according to the target syntax function, obtain the function name corresponding to the target syntax function from the data dictionary.
[0099] In operation S403, extract the statements containing the function name from at least one function linked list to obtain at least one line of target statements of at least one method object.
[0100] According to an embodiment of the present disclosure, parsing the method object can obtain the corresponding function linked list. The method object may include binary code. According to the target syntax function, obtain the function name corresponding to the target syntax function from the data dictionary. For example, the corresponding function name can be obtained as CodeEvaluation from the data dictionary through the Evaluation syntax, and thus extract the statements containing the function name from the function linked list according to the function name to obtain the target statements of the method object.
[0101] According to an embodiment of the present disclosure, based on a judgment rule, judging whether at least one line of target statements is correct may include the following operations.
[0102] According to the target grammar function, obtain at least one judgment keyword corresponding to the target grammar function from the data dictionary. For each line of target statements, extract the statement attributes of the target statements according to the at least one judgment keyword. Based on the judgment rule, judge whether the statement attributes of the target statements are correct to judge whether the target statements are correct.
[0103] According to an embodiment of the present disclosure, a program package written in Enterprise Generation Language (EGL) is used as an example of the target program package for an enterprise.
[0104] According to an embodiment of the present disclosure, process the target program package written in Enterprise Generation Language to obtain a corresponding method object, and parse the method object to obtain a corresponding function linked list.
[0105] For example, if the target grammar function is "If", the function name corresponding to "If" can be obtained from the data dictionary as "CodeIf", and then multiple lines of target statements containing "CodeIf" can be determined from the function linked list. One line of target statements can be "CodeIf - code: if(A == 1 && B != A)", and then the statement attributes of the target statements are extracted according to the judgment keyword to judge whether the statement attributes are correct.
[0106] According to an embodiment of the present disclosure, extract the statement attributes of the target statements from each line of the target statements of the method object according to the judgment keyword, and judge whether the statement attributes are correct according to the judgment rule determined from the analysis requirements.
[0107] Figure 5 A usage schematic diagram of the static code analysis method according to an embodiment of the present disclosure is schematically shown.
[0108] According to an embodiment of the present disclosure, as Figure 5 shown, the target program package may include an EGL program package.
[0109] According to an embodiment of the present disclosure, the target program package may be a program package written in assembly language, script language, and high-level language. Among them, the high-level language may include, but is not limited to, Enterprise Generation Language (EGL), Basic language, C / C++ language, and JAVA language, etc.
[0110] According to an embodiment of the present disclosure, a program package written in Enterprise Generation Language is used as an example of the target program package.
[0111] According to an embodiment of the present disclosure, the target program package is parsed through a policy chain. Since the definitions of the semantics of the enterprise-generated language are scattered in various files throughout the system, for example, a certain definition is made in any one file and can be accessed in other files. Therefore, when parsing a single program, the method object obtained by parsing is incomplete. Thus, the entire target program package needs to be parsed to obtain a method class syntax tree, and the method class syntax tree is serialized to obtain a method object.
[0112] According to an embodiment of the present disclosure, the method object is analyzed based on the analysis requirements. Each judgment rule in the analysis requirements is directed to the syntax of the target statement in the target program package written in the enterprise-generated language.
[0113] According to an embodiment of the present disclosure, during the process of parsing the target program package through the policy chain, corresponding parsers can be established for different syntax objects in the target program package of the enterprise-generated language. For example, corresponding Evaluation parsers, Expression parsers, Flow-control parsers, etc. can be established for syntax objects such as Evaluation, Expression, and Flow-control. Each line of method statement in the target program package is parsed according to different parsers to obtain a corresponding method class syntax tree.
[0114] Figure 6 A block diagram of a static code analysis device according to an embodiment of the present disclosure is schematically shown.
[0115] As Figure 6 shown, the static code analysis device 600 includes an acquisition module 610, a parsing module 620, and an analysis module 630.
[0116] The acquisition module 610 is configured to acquire a target program package and analysis requirements, where the target program package includes at least one method data block, and the method data block includes at least one line of method statement, and the method statement is used to implement a syntax function.
[0117] The parsing module 620 is configured to parse the target program package to obtain at least one method object.
[0118] The analysis module 630 is configured to analyze at least one method object based on the analysis requirements.
[0119] According to an embodiment of the present disclosure, by means of the technical means of parsing a target program package into method objects and analyzing the method objects based on analysis requirements, at least partially overcome the technical problems that both manual or dynamic code analysis are prone to code omissions, and manual code analysis requires a certain understanding of the programming language and has a relatively high learning cost. Furthermore, the technical effect of converting the analysis requirements in logical form into static analysis rules is achieved, so that only the correctness of the logic needs to be judged, and the learning cost is reduced.
[0120] According to an embodiment of the present disclosure, the parsing module 620 may include a generating unit and a serializing unit.
[0121] The generating unit is configured to, for each method data block, use a policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree.
[0122] The serializing unit is configured to serialize at least one method class syntax tree to obtain a method object.
[0123] According to an embodiment of the present disclosure, the generating unit may include an identifying subunit and a generating subunit.
[0124] The identifying subunit is configured to, for each line of method statements, sequentially use a plurality of method parsers to identify the method statements.
[0125] The generating subunit is configured to use the method parser that successfully identifies the method statements to parse the method statements to generate a method class syntax tree.
[0126] According to an embodiment of the present disclosure, the generating unit may further include a constructing subunit and an adding subunit.
[0127] The constructing subunit is configured to, in the case where a plurality of method parsers are unable to identify the method statements, construct a new method parser based on the method statements.
[0128] The adding subunit is configured to add the new method parser to the policy chain.
[0129] According to an embodiment of the present disclosure, the analysis module 630 may include a determining unit, an obtaining unit, and a judging unit.
[0130] The determining unit is configured to determine a target syntax function and a judging rule based on the analysis requirements.
[0131] The obtaining unit is configured to obtain at least one line of target statements from at least one method object according to the target syntax function.
[0132] The judging unit is configured to judge whether at least one line of target statements is correct based on the judging rule to complete the analysis of at least one method object.
[0133] According to an embodiment of the present disclosure, the acquisition unit may include a parsing subunit, a first acquisition subunit, and a first extraction subunit.
[0134] The parsing subunit is configured to parse at least one method object to obtain at least one function linked list.
[0135] The first acquisition subunit is configured to obtain, according to a target syntax function, a function name corresponding to the target syntax function from a data dictionary.
[0136] The first extraction subunit is configured to extract, from at least one function linked list, a statement containing the function name to obtain at least one target statement of at least one method object.
[0137] According to an embodiment of the present disclosure, the judgment unit may include a second acquisition subunit, a second extraction subunit, and a judgment subunit.
[0138] The second acquisition subunit is configured to obtain, according to a target syntax function, at least one judgment keyword corresponding to the target syntax function from a data dictionary.
[0139] The second extraction subunit is configured to extract, for each line of the target statement, a statement attribute of the target statement according to at least one judgment keyword.
[0140] The judgment subunit is configured to judge, based on a judgment rule, whether the statement attribute of the target statement is correct to judge whether the target statement is correct.
[0141] According to an embodiment of the present disclosure, any multiple of the modules, units, and subunits, or at least part of the functions of any multiple of them, may be implemented in one module. Any one or more of the modules, units, and subunits according to the embodiments of the present disclosure may be split into multiple modules for implementation. Any one or more of the modules, units, and subunits according to the embodiments of the present disclosure may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or may be implemented by any other reasonable way of integrating or packaging circuits, or by hardware or firmware in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, one or more of the modules, units, and subunits according to the embodiments of the present disclosure may be at least partially implemented as a computer program module, and when the computer program module runs, it may execute corresponding functions.
[0142] For example, any number of the obtaining module 610, the parsing module 620, and the analyzing module 630 may be combined and implemented in one module / unit / sub-unit, or any one of the modules / units / sub-units may be split into multiple modules / units / sub-units. Or, at least part of the functions of one or more of these modules / units / sub-units may be combined with at least part of the functions of other modules / units / sub-units and implemented in one module / unit / sub-unit. According to an embodiment of the present disclosure, at least one of the obtaining module 610, the parsing module 620, and the analyzing module 630 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or may be implemented by any other reasonable means such as hardware or firmware for integrating or packaging circuits, or may be implemented in any one of the three implementation manners of software, hardware, and firmware or in an appropriate combination of any several of them. Or, at least one of the obtaining module 610, the parsing module 620, and the analyzing module 630 may be at least partially implemented as a computer program module, and when the computer program module is run, it may execute the corresponding functions.
[0143] It should be noted that the static code analysis system part in the embodiments of the present disclosure corresponds to the static code analysis method part in the embodiments of the present disclosure. For the description of the static code analysis system part, please refer to the static code analysis method part specifically, and details are not described herein again.
[0144] Figure 7 A block diagram of an electronic device suitable for implementing the method described above according to an embodiment of the present disclosure is schematically shown. Figure 7 The shown electronic device is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.
[0145] As Figure 7 shown, the computer electronic device 700 according to an embodiment of the present disclosure includes a processor 701, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage section 708 into a random access memory (RAM) 703. The processor 701 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), and so on. The processor 701 may also include on-board memory for caching purposes. The processor 701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0146] In the RAM 703, various programs and data required for the operation of the electronic device 700 are stored. The processor 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. The processor 701 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 702 and / or the RAM 703. It should be noted that the programs may also be stored in one or more memories other than the ROM 702 and the RAM 703. The processor 701 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.
[0147] According to an embodiment of the present disclosure, the electronic device 700 may further include an input / output (I / O) interface 705, and the input / output (I / O) interface 705 is also connected to the bus 704. The electronic device 700 may further include one or more of the following components connected to the I / O interface 705: an input portion 706 including a keyboard, a mouse, etc.; an output portion 707 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 708 including a hard disk, etc.; and a communication portion 709 including a network interface card such as a LAN card, a modem, etc. The communication portion 709 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 710 as needed so that a computer program read from it can be installed into the storage portion 708 as needed.
[0148] According to an embodiment of the present disclosure, the method flow according to the embodiments of the present disclosure may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication portion 709, and / or installed from the removable medium 711. When the computer program is executed by the processor 701, the above functions defined in the system according to the embodiments of the present disclosure are performed. According to an embodiment of the present disclosure, the above-described system, device, apparatus, module, unit, etc. may be implemented by computer program modules.
[0149] The present disclosure also provides a computer-readable storage medium, which may be included in the device / device / system described in the above embodiments; or may exist separately without being assembled into the device / device / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.
[0150] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium. For example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.
[0151] For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include one or more memories other than the above-described ROM 702 and / or RAM 703 and / or ROM 702 and RAM 703.
[0152] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method provided by the embodiment of the present disclosure. When the computer program product runs on an electronic device, the program code is used to cause the electronic device to implement the static code analysis method provided by the embodiment of the present disclosure.
[0153] When the computer program is executed by the processor 701, the above functions defined in the system / apparatus of the embodiment of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.
[0154] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium and downloaded and installed through the communication part 709, and / or installed from the removable medium 711. The program code included in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0155] In accordance with embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0156] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions. Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0157] The above describes the embodiments of the present disclosure. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments are described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.
Claims
1. A static code analysis method, comprising: Obtaining a target program package and analysis requirements, wherein the target program package includes an EGL program package, the target program package includes at least one method data block, and the method data block includes at least one line of method statements for implementing a syntax function; Parsing the target program package to obtain at least one method object; and Analyzing the at least one method object based on the analysis requirements; wherein, parsing the target program package to obtain at least one method object includes: For each method data block, using multiple method parsers in a policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree, wherein the policy chain includes multiple method parsers respectively established for each syntax function; and Serializing the at least one method class syntax tree to obtain the method object; wherein, using the policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree includes: For each line of method statements, sequentially using the multiple method parsers to identify the method statements; and Using the method parser that successfully identifies the method statements to parse the method statements to generate a method class syntax tree.
2. The method according to claim 1, further comprising: In the case where the multiple method parsers cannot identify the method statements, constructing a new method parser based on the method statements; and Adding the new method parser to the policy chain.
3. The method according to claim 1, wherein, The analyzing the at least one method object based on the analysis requirements includes: Determining a target syntax function and a judgment rule based on the analysis requirements; Obtaining at least one line of target statements from the at least one method object according to the target syntax function; and Judging whether the at least one line of target statements is correct based on the judgment rule to complete the analysis of the at least one method object.
4. The method according to claim 3, wherein, The obtaining at least one line of target statements from the at least one method object according to the target syntax function includes: Parsing the at least one method object to obtain at least one function linked list; Obtaining a function name corresponding to the target syntax function from a data dictionary according to the target syntax function; and Extracting the statements containing the function name from the at least one function linked list to obtain at least one line of target statements of the at least one method object.
5. The method according to claim 3, wherein, The judging whether the at least one line of target statements is correct based on the judgment rule includes: Obtaining at least one judgment keyword corresponding to the target syntax function from a data dictionary according to the target syntax function; For each line of target statements, extracting the statement attributes of the target statements according to the at least one judgment keyword; and Judging whether the statement attributes of the target statements are correct based on the judgment rule to judge whether the target statements are correct.
6. A static code analysis device, comprising: An acquisition module, configured to acquire a target program package and analysis requirements, wherein the target program package includes an EGL program package, and the target program package includes at least one method data block, and the method data block includes at least one line of method statements for implementing a syntax function; A parsing module, configured to parse the target program package to obtain at least one method object; and An analysis module, configured to analyze the at least one method object based on the analysis requirements; Wherein, the parsing module includes: A generation unit, configured to, for each method data block, use multiple method parsers in a policy chain to parse at least one line of method statements in the method data block to generate at least one method class syntax tree, wherein the policy chain includes multiple method parsers respectively established for each syntax function; A serialization unit, configured to serialize at least one method class syntax tree to obtain a method object; Wherein, the generation unit includes: An identification subunit, configured to, for each line of method statements, sequentially use multiple method parsers to identify the method statements; A generation subunit, configured to use the method parser that successfully identifies the method statements to parse the method statements to generate a method class syntax tree.
7. An electronic device, comprising: One or more processors; A memory, configured to store one or more instructions, Wherein, when the one or more instructions are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.
8. A computer-readable storage medium, on which executable instructions are stored, and when the executable instructions are executed by a processor, the processor implements the method according to any one of claims 1 to 5.
9. A computer program product, the computer program product includes computer-executable instructions, and the computer-executable instructions are used to implement the method according to any one of claims 1 to 5 when executed.
Citation Information
Patent Citations
Analysis method and monitoring method for C language simulation model
CN102629213A
Application package analysis method and device and computer readable storage medium
CN111400197A