Analysis result management device, analysis result management method, and program product
By establishing the corresponding relationship between warning table notation and identification information between analysis tools, and calculating and storing the hash value of the warning, the problem that the same code errors in multiple static analysis systems are identified as different warnings, achieving the effect of suppressing the display of repeated warnings, and improving the efficiency of judging the analysis results.
Patent Information
- Application Number
- CN202411914472.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2024-12-24
- Publication Date
- 2025-06-27
AI Technical Summary
In software development, when multiple static analysis systems are used, errors in the same code are identified by multiple systems as different warnings, resulting in an increase in the number of warnings and it is difficult for software developers to confirm the warning content.
By establishing the corresponding relationship between the table notation and identification information of the same warning output by different analysis tools, the hash value of the warning is calculated, and the correspondence between the warning data and the hash value is stored in the database to suppress the display of repeated warnings.
It effectively suppresses repeated warning displays in multiple static analysis systems, improving the efficiency of software developers in judging analysis results.
Smart Images

Figure CN120216014A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an analysis result management device for managing analysis results of source code, etc. Background Art
[0002] In software development, due to coding errors, situations often occur where the software does not operate properly. Such errors can be prevented by reviewing the source code, but as the scale of the software increases and the content becomes more complex, the number of such situations increases sharply.
[0003] In order to detect such errors before the execution test of the program, a static analysis system as follows has been developed and sold: performing syntactic or semantic analysis without actually executing the source file of the software, and outputting a warning for a source code description that has a possibility of becoming a defect (Bug). Such an analysis system outputs information that can be corrected by software developers.
[0004] The analysis system outputs the result after analyzing the source code, but the number of warnings included in the result is often huge. In software development, multiple versions are created. If a warning that has been confirmed in a previous version is warned again, although it has been confirmed, it still needs to be reconfirmed, which is inefficient. Patent Document 1 discloses the following technique: suppressing warning messages by comparing the line and column numbers of the source code, the syntax of the analysis object, and the constituent elements in the syntax between the previous and subsequent versions.
[0005] In addition, conventionally, there has also been known a system as follows: calculating a hash value for a set of source code description contents and tool detection results, and using the hash value to manage the analysis results. By using the hash value, it is possible to simply compare the analysis results for source codes of different versions. Analysis results having the same hash value can be treated as the same, so the analysis results can also be reused. In addition, the hash value can be used to retrieve warnings, so efficient and correct management can be achieved.
[0006] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2004 - 126866
[0007] When analyzing source code, multiple static analysis systems are sometimes used. Since analysis can be performed from different viewpoints by multiple static analysis systems, the detection accuracy of errors in the source code can be improved.
[0008] However, if multiple static analysis systems are used, for the same error in the code, multiple warnings are pointed out as different warnings, so the number of warnings increases accordingly, and it may become increasingly difficult for software developers to confirm the warning contents. Summary of the Invention
[0009] In view of the above background, an object of the present invention is to provide a technique capable of appropriately judging analysis results.
[0010] The present invention includes the following aspects.
[0011] The analysis result management device of the present invention is an analysis result management device that manages a plurality of static analysis result data obtained by analyzing source code through different analysis tools. Among them, the above analysis result management device includes: a table that associates different warning notations output by the above different analysis tools for warnings of the same type with identification information; an input unit that accepts the input of a plurality of the above static analysis results of the source code; a hash value calculation unit that calculates the hash value of the above warning with the data related to the above warning as input. When there is identification information corresponding to the warning notation that is the object of hash value calculation in reference to the above table, the above hash value calculation unit reads out the above identification information and uses the read identification information instead of the above warning notation to calculate the hash value; a database that stores the data of the above warning in correspondence with the above hash value; and a display unit that displays the data stored in the above database.
[0012] The analysis result management method of the present invention is an analysis result management method that uses an analysis result management device to manage a plurality of static analysis result data obtained by analyzing source code through different analysis tools. Among them, the above analysis result management method includes: a step in which the analysis result management device prepares a table in which different warning notations output by the above different analysis tools for warnings of the same type are associated with identification information; a step in which the analysis result management device accepts the input of a plurality of the above static analysis results of the source code; a step in which the analysis result management device calculates the hash value of the above warning with the data related to the above warning as input, and it is a step in which the analysis result management device reads out the above identification information when there is identification information corresponding to the warning notation that is the object of hash value calculation in reference to the above table and uses the read identification information instead of the above warning notation to calculate the hash value; a step of storing the data of the above warning in correspondence with the above hash value in a database; and a step of displaying the data stored in the above database.
[0013] The program of the present invention is a program for managing multiple static analysis result data obtained by analyzing source code through different analysis tools, wherein the above-mentioned program enables a computer to function as follows: a table that establishes a correspondence between different warning marks output by the above-mentioned different analysis tools for the same type of warnings and identification information; an input unit that receives input of multiple above-mentioned static analysis results of the source code; a hash value calculation unit that uses data related to the above-mentioned warnings as input to calculate the hash value of the above-mentioned warnings, and the above-mentioned hash value calculation unit reads the above-mentioned identification information when there is identification information corresponding to the warning mark that is the object of hash value calculation with reference to the above-mentioned table, and uses the read-out identification information instead of the above-mentioned warning mark to calculate the hash value; a database that stores the above-mentioned warning data in correspondence with the above-mentioned hash value; and a display unit that displays the data stored in the above-mentioned database.
[0014] According to the present invention, it is possible to suppress the display of redundant warnings in static analysis results by a plurality of analysis tools, and the software developer can appropriately judge the analysis results. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 It is a diagram showing the functional structure of the analysis result management device according to the first embodiment.
[0016] Figure 2 It is a diagram showing the hardware configuration of the analysis result management device according to the first embodiment.
[0017] Figure 3 (a) is a diagram showing an example of static analysis result data stored in a database. Figure 3 (b) is a diagram showing an example of data of the review results stored in the database.
[0018] Figure 4 This is a diagram showing an example of source code that is the target of static analysis.
[0019] Figure 5 (a) is a diagram for explaining the code used for calculating the hash value of the warning in warning line 1. Figure 5 (b) is a diagram for explaining the code used for calculating the hash value of the warning in warning line 2. Figure 5 (c) is a diagram for explaining the code used for calculating the hash value of the warning in warning line 3.
[0020] Figure 6 This is a flowchart showing the calculation processing of the hash value calculation unit.
[0021] Figure 7 (a) is a diagram for explaining the code used for calculating the hash value of the warning in warning line 1. Figure 7The (b) is a diagram showing the code used for calculating the hash value of the warning of warning line 2. Figure 7 The (c) is a diagram showing the code used for calculating the hash value of the warning of warning line 3.
[0022] Figure 8 It is a diagram showing another example of the hash value calculation by the hash value calculation unit.
[0023] Figure 9 It is a diagram for explaining the calculation process performed by the hash value calculation unit of the analysis result management device according to the second embodiment.
[0024] Figure 10 It is a diagram showing the functional structure of the analysis result management device according to the third embodiment.
[0025] Figure 11 It is a diagram showing an example of the data stored in the warning correspondence table.
[0026] Figure 12 It is a diagram for explaining the calculation process of the hash value calculation unit.
[0027] Figure 13 It is a diagram showing an example of a screen that outputs the analysis result managed by the analysis result management device.
[0028] Figure 14 It is a diagram for explaining the calculation process performed by the hash value calculation unit of the analysis result management device according to the third embodiment.
[0029] Figure 15 It is a diagram showing the types of inputs used for calculating the hash value among multiple calculation methods. Detailed Embodiment
[0030] Hereinafter, the analysis result management device according to the present embodiment will be described with reference to the drawings. In addition, the following description is only an example showing a preferred mode and is not intended to limit the invention described in the claims.
[0031] (First Embodiment)
[0032] [Overall Structure of Analysis Result Management Device]
[0033] Figure 1 It is a diagram showing the functional structure of the analysis result management device 1 according to the present embodiment. The analysis result management device 1 receives the input of the result obtained by analyzing the source code of the software using the static analysis tool 20 and manages the static analysis result data. The analysis result management device 1 receives the input of the static analysis results of multiple static analysis tools 20.
[0034] Figure 2This is a diagram showing the hardware structure of the analysis result management device 1 of the present embodiment. The analysis result management device 1 is configured on a network, and the analysis result management device 1 and the user terminal 40 can communicate via the network. Here, the type of the network is not limited. For example, it can be the Internet, an intranet within a company, etc. In addition, in the present embodiment, an example of configuring the analysis result management device 1 on the network is shown, but the analysis result management device 1 can also be implemented by a local PC. In this case, the local PC has the functions of the analysis result management device 1 and the user terminal 40.
[0035] The analysis result management device 1 includes a control unit 30 having a CPU 31, a RAM 32, and a ROM 33, an input unit 34, an output unit 35, a storage unit 36, and a communication unit 37. The functions of the analysis result management device 1 described later are implemented by executing the program stored in the ROM 33. Such a program is also within the scope of the present invention.
[0036] Users such as software developers access the analysis result management device 1 from the user terminal 40 through a web browser. The data of the static analysis result is sent from the user terminal 40 to the analysis result management device 1. The analysis result management device 1 manages the data of the static analysis result.
[0037] Return to Figure 1 , the functions of the analysis result management device 1 will be described. The analysis result management device 1 includes a data input unit 11, a data converter 12, a database 15, a display unit 16, and a review result input unit 17.
[0038] The data input unit 11 receives the input of the data of the static analysis result of the source file by the static analysis tool 20. The static analysis result data is warning data for the description of the source code including the possibility of defects. It is data indicating where there are what kind of syntax errors, etc. in the source code. In addition, the data input unit 11 also receives the input of the data of the source file. The input source file is because the analysis result management device 1 of the present embodiment also uses the data of the source code in the calculation of the hash value as described later.
[0039] As a static analysis tool 20, there are various tools. The data input unit 11 receives the input of data analyzed by different static analysis tools 20. The results of static analysis vary depending on the static analysis tool 20. A description detected as a warning in one static analysis tool 20 may not be detected as a warning in other static analysis tools 20. This is because, based on the specifications of the static analysis tool 20, the fields in which the static analysis tool 20 is good at analysis are different. By obtaining the static analysis results of multiple static analysis tools 20, a highly accurate review can be performed. The data input unit 11 transfers the input static analysis result data to the data converter 12. In addition, the data input unit 11 stores the source file in the database 15.
[0040] The data converter 12 has a data format conversion unit 13 and a hash value calculation unit 14. The static analysis result data input to the data input unit 11 varies in items or formats (e.g., text data, HTML format, etc.) depending on the static analysis tool 20. The data format conversion unit 13 has a function of converting data formats that vary according to the static analysis result data into a common format.
[0041] The hash value calculation unit 14 has a function of calculating the hash value of the warnings included in the static analysis result data. The hash value is unique data calculated based on the data related to the warning and the code of the line involved in the warning, and is used as identification information for determining the warning. The details of the hash value calculation method will be described later.
[0042] By using the hash value as identification information, it is possible to easily determine the same warning between source files of different versions. Thus, it is possible to eliminate the trouble of re-reviewing warnings that have already been reviewed, and significantly reduce the source code review time.
[0043] The database 15 stores the static analysis results, review results, and source files. The data storage of the static analysis results stores the static analysis result data after converting the data format by the data converter 12 and assigning a hash value to the warning.
[0044] Figure 3 (a) is a diagram showing an example of the data of the static analysis results stored in the database 15. The data of the static analysis results has data of file name, detector name, warning message, tool name, severity, line, and column corresponding to the hash value. The hash value is identification information for determining the warning, and is calculated based on the data related to the warning and the data of the code of the line involved in the warning.
[0045] The file name is the file name of the source file that is the object of static analysis. The detector name is the name of the detector that detects a warning. A static analysis tool 20 has multiple detector algorithms. By executing the detector algorithms, it searches for potentially defective code and outputs a warning. The warning message is a message used to notify the user of the content of the warning.
[0046] The tool name is the name of the static analysis tool 20 that detects a warning. The severity is data indicating the severity level of the warning. It is represented by a numerical value from 0 to 30. The larger the number, the more serious the content of the warning. The line and column are data for determining the location of the code involved in the warning. The line indicates the line number where the warning starts, and the column indicates the column number within the file. In addition, what is shown here is an example, and the data of the static analysis result can also include Figure 3 data other than those shown in (a) below.
[0047] Figure 3 The notations of the detector name, warning message, tool name, and severity data in the static analysis result data shown in (a) below vary depending on the static analysis tool 20 and are data for different notations of the same code error.
[0048] Figure 3 Figure (b) below is a diagram showing an example of the data of the review result stored in the database 15. The data of the review result has data of status, confirmator, comment, and confirmation date and time corresponding to the hash value. The hash value corresponds to the hash value included in the static analysis result data and determines the warning. The status is the status of the review situation for the warning determined by the hash value. For example, "confirmed" indicates that the confirmation is complete, and "unreviewed" indicates that it has not been reviewed yet. The confirmator is the name of the user who reviewed the warning and changed the status. The comment is the comment on what kind of processing was taken for the warning when the warning review was completed, etc. The confirmation date and time is the data of the date and time when the content of the warning was confirmed. In addition, what is shown here is an example, and the data of the review result can also include Figure 3 data other than those shown in (b) below.
[0049] The display unit 16 has a function of displaying the data of the analysis result stored in the database 15 on the user terminal 40. Specifically, according to a request from the user terminal 40, it reads out the analysis result data from the database 15, sends the analysis result data to the user terminal 40, and causes the user terminal 40 to display the analysis result data.
[0050] If the data of the review result is sent from the user terminal 40, the review result input unit 17 stores the sent review result in the database 15 in association with the hash value representing the corresponding warning. Specifically, the review result input unit 17 updates the status, confirmator, comment, and confirmation date and time of the warning determined by the hash value.
[0051] [Calculation of Hash Value]
[0052] Next, the calculation process of the hash value by the hash value calculation unit 14 will be described. The hash value calculation unit 14 calculates the hash value by using the data related to the warning and the code involved in the warning as inputs. As the data related to the warning, the file name of the source file, the name of the detector that has performed the analysis, and the warning message are used. In addition, what is shown here is an example of the data related to the warning used in the calculation of the hash value. Of course, other data related to the warning can also be used in the calculation of the hash value.
[0053] Figure 4 is a diagram showing an example of the source code that is the object of static analysis. Taking the Figure 4 shown code as an example, the calculation of the hash value will be described. In the Figure 4 shown example, it is possible that the code "len++" has an error and is detected as a warning. The hash value calculation unit 14 calculates the hash value by using, in addition to the data related to the warning, the code involved in the warning, that is, "len++", as an input.
[0054] In addition, line numbers are not used in the calculation of the hash value. By adopting a structure that does not include line numbers in the calculation of the hash value, in source codes with different versions, for example, even when the line numbers are offset due to the addition of blank lines, the hash values are the same, and it can be recognized as the same warning. However, by adopting a structure that does not use line numbers in the calculation of the hash value, in the case where the same warning exists in multiple lines, those hash values become the same value.
[0055] Refer to Figure 4 , the code of warning line 1 to warning line 3 is the same. Therefore, the content of the data related to the warning (specifically, the file name of the source file, the name of the detector that has performed the analysis, and the warning message) is also the same. In this way, the hash values for the code of warning line 1 to warning line 3 are the same, and the same identification information is assigned to the warnings of warning line 1 to warning line 3, and they are processed as one warning. Although there is an idea that such processing is sufficient, in the analysis result management device 1 of the present embodiment, even if multiple warnings have the same content, they are processed as different warnings. The hash value calculation unit 14 calculates the hash value so as to distinguish Figure 4 the same warnings as shown.
[0056] In the case where the hash value calculated with the data related to the warning and the code of the line involved in the warning as input (referred to as the "first hash value" for convenience of explanation) duplicates any of the calculated hash values, the hash value calculation unit 14 calculates the hash value with the code of multiple lines from the line involved in the warning where the initial hash value duplicates to the line involved in the warning as input (referred to as the "second hash value" for convenience of explanation), and uses the second hash value as the hash value for the warning.
[0057] Figure 5 is a diagram showing the code used for calculating the hash value of the warnings for warning lines 1 to 3. In the explanation using Figure 5 focuses on the code, but as described above, uses the data related to the warning as the input for hash value calculation. Figure 5 In (a) of , it shows the code used for calculating the hash value of the warning for warning line 1. The code of the fourth line enclosed by box a is used as the input.
[0058] Figure 5 In (b) of , it shows the code used for calculating the hash value of the warning for warning line 2. In addition to the code enclosed by box a, the code of the fifth line enclosed by box b from the warning line 1 determined to be the initial hash value duplicate to warning line 2 is used as the input. Figure 5 In (c) of , it shows the code used for calculating the hash value of the warning for warning line 3. In addition to the code enclosed by box a, the code of the fifth to seventh lines enclosed by box c from the warning line 1 determined to be the initial hash value duplicate to warning line 3 is used as the input.
[0059] As Figure 5 in (a) to Figure 5 in (c) of shows, even in the case where the same warning is detected for the code "len++", by changing the range of the code used for hash value calculation, the hash values can be distinguished.
[0060] Figure 6 is a flowchart showing the calculation process of the hash value calculation unit 14. The hash value calculation unit 14 first sorts all the warnings in the static analysis result data according to the file name and line number of the warning (S10). Then, the hash value calculation unit 14 calculates the first hash value with the data related to the warning and the code of the line involved in the warning as input (S11), and determines whether there already exists a hash value identical to the calculated first hash value (S12).
[0061] In the case where there is an identical hash value (Yes in S12), the hash value calculation unit 14 calculates a second hash value (S13), using the code from the line where the initial hash value repeats to the warning behavior of the calculation target, in addition to the data related to the warning and the code of the line involved in the warning, and uses the second hash value as the hash value for the warning. At this time, for parts such as blanks and comments that do not directly affect the warning, they may or may not be used for hash value calculation. Next, the hash value calculation unit 14 determines whether there is still a warning for which the hash value has not been calculated (S14). In the case where there is a warning for which the hash value has not been calculated (Yes in S14), the process returns to step S11 for calculating the first hash value for this warning.
[0062] In the determination of whether there is already an identical hash value to the first hash value (S12), when it is determined that there is no identical hash value (No in S12), the first hash value is used as the hash value for the warning of the calculation target. In the determination of whether there is still a warning for which the hash value has not been calculated (S14), when there is no warning for which the hash value has not been calculated (No in S14), the calculation process of the hash value for the data of the corresponding static analysis result is ended.
[0063] As described above, the analysis result management device 1 and the analysis result management method of the first embodiment have been described. In the case where the first hash value repeats the already existing hash value, the analysis result management device 1 of the first embodiment calculates the second hash value using the code from the warning line where the initial hash value repeats to the warning behavior of the calculation target, thereby being able to avoid hash value repetition. The code before the repetition of the initial hash value does not affect the calculation of the second hash value, so even if corrections were made previously, the differential analysis between versions is not affected. Thus, warnings can be appropriately managed.
[0064] The software under development changes frequently due to version upgrades and the like. Therefore, it is important to identify the change points and problem points. According to the analysis result management device 1 of the present embodiment, by devising a method for managing the analysis results of the source code before and after the software under development and identifying the change points and problem points, as well as a method for managing the analysis results, different warnings can be distinguished, and undetected problems can be improved.
[0065] In the above first embodiment, when calculating the second hash value, the code from the warning line where the initial hash value repeats to the warning behavior of the calculation target is used as the input, but other ranges of code can also be used as the input. For example, the code from the first line of the source code to the warning behavior of the calculation target can also be used as the input to calculate the hash value.
[0066] Figure 7This is a diagram showing an example of the code used for calculating the second hash value. Figure 7 (a) to Figure 7 (c) of Figure 5 correspond to (a) to Figure 5 (c) of
[0067] respectively, and show an example of calculating the hash values of warning lines 1 to 3. Figure 7 In (a) of Figure 7 , since the hash value of warning line 1 is not duplicated, the code related to warning line 1 is used as input to calculate the hash value. When calculating the hash value of warning line 2, the first hash value obtained using only the code of warning line 2 is duplicated with the hash value of warning line 1. Therefore, as shown in (b) of
[0068] , the hash value calculation unit 14 uses the code within the range enclosed by box d from the first line of the source code to warning line 2 as input to calculate the second hash value. Figure 7 When calculating the hash value of warning line 3, the first hash value obtained using only the code of warning line 3 is duplicated with the hash value of warning line 1. Therefore, as shown in (c) of
[0069] , the hash value calculation unit 14 uses the code within the range enclosed by box e from the first line of the source code to warning line 3 as input to calculate the second hash value. With such a structure, duplication of hash values can also be avoided. Figure 8 Figure 8 In addition, as another example of the range of code used for calculating the hash value, the code from the previous warning line to the warning line being calculated can be used as input.
[0070] Figure 8 This is a diagram showing an example of such calculation. In , the three lines starting with "tmp =" are warning lines 1 to 3.
[0071] In
[0072] , since the hash value of warning line 1 is not duplicated, the code related to warning line 1 is used as input to calculate the hash value. When calculating the hash value of warning line 2, the first hash value obtained using only the code of warning line 2 is duplicated with the hash value of warning line 1. Therefore, the hash value calculation unit 14 uses the code within the range enclosed by box f from the line immediately following warning line 1 to warning line 2 as input to calculate the second hash value. (Second Embodiment)
[0073] Next, the analysis result management device of the second embodiment will be described. The basic structure of the analysis result management device of the second embodiment is the same as that of the analysis result management device 1 of the first embodiment (refer to Figure 1 and Figure 2 ). However, the difference in the second analysis result management device is that it also calculates the hash value considering the process information associated with the warning line.
[0074] Figure 9 is a diagram for explaining the calculation process performed by the hash value calculation unit 14 of the analysis result management device of the second embodiment. In Figure 9 , the warning line is "case 1: result = a / ZERO; break;" surrounded by box a, and it is possible that there is an error in warning a divided by ZERO. Here, ZERO is defined as 0 by "#define ZERO 0" surrounded by box h. That is, the variable in the code surrounded by box a refers to the code surrounded by box h, and these two lines are associated. In the source code, when a certain problem is found as a warning, it is sometimes necessary to view the processing flow up to the part where the problem occurs. In this specification, such a movement on the source code is called "process information".
[0075] When calculating the hash value of the warning line surrounded by box a, the hash value calculation unit 14 calculates the hash value by taking the code of the line surrounded by box h as input in addition to the code of the warning line.
[0076] According to the analysis result management device of the second embodiment, by calculating the hash value considering not only the warning message and the source code but also the process information associated with the warning line, it is possible to suppress the occurrence of undetected warnings and improve the quality of the management of the analysis results.
[0077] In addition, in this embodiment, in addition to the structure of the analysis result management device 1 of the first embodiment, the calculation of the hash value considering the process information is also described. However, the calculation of the hash value considering the process information described in the second embodiment is not based on the hash value calculation method for avoiding hash value duplication described in the first embodiment. Therefore, in an analysis result management device that allows the same hash value to be assigned to the same type of warning, it is also possible to calculate the hash value considering the process information.
[0078] (Third Embodiment)
[0079] Figure 10This is a diagram showing the functional structure of the analysis result management device 3 of the third embodiment. The basic structure of the analysis result management device 3 of the third embodiment is the same as that of the analysis result management device 1 of the first embodiment, but the analysis result management device 3 of the third embodiment has a warning correspondence table 18. The warning correspondence table 18 is a table showing the correspondence relationship of detectors that detect the same type of warning in the static analysis result data based on multiple static analysis tools 20.
[0080] Figure 11 This is a diagram showing an example of the data stored in the warning correspondence table 18. The warning correspondence table 18 shows the correspondence relationship of the detector names of tool X, tool Y, and tool Z as static analysis tools 20. In Figure 11 the example shown, "Division By Zero" in tool X, "core.DivideZero" in tool Y, and "Integer divisionby zero" in tool Z correspond to each other. The warning correspondence table 18 associates the identification information with the detector names of each tool. Here, the identification information "INT31-C" is a string attached to the rule of "ensuring that data disappearance and misinterpretation will not occur due to integer conversion" in the CERT C coding standard. It is possible to use meaningful strings as identification information like this, but as long as there is no duplication, it can also be random information without meaning. In addition, in Figure 11 , the warning correspondence table 18 stores the correspondence of the detector names of three analysis tools, but it is also possible to associate the detector names of four or more analysis tools. When the number of analysis tools increases, the detector names of the new analysis tools can be registered in the warning correspondence table 18.
[0081] When calculating the hash value of a warning, the hash value calculation unit 14 determines whether the detector name that detected the warning to be calculated is recorded in the warning correspondence table 18. When the detector name is recorded in the warning correspondence table 18, the identification information corresponding to the detector name is read out, and the identification information is used as the input instead of the detector name to calculate the hash value.
[0082] Figure 12 This is a diagram for explaining the calculation process of the hash value calculation unit 14. Figure 12 The process shown is the positioning of the specific process of the first hash value calculation (S11) or the second hash value calculation (S13) in the hash value calculation process shown in Figure 6 .
[0083] When the analysis result management device 3 of the third embodiment calculates the hash value, it first determines whether the detector name of the detector that has detected a warning for the calculation target exists in the warning correspondence table 18 (S20). If the determination result is that the detector name exists in the warning correspondence table 18, the identification information is read from the warning correspondence table 18 (S21), and the identification information is used as the input instead of the detector name in the data related to the warning to calculate the hash value (S23). That is, as the data related to the warning, the file name of the source file and the identification information are used. In addition, when calculating the hash value in the analysis result management device 1 of the first embodiment, as the information related to the warning, the file name of the source file, the name of the detector that has performed the analysis, and the warning message are used, but the warning message is not used in this embodiment.
[0084] When the detector name of the detector that has detected a warning for the calculation target is not recorded in the warning correspondence table 18 (in S20, "no"), the detector name is referred to (S22), and the hash value is calculated (S23). That is, as the data related to the warning, the file name of the source file and the detector name are used.
[0085] Figure 13 FIG. is an example of a screen for outputting the analysis results managed by the analysis result management device 3. The analysis results include, corresponding to the hash value for determining the warning, the file name of the source file in which the warning was detected, the detector name of the detector that detected the warning, the warning message, the tool name of the static analysis tool 20 that detected the warning, the severity indicating the severity of the warning, and the data of the review result for the warning.
[0086] In this embodiment, when the warnings detected by multiple static analysis tools 20 are warnings for the same code, they are output as one warning. Specifically, in Figure 13 the hash value of the third line in is associated with the data of three tools, namely tool K, tool L, and tool M. Although the warnings are detected by each of the three static analysis tools 20, since they are warnings for the same code, they are processed as one warning. It is not necessary to process the warnings for each static analysis tool 20, and as long as the review result is input once, it is possible to set the end of the processing of the warnings.
[0087] In the past, when using multiple static analysis tools 20, warnings were sometimes repeatedly displayed, so there was a problem that it took time to make a judgment. However, according to this embodiment, the results of different static analysis tools 20 can be determined to be the same warning, realizing the efficiency of verification.
[0088] In addition, as Figure 13As shown, although it is handled as a warning, the static messages and information about the tool names retain data regarding each static analysis tool 20, so the static analysis results of each static analysis tool 20 can be referred to.
[0089] In addition, in the present embodiment, an example is described in which, in calculating the hash value in the analysis result management device of the first embodiment, with reference to the warning correspondence table 18, the same hash value is assigned to the same warnings detected by a plurality of static analysis tools (refer to Figure 12 ), but the technique of identifying the warnings of the plurality of static analysis tools described in the present embodiment as the same warnings does not necessarily assume the structure of the first embodiment. The hash value calculation unit 14 may also calculate the hash value as Figure 14 shown.
[0090] Figure 14 FIG. is a diagram showing the process of calculating the hash value of the analysis result management device 3 of the third embodiment. The hash value calculation unit 14 first sorts the source files according to the file name and line number (S30). Next, it is determined whether the detector name of the detector that detected the warning to be calculated exists in the warning correspondence table 18 (S31). If the result of this determination is that the detector name exists in the warning correspondence table 18 (in S31, "Yes"), the identification information is read out from the warning correspondence table 18 (S32), and the identification information is used as the input instead of the detector name in the data related to the warning to calculate the hash value (S34).
[0091] If the detector name of the detector that detected the warning to be calculated is not recorded in the warning correspondence table 18 (in S31, "No"), the detector name is referred to (S33), and the hash value is calculated (S34).
[0092] Next, the hash value calculation unit 14 determines whether there are still warnings for which the hash value has not been calculated (S35). If there are warnings for which the hash value has not been calculated (in S35, "Yes"), the process returns to step S31 of determining whether the detector name of the detector that detected the warning to be calculated exists in the warning correspondence table 18. If there are no remaining warnings for which the hash value has not been calculated (in S35, "No"), the calculation process of the hash value for the data of the corresponding static analysis result is ended.
[0093] In addition, the technique described in the present embodiment can of course also be applied to the analysis result management device of the second embodiment.
[0094] (Modification example)
[0095] As described above, the analysis result management device of the present invention has been described in detail with reference to the embodiments. However, the analysis result management device of the present invention is not limited to the above-described embodiments. The analysis result management device may also prepare multiple calculation methods in advance for the calculation of hash values, and be able to select a calculation method that conforms to the development policy of product items, etc. from among them.
[0096] Figure 15 It is a diagram showing the types of inputs used for the calculation of hash values among multiple calculation methods. In Figure 15 the example shown, three calculation methods, calculation methods 1 to 3, are described. Figure 15 It shows the data used as inputs in each calculation method. Specifically, the data "レ" is described as being used for the calculation of hash values.
[0097] The inputs used for the calculation of hash values in calculation method 1 are the file name, detector name, warning message, code of the corresponding line, and in the case of hash value duplication, the code within a specified range is used. The inputs used for the calculation of hash values in calculation method 2 are the file name, detector name, warning message, code of the corresponding line, code of the associated line, and in the case of hash value duplication, the code within a specified range is used. In contrast, the inputs used for the calculation of hash values in calculation method 3 are the file name, detector name, warning message, code of the corresponding line. In calculation method 3, even if hash value duplication occurs, the code within a specified range is not used. That is, in calculation method 3, hash value duplication is allowed.
[0098] In this way, calculation methods 1 to 3 that allow hash value duplication can also be prepared in advance, enabling the user to select which calculation method to use. Specifically, the data of calculation methods 1 to 3 is sent to the user terminal 40, and the calculation methods are displayed on the user terminal 40. Moreover, the analysis result management device 1 is provided with a selection acceptance unit that accepts the selection of a calculation method, and the selection acceptance unit receives the selection data of the calculation method input by the user terminal 40, and sets the calculation method according to the selection data.
[0099] Similarly, in the analysis result management device 3 of the third embodiment, calculation methods that use the warning correspondence table 18 of the analysis results of multiple static analysis tools 20 and those that do not use it can also be prepared in advance, and the user can be allowed to select which calculation method to use.
Claims
1. An analysis result management device is an analysis result management device that manages multiple static analysis result data obtained by analyzing source code using different analysis tools, wherein: The analysis result management device comprises: a table that establishes a correspondence between different warning notations output by the different analysis tools for the same type of warning and identification information; An input unit, receiving input of a plurality of static analysis results of source code; a hash value calculation unit that calculates a hash value of the warning by taking the data related to the warning as input, the hash value calculation unit reading the identification information when there is identification information corresponding to the warning mark to be calculated by hash value by referring to the table, and calculating the hash value by using the read identification information instead of the warning mark; A database stores the warning data and the hash value in correspondence with each other; as well as The display unit displays the data stored in the database.
2. The analysis result management device according to claim 1, wherein: A review result input unit is provided, wherein the review result input unit receives an input of a review result for the warning, The examination result input unit stores the examination result data in the database in association with the hash value corresponding to the warning.
3. The analysis result management device according to claim 2, wherein: The display unit displays warning symbols of a plurality of analysis tools in association with one hash value for warnings having the same hash value.
4. The analysis result management device according to claim 2, wherein: A selection accepting unit is provided, wherein the selection accepting unit accepts a selection of whether to make different static analysis results common with respect to the hash value calculation method, The hash value calculation unit calculates a hash value by taking as input data related to warnings included in the static analysis result input from the analysis tool without referring to the table.
5. The analysis result management device according to claim 2, wherein: The hash value calculation unit calculates a hash value by taking as input data related to the warning, a line related to the warning, and codes of other lines associated with the line in the source code.
6. An analysis result management method, which is an analysis result management method for managing a plurality of static analysis result data obtained by analyzing source code using different analysis tools using an analysis result management device, wherein: The analysis result management method has the following features: The analysis result management device prepares a table in which different warning marks output by the different analysis tools for the same type of warning are associated with identification information; The analysis result management device receives input of a plurality of static analysis results of the source code; the analysis result management device calculates a hash value of the warning by taking data related to the warning as input, and the analysis result management device reads the identification information when referring to the table and finds that there is identification information corresponding to the warning mark to be calculated for the hash value, and calculates the hash value using the read identification information instead of the warning mark; The step of storing the warning data and the hash value in a database in correspondence with each other; as well as The step of displaying the data stored in the database.
7. A program product for managing a plurality of static analysis result data obtained by analyzing source code using different analysis tools, wherein: The program product causes a computer to function as: a table that establishes a correspondence between different warning notations output by the different analysis tools for the same type of warning and identification information; An input unit, receiving input of a plurality of static analysis results of source code; a hash value calculation unit that calculates a hash value of the warning by taking the data related to the warning as input, the hash value calculation unit reading the identification information when there is identification information corresponding to the warning mark to be calculated by hash value by referring to the table, and calculating the hash value by using the read identification information instead of the warning mark; A database stores the warning data and the hash value in correspondence with each other; as well as The display unit displays the data stored in the database.