Analysis result management device, analysis result management method, and program product
By calculating and storing the hash value related to the warning in the static analysis result management device, the problem in the prior art is solved that it is difficult to compare the analysis results and hash value duplication in different versions, and efficient analysis result management and review efficiency are achieved.
Patent Information
- Application Number
- CN202411914722.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2024-12-24
- Publication Date
- 2025-06-27
AI Technical Summary
In the prior art, when managing static analysis results, it is difficult to effectively compare the analysis results of different versions, and the duplication of hash values leads to unjudged warning residues.
By inputting static analysis result data in the analysis result management device, the hash value of the data related to the warning and the code involved in the row is calculated, and the warning data is stored in the database in a corresponding manner with a hash value established.
The appropriate hash value assignment of warnings is achieved, which improves the efficiency of software developers in judging analysis results, reduces source code review time, and improves the management quality of analysis results.
Smart Images

Figure CN120216016A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an analysis result management device for managing analysis results of source code, etc. Background Art
[0002] In software development, due to coding errors, there are often situations where the software does not operate properly. Such errors can be prevented by reviewing the source code, but as the scale of the software increases and the content becomes more complex, the number of such situations increases sharply.
[0003] In order to detect such errors before the execution test of the program, a static analysis system as follows has been developed and sold: performing syntactic or semantic analysis without actually executing the source file of the software, and outputting a warning for a description of the source code that has a possibility of becoming a defect (Bug). Such an analysis system outputs information that can be corrected by software developers.
[0004] The analysis system outputs the result after analyzing the source code, but the number of warnings included in the result is often huge. In software development, multiple versions are made. If a warning that has been confirmed in the previous version is warned again, although it has been confirmed, it still needs to be confirmed again, which is inefficient. Patent Document 1 discloses the following technique: suppressing warning messages by comparing the line and column numbers of the source code, the syntax of the analysis target, and the constituent elements in the syntax between the previous and subsequent versions.
[0005] In addition, conventionally, there has also been known a system as follows: calculating a hash value for a set of source code description contents and tool detection results, and using the hash value to manage the analysis results. By using the hash value, it is possible to simply compare the analysis results for source codes of different versions. Analysis results with the same hash value can be treated as the same, so the analysis results can also be reused. In addition, since the hash value can be used to retrieve warnings, efficient and correct management can be achieved.
[0006] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2004 - 126866
[0007] In Patent Document 1, the analysis results are manually managed, so it is difficult to compare the results of different versions. In addition, the method of Patent Document 1 can suppress warning messages, but it is difficult to reuse and analyze the analysis results.
[0008] In the verification process, it is necessary to confirm each warning, but for the existing method of managing analysis results using hash values, in the case where the warning contents are the same, the hash values are duplicated and the warnings are treated as the same, so there is a risk that unjudged warnings remain. Summary of the Invention
[0009] In view of the above background, an object of the present invention is to provide a technique capable of assigning an appropriate hash value to a warning.
[0010] The present invention includes the following modes.
[0011] An analysis result management device according to one mode of the present invention includes: an input unit that receives an input of static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code; a hash value calculation unit that calculates a hash value by using as input data related to the warning and code of a plurality of lines within a specified range including the line related to the warning; a database that stores the data of the warning in association with the hash value; and a display unit that displays the data stored in the database.
[0012] An analysis result management device according to another mode of the present invention includes: an input unit that receives an input of static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code; a hash value calculation unit that calculates a hash value by using as input data related to the warning, code of the line related to the warning, and code of other lines associated with the line related to the warning in the source code; a database that stores the data of the warning in association with the hash value; and a display unit that displays the data stored in the database.
[0013] An analysis result management method of the present invention is a method of managing static analysis result data by using an analysis result management device, where the static analysis result data includes source code and data of a plurality of warnings detected by statically analyzing the source code. The analysis result management method includes: a step in which the analysis result management device receives an input of the static analysis result data; a step in which the analysis result management device calculates a hash value by using as input data related to the warning and code of a plurality of lines within a specified range including the line related to the warning; a step in which the analysis result management device stores the data of the warning in association with the hash value in a database; and a step in which the analysis result management device displays the data stored in the database.
[0014] Another method for managing analysis result data of the present invention is a method for managing static analysis result data by using an analysis result management device. The above-mentioned static analysis result data includes source code and data of a plurality of warnings detected by performing static analysis on the above-mentioned source code. Among them, the above-mentioned analysis result management method includes: a step of receiving the input of the above-mentioned static analysis result data; a step of calculating a hash value by using, as input, data related to the above-mentioned warning, the code of the line involved in the above-mentioned warning, and the code of other lines associated with the line involved in the above-mentioned warning in the above-mentioned source code; a step of storing, in a database, the data related to the above-mentioned warning in correspondence with the above-mentioned hash value; and a step of displaying the data stored in the above-mentioned database.
[0015] A program of the present invention is a program for managing static analysis result data. The above-mentioned static analysis result data includes source code and data of a plurality of warnings detected by performing static analysis on the above-mentioned source code. Among them, the above-mentioned program causes a computer to function as follows: an input unit that receives the input of the above-mentioned static analysis result data; a hash value calculation unit that calculates a hash value by using, as input, data related to the above-mentioned warning and the code of a plurality of lines within a specified range including the line involved in the above-mentioned warning; a database that stores the data of the above-mentioned warning in correspondence with the above-mentioned hash value; and a display unit that displays the data stored in the above-mentioned database.
[0016] Another program of the present invention is a program for managing static analysis result data. The above-mentioned static analysis result data includes source code and data of a plurality of warnings detected by performing static analysis on the above-mentioned source code. Among them, the above-mentioned program causes a computer to function as follows: an input unit that receives the input of the above-mentioned static analysis result data; a hash value calculation unit that calculates a hash value by using, as input, data related to the above-mentioned warning, the code of the line involved in the above-mentioned warning, and the code of other lines associated with the line involved in the above-mentioned warning in the above-mentioned source code; a database that stores the data of the above-mentioned warning in correspondence with the above-mentioned hash value; and a display unit that displays the data stored in the above-mentioned database.
[0017] According to the present invention, an appropriate hash value can be assigned to a warning, and a software developer can appropriately judge the analysis result. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 FIG. is a diagram showing a functional structure of an analysis result management device according to the first embodiment.
[0019] Figure 2 FIG. is a diagram showing a hardware structure of an analysis result management device according to the first embodiment.
[0020] Figure 3Figure (a) is a diagram showing an example of data of static analysis results stored in a database. Figure 3 Figure (b) is a diagram showing an example of data of review results stored in a database.
[0021] Figure 4 It is a diagram showing an example of source code that is the object of static analysis.
[0022] Figure 5 Figure (a) is a diagram showing the code used for calculating the hash value for explaining the warning of warning line 1. Figure 5 Figure (b) is a diagram showing the code used for calculating the hash value for explaining the warning of warning line 2. Figure 5 Figure (c) is a diagram showing the code used for calculating the hash value for explaining the warning of warning line 3.
[0023] Figure 6 It is a flowchart showing the calculation process of the hash value calculation unit.
[0024] Figure 7 Figure (a) is a diagram showing the code used for calculating the hash value for explaining the warning of warning line 1. Figure 7 Figure (b) is a diagram showing the code used for calculating the hash value for explaining the warning of warning line 2. Figure 7 Figure (c) is a diagram showing the code used for calculating the hash value for explaining the warning of warning line 3.
[0025] Figure 8 It is a diagram showing another example of the hash value calculation of the hash value calculation unit.
[0026] Figure 9 It is a diagram for explaining the calculation process performed by the hash value calculation unit of the analysis result management device according to the second embodiment.
[0027] Figure 10 It is a diagram showing the functional structure of the analysis result management device according to the third embodiment.
[0028] Figure 11 It is a diagram showing an example of data stored in the warning correspondence table.
[0029] Figure 12 It is a diagram for explaining the calculation process of the hash value calculation unit.
[0030] Figure 13 It is a diagram showing an example of a screen that outputs the analysis results managed by the analysis result management device.
[0031] Figure 14 It is a diagram for explaining the calculation process performed by the hash value calculation unit of the analysis result management device according to the third embodiment.
[0032] Figure 15 It is a diagram showing the types of inputs used in the calculation of hash values in multiple calculation methods. Detailed implementation
[0033] Hereinafter, the analysis result management device of the present embodiment will be described with reference to the accompanying drawings. In addition, the following description is only an example showing a preferred mode and is not intended to limit the invention described in the claims.
[0034] (First Embodiment)
[0035] [Overall Structure of Analysis Result Management Device]
[0036] Figure 1 It is a diagram showing the functional structure of the analysis result management device 1 of the present embodiment. The analysis result management device 1 receives the input of the result obtained by analyzing the source code of the software using the static analysis tool 20 and manages the static analysis result data. The analysis result management device 1 receives the input of the static analysis results of multiple static analysis tools 20.
[0037] Figure 2 It is a diagram showing the hardware structure of the analysis result management device 1 of the present embodiment. The analysis result management device 1 is configured on the network, and the analysis result management device 1 and the user terminal 40 can communicate via the network. Here, the type of the network is not limited. For example, it can be the Internet, an intranet within a company, etc. In addition, in the present embodiment, an example of configuring the analysis result management device 1 on the network is shown, but the analysis result management device 1 can also be implemented by a local PC. In this case, the local PC has the functions of the analysis result management device 1 and the user terminal 40.
[0038] The analysis result management device 1 includes a control unit 30 having a CPU 31, a RAM 32, and a ROM 33, an input unit 34, an output unit 35, a storage unit 36, and a communication unit 37. By executing the program stored in the ROM 33, the functions of the analysis result management device 1 described later are realized. Such a program is also within the scope of the present invention.
[0039] Users such as software developers access the analysis result management device 1 from the user terminal 40 through a web browser. The data of the static analysis result is sent from the user terminal 40 to the analysis result management device 1. The analysis result management device 1 manages the data of the static analysis result.
[0040] Return to Figure 1 , the functions of the analysis result management device 1 will be described. The analysis result management device 1 includes a data input unit 11, a data converter 12, a database 15, a display unit 16, and a review result input unit 17.
[0041] The data input unit 11 receives the input of data of the static analysis results of the source file by the static analysis tool 20. The static analysis result data is warning data for the description of the source code that includes the possibility of defects. It is data indicating where in the source code there are what kind of syntax errors, etc. In addition, the data input unit 11 also receives the input of the data of the source file. The input source file is because, as will be described later, the analysis result management device 1 of the present embodiment also uses the data of the source code in the calculation of the hash value.
[0042] As the static analysis tool 20, there are various tools. The data input unit 11 receives the input of data analyzed by different static analysis tools 20. The results of the static analysis vary depending on the static analysis tool 20. A description detected as a warning in one static analysis tool 20 may not be detected as a warning in other static analysis tools 20. This is because, based on the specifications of the static analysis tool 20, the fields in which the static analysis tool 20 is good at analyzing are different. By obtaining the static analysis results of multiple static analysis tools 20, a high-precision review can be performed. The data input unit 11 transfers the input static analysis result data to the data converter 12. In addition, the data input unit 11 stores the source file in the database 15.
[0043] The data converter 12 has a data form conversion unit 13 and a hash value calculation unit 14. The static analysis result data input to the data input unit 11 varies in items or forms (e.g., text data, HTML form, etc.) depending on the static analysis tool 20. The data form conversion unit 13 has a function of converting data forms that are different according to the static analysis result data into a common form.
[0044] The hash value calculation unit 14 has a function of calculating the hash value of the warning included in the static analysis result data. The hash value is unique data calculated based on the data related to the warning and the code of the line involved in the warning, and is used as the identification information for determining the warning. The detailed method of calculating the hash value will be described later.
[0045] By using the hash value as the identification information, it is possible to easily determine the same warning between source files of different versions. Thereby, the trouble of re-reviewing warnings that have already been reviewed can be saved, and the source code review time can be significantly reduced.
[0046] The database 15 stores the static analysis results, review results, and source files. The data of the static analysis results stores the static analysis result data after converting the data form by the data converter 12 and assigning a hash value to the warning.
[0047] Figure 3(a) is a diagram showing an example of data of the static analysis results stored in the database 15. The data of the static analysis results has, corresponding to the hash value, data of file name, detector name, warning message, tool name, severity, line, and column. The hash value is identification information for determining the warning, and is calculated based on the data related to the warning and the data of the code of the line involved in the warning.
[0048] The file name is the file name of the source file that is the object of the static analysis. The detector name is the name of the detector that detected the warning. One static analysis tool 20 has multiple detector algorithms, and searches for potentially defective code by executing the detector algorithms and outputs warnings. The warning message is a message for notifying the user of the content of the warning.
[0049] The tool name is the name of the static analysis tool 20 that detected the warning. The severity is data indicating the severity level of the warning. It is represented by a numerical value from 0 to 30, and the larger the number, the more serious the content of the warning. The line and column are data for determining the position of the code involved in the warning. The line indicates which line the warning starts from, and the column indicates which column it is within the file. In addition, what is shown here is an example, and the data of the static analysis results may also include Figure 3 data other than those shown in (a).
[0050] Figure 3 The notations of the data of the detector name, warning message, tool name, and severity in the static analysis results data shown in (a) vary depending on the static analysis tool 20, and are data for differently notating the same code error.
[0051] Figure 3 (b) is a diagram showing an example of data of the review results stored in the database 15. The data of the review results has, corresponding to the hash value, data of status, confirmator, comment, and confirmation date and time. The hash value corresponds to the hash value included in the static analysis results data and determines the warning. The status is the status of the review situation for the warning determined by the hash value. For example, "confirmed" indicates that the confirmation is complete, and "unreviewed" indicates that it has not been reviewed yet. The confirmator is the name of the user who reviewed the warning and changed the status. The comment is a comment on what kind of processing was done for the warning when the warning review was completed. The confirmation date and time is data of the date and time when the content of the warning was confirmed. In addition, what is shown here is an example, and the data of the review results may also include Figure 3 data other than those shown in (b).
[0052] The display unit 16 has a function of displaying the analysis result data stored in the database 15 on the user terminal 40. Specifically, according to a request from the user terminal 40, the analysis result data is read out from the database 15, and the analysis result data is sent to the user terminal 40, causing the user terminal 40 to display the analysis result data.
[0053] If data of the review result is sent from the user terminal 40, the review result input unit 17 stores the sent review result in the database 15 in association with the hash value indicating the corresponding warning. Specifically, the review result input unit 17 updates the status, confirmator, comment, and confirmation date and time of the warning determined by the hash value.
[0054] [Calculation of Hash Value]
[0055] Next, the calculation process of the hash value by the hash value calculation unit 14 will be described. The hash value calculation unit 14 calculates the hash value by taking as input the data related to the warning and the code involved in the warning. As the data related to the warning, the file name of the source file, the name of the detector that has performed the analysis, and the warning message are used. In addition, what is shown here is an example of the data related to the warning used in the calculation of the hash value. Of course, other data related to the warning can also be used in the calculation of the hash value.
[0056] Figure 4 is a diagram showing an example of the source code that is the object of static analysis. Taking the Figure 4 shown code as an example, the calculation of the hash value will be described. In the Figure 4 shown example, it is possible that there is an error in the code "len++", which is detected as a warning. The hash value calculation unit 14 calculates the hash value by taking as input, in addition to the data related to the warning, the code involved in the warning, that is, "len++".
[0057] In addition, line numbers are not used in the calculation of the hash value. By adopting a structure in which line numbers are not included in the calculation of the hash value, in source codes with different versions, for example, even when the line numbers are offset due to the addition of blank lines, the hash values are the same, and it can be recognized as the same warning. However, by adopting a structure in which line numbers are not used in the calculation of the hash value, in the case where the same warning exists in multiple lines, those hash values become the same value.
[0058] Refer to Figure 4, the codes of Warning Line 1 to Warning Line 3 are the same. Therefore, the content of the data related to the warning (specifically, the file name of the source file, the name of the detector that has been analyzed, and the warning message) is also the same. In this way, the hash values of the codes for Warning Line 1 to Warning Line 3 are the same, and the same identification information is assigned to the warnings for Warning Line 1 to Warning Line 3, and they are processed as one warning. Although there is an idea that such processing is sufficient, in the analysis result management device 1 of the present embodiment, even if multiple warnings have the same content, they are processed as different warnings. The hash value calculation unit 14 calculates hash values so as to distinguish Figure 4 the same warnings as shown.
[0059] When the hash value (referred to as "first hash value" for ease of explanation) calculated by using the data related to the warning and the code of the line related to the warning as input duplicates any of the calculated hash values, the hash value calculation unit 14 uses the codes of multiple lines from the line related to the warning where the first hash value duplicates to the line related to the warning as input to calculate a hash value (referred to as "second hash value" for ease of explanation), and uses the second hash value as the hash value for the warning.
[0060] Figure 5 is a diagram showing the codes used for calculating the hash values of the warnings for Warning Line 1 to 3. In the explanation using Figure 5 , the focus is on the code, but as described above, the data related to the warning is used as the input for hash value calculation. Figure 5 The (a) of shows the code used to calculate the hash value of the warning for Warning Line 1. The code of the fourth line surrounded by box a is used as the input.
[0061] Figure 5 The (b) of shows the code used to calculate the hash value of the warning for Warning Line 2. In addition to the code surrounded by box a, the code of the fifth line surrounded by box b from the warning line 1 where the first hash value is determined to duplicate to warning line 2 is used as the input. Figure 5 The (c) of shows the code used to calculate the hash value of the warning for Warning Line 3. In addition to the code surrounded by box a, the codes of the fifth to seventh lines surrounded by box c from the warning line 1 where the first hash value is determined to duplicate to warning line 3 are used as the input.
[0062] As Figure 5 shown in (a) to Figure 5 shown in (c) of , even when the same warning is detected for the code "len++", the hash values can be distinguished by changing the range of the code used for hash value calculation.
[0063] Figure 6It is a flowchart showing the calculation process of the hash value calculation unit 14. First, the hash value calculation unit 14 sorts all the warnings in the static analysis result data according to the file name and line number of the warning (S10). Next, the hash value calculation unit 14 takes the data related to the warning and the code of the line involved in the warning as input, calculates the first hash value (S11), and determines whether there already exists a hash value identical to the calculated first hash value (S12).
[0064] In the case where there exists an identical hash value (Yes in S12), the hash value calculation unit 14 uses, in addition to the data related to the warning and the code of the line involved in the warning, the code from the line where the initial hash value repeats to the warning line being calculated to calculate the second hash value (S13), and takes the second hash value as the hash value for the warning. At this time, for parts such as blanks and comments that do not directly affect the warning, they can be used for the calculation of the hash value or not. Next, the hash value calculation unit 14 determines whether there remains a warning for which the hash value has not been calculated (S14). In the case where there remains a warning for which the hash value has not been calculated (Yes in S14), it returns to step S11 for calculating the first hash value for this warning.
[0065] In the determination of whether there already exists a hash value identical to the first hash value (S12), in the case where it is determined that there is no identical hash value (No in S12), the first hash value is taken as the hash value for the warning being calculated. In the determination of whether there remains a warning for which the hash value has not been calculated (S14), in the case where there is no warning for which the hash value has not been calculated (No in S14), the calculation process of the hash value for the corresponding static analysis result data is ended.
[0066] As described above, the analysis result management device 1 and the analysis result management method of the first embodiment have been explained. In the case where the first hash value repeats the already existing hash value, the analysis result management device 1 of the first embodiment takes the code from the warning line where the initial hash value repeats to the warning line being calculated as input to calculate the second hash value, thereby being able to avoid the repetition of the hash value. The code before the repetition of the initial hash value does not affect the calculation of the second hash value, so even if corrections have been made previously, the differential analysis between versions will not be affected. Thus, warnings can be appropriately managed.
[0067] The software under development changes frequently due to version upgrades and the like. Therefore, it is important to identify the change points and problem points. According to the analysis result management device 1 of the present embodiment, by devising a method for managing the analysis results of the source codes before and after the software under development and identifying the change points and problem points, as well as a method for managing the analysis results, different warnings can be distinguished, and undetected problems can be improved.
[0068] In the above-described first embodiment, when calculating the second hash value, the code from the warning line where the initial hash value repeats to the warning line of the calculation target is used as the input. However, codes in other ranges can also be used as the input. For example, the code from the first line of the source code to the warning line of the calculation target can be used as the input to calculate the hash value.
[0069] Figure 7 It is a diagram showing an example of the code used for calculating the second hash value. Figure 7 (a) to Figure 7 (c) respectively correspond to Figure 5 (a) to Figure 5 (c), showing an example of obtaining the hash values of warning lines 1 to 3.
[0070] In Figure 7 (a), since the hash value of warning line 1 does not repeat, the code related to warning line 1 is used as the input to calculate the hash value. When calculating the hash value of warning line 2, the first hash value obtained by using only the code of warning line 2 repeats the hash value of warning line 1. Therefore, as shown in Figure 7 (b), the hash value calculation unit 14 uses the code in the range surrounded by the box d from the first line of the source code to warning line 2 as the input to calculate the second hash value.
[0071] When calculating the hash value of warning line 3, the first hash value obtained by using only the code of warning line 3 repeats the hash value of warning line 1. Therefore, as shown in Figure 7 (c), the hash value calculation unit 14 uses the code in the range surrounded by the box e from the first line of the source code to warning line 3 as the input to calculate the second hash value. With such a structure, duplication of hash values can also be avoided.
[0072] In addition, as another example of the range of the code used for calculating the hash value, the code from the previous warning line to the warning line of the calculation target can be used as the input. Figure 8 It is a diagram showing an example of such calculation. In Figure 8 , the three lines starting with "tmp =" are warning lines 1 to 3.
[0073] In Figure 8 , since the hash value of warning line 1 does not repeat, the code related to warning line 1 is used as the input to calculate the hash value. When calculating the hash value of warning line 2, the first hash value obtained by using only the code of warning line 2 repeats the hash value of warning line 1. Therefore, the hash value calculation unit 14 uses the code in the range surrounded by the box f from the next line of warning line 1 to warning line 2 as the input to calculate the second hash value.
[0074] When calculating the hash value of warning line 3, the first hash value calculated only using the code of warning line 3 is the same as the hash value of warning line 1. Therefore, the hash value calculation unit 14 calculates the second hash value using the code in the range surrounded by the box g from the next line of the previous warning line 2 to warning line 3 as the input. With such a structure, it is also possible to reduce the duplication of hash values.
[0075] (Second Embodiment)
[0076] Next, the analysis result management device of the second embodiment will be described. The basic structure of the analysis result management device of the second embodiment is the same as that of the analysis result management device 1 of the first embodiment (refer to Figure 1 and Figure 2 ), but the difference in the second analysis result management device is that it also calculates the hash value considering the process information associated with the warning line.
[0077] Figure 9 is a diagram for explaining the calculation process performed by the hash value calculation unit 14 of the analysis result management device of the second embodiment. In Figure 9 , the warning line is "case 1: result = a / ZERO; break;" surrounded by the box a, and it is possible that dividing a by ZERO is incorrect. Here, ZERO is defined as 0 by "#define ZERO 0" surrounded by the box h. That is, the variable in the code surrounded by the box a refers to the code surrounded by the box h, and these two lines are associated. In the source code, when a certain problem is found as a warning, it is sometimes necessary to view the processing flow up to the part where the problem occurs. In this specification, such a movement on the source code is called "process information".
[0078] When calculating the hash value of the warning line surrounded by the box a, the hash value calculation unit 14 calculates the hash value using the code of the line surrounded by the box h in addition to the code of the warning line as the input.
[0079] According to the analysis result management device of the second embodiment, by calculating the hash value considering not only the warning message and the source code but also the process information associated with the warning line, it is possible to suppress the occurrence of undetected warnings and improve the quality of the management of the analysis results.
[0080] In addition, in this embodiment, in addition to the structure of the analysis result management device 1 of the first embodiment, the calculation of the hash value considering the process information is also described. However, the calculation of the hash value considering the process information described in the second embodiment is not based on the method of calculating the hash value to avoid duplication of hash values described in the first embodiment. Therefore, in an analysis result management device that allows the same hash value to be assigned to the same type of warning, it is also possible to calculate the hash value considering the process information.
[0081] (Third Embodiment)
[0082] Figure 10 FIG. 6 is a diagram showing the functional structure of the analysis result management apparatus 3 according to the third embodiment. The basic structure of the analysis result management apparatus 3 according to the third embodiment is the same as that of the analysis result management apparatus 1 according to the first embodiment, but the analysis result management apparatus 3 according to the third embodiment includes a warning correspondence table 18. The warning correspondence table 18 is a table showing the correspondence relationship of detectors that detect warnings of the same type in the static analysis result data based on a plurality of static analysis tools 20.
[0083] Figure 11 FIG. 7 is a diagram showing an example of the data stored in the warning correspondence table 18. The warning correspondence table 18 shows the correspondence relationship of the detector names of tools X, Y, and Z as the static analysis tools 20. In Figure 11 the example shown, "Division By Zero" in tool X, "core.DivideZero" in tool Y, and "Integer divisionby zero" in tool Z correspond to each other. The warning correspondence table 18 associates the identification information with the detector names of each tool. Here, the identification information "INT31-C" is a string attached to the rule of "ensuring that data disappearance and misinterpretation do not occur due to integer conversion" in the CERT C coding standard. Meaningful strings can be used as identification information in this way, but as long as there is no duplication, meaningless random information can also be used. In addition, in Figure 11 , the warning correspondence table 18 stores the correspondence of the detector names of three analysis tools, but the correspondence of the detector names of four or more analysis tools can also be established. When the number of analysis tools increases, the detector names of the new analysis tools can be registered in the warning correspondence table 18.
[0084] When calculating the hash value of a warning, the hash value calculation unit 14 determines whether the detector name that detected the warning to be calculated is recorded in the warning correspondence table 18. When the detector name is recorded in the warning correspondence table 18, the identification information corresponding to the detector name is read out, and the identification information is used as the input instead of the detector name to calculate the hash value.
[0085] Figure 12 FIG. 8 is a diagram for explaining the calculation process of the hash value calculation unit 14. Figure 12 The process shown is the positioning of the specific process of the first hash value calculation (S11) or the second hash value calculation (S13) in the hash value calculation process shown in Figure 6 .
[0086] When the analysis result management device 3 of the third embodiment calculates the hash value, it first determines whether the detector name of the detector that has detected a warning for the calculation target exists in the warning correspondence table 18 (S20). If the determination result is that the detector name exists in the warning correspondence table 18, the identification information is read from the warning correspondence table 18 (S21), and the identification information is used as the input instead of the detector name in the data related to the warning to calculate the hash value (S23). That is, as the data related to the warning, the file name of the source file and the identification information are used. In addition, when calculating the hash value in the analysis result management device 1 of the first embodiment, as the information related to the warning, the file name of the source file, the name of the detector that has performed the analysis, and the warning message are used, but the warning message is not used in this embodiment.
[0087] When the detector name of the detector that has detected a warning for the calculation target is not recorded in the warning correspondence table 18 ( "No" in S20), the detector name is referred to (S22), and the hash value is calculated (S23). That is, as the data related to the warning, the file name of the source file and the detector name are used.
[0088] Figure 13 It is a diagram showing an example of a screen for outputting the analysis results managed by the analysis result management device 3. The analysis results include, corresponding to the hash value for determining the warning, the file name of the source file in which the warning was detected, the detector name of the detector that detected the warning, the warning message, the tool name of the static analysis tool 20 that detected the warning, the severity indicating the severity of the warning, and the data of the review result for the warning.
[0089] In this embodiment, when the warnings detected by multiple static analysis tools 20 are warnings for the same code, they are output as one warning. Specifically, in Figure 13 the hash value of the third line in is associated with the data of three tools, namely tool K, tool L, and tool M. Although the warnings are detected by each of the three static analysis tools 20, since they are warnings for the same code, they are processed as one warning. It is not necessary to process the warnings for each static analysis tool 20, and as long as the review result is input once, it is possible to set the completion of the processing of the warnings.
[0090] In the past, when using multiple static analysis tools 20, warnings were sometimes repeatedly displayed, so there was a problem that it took time to make a judgment. However, according to this embodiment, the results of different static analysis tools 20 can be determined to be the same warning, achieving the efficiency of verification.
[0091] In addition, as Figure 13As shown, although it is handled as a warning, information on static messages and tool names remains data regarding each static analysis tool 20, so the static analysis results of each static analysis tool 20 can be referred to.
[0092] In addition, in the present embodiment, an example has been described in which, in calculating the hash value in the analysis result management device of the first embodiment, with reference to the warning correspondence table 18, the same hash value is given to the same warnings detected by a plurality of static analysis tools (refer to Figure 12 ), but the technique of identifying the warnings of the plurality of static analysis tools described in the present embodiment as the same warning does not necessarily assume the structure of the first embodiment. The hash value calculation unit 14 may also calculate the hash value as Figure 14 shown.
[0093] Figure 14 is a diagram showing the process of calculating the hash value of the analysis result management device 3 of the third embodiment. The hash value calculation unit 14 first sorts the source files according to the file name and line number (S30). Next, it is determined whether the detector name of the detector that detected the warning to be calculated exists in the warning correspondence table 18 (S31). If the result of this determination is that the detector name exists in the warning correspondence table 18 (in S31, "yes"), the identification information is read out from the warning correspondence table 18 (S32), and the identification information is used as the input instead of the detector name in the data related to the warning to calculate the hash value (S34).
[0094] If the detector name of the detector that detected the warning to be calculated is not recorded in the warning correspondence table 18 (in S31, "no"), the detector name is referred to (S33), and the hash value is calculated (S34).
[0095] Next, the hash value calculation unit 14 determines whether there are still warnings for which the hash value has not been calculated (S35). If there are warnings for which the hash value has not been calculated (in S35, "yes"), the process returns to step S31 of determining whether the detector name of the detector that detected the warning to be calculated exists in the warning correspondence table 18. If there are no remaining warnings for which the hash value has not been calculated (in S35, "no"), the calculation process of the hash value for the data of the corresponding static analysis result is ended.
[0096] In addition, the technique described in the present embodiment can of course also be applied to the analysis result management device of the second embodiment.
[0097] (Modification example)
[0098] As described above, the analysis result management apparatus of the present invention has been described in detail with reference to the embodiments. However, the analysis result management apparatus of the present invention is not limited to the above-described embodiments. The analysis result management apparatus may also prepare a plurality of calculation methods in advance for the calculation of the hash value, and be able to select a calculation method that conforms to the development policy of the product item or the like from among them.
[0099] Figure 15 It is a diagram showing the types of inputs used for the calculation of the hash value among a plurality of calculation methods. In Figure 15 the example shown, three calculation methods, calculation methods 1 to 3, are described. Figure 15 It shows the data used as the input in each calculation method. Specifically, the data "レ" is described as being used for the calculation of the hash value.
[0100] The inputs used for the calculation of the hash value in calculation method 1 are the file name, detector name, warning message, code of the corresponding line, and in the case of hash value duplication, the code within a specified range is used. The inputs used for the calculation of the hash value in calculation method 2 are the file name, detector name, warning message, code of the corresponding line, code of the associated line, and in the case of hash value duplication, the code within a specified range is used. In contrast, the inputs used for the calculation of the hash value in calculation method 3 are the file name, detector name, warning message, code of the corresponding line. In calculation method 3, even if hash value duplication occurs, the code within a specified range is not used. That is, in calculation method 3, hash value duplication is allowed.
[0101] In this way, calculation methods 1 to 3 including the case where hash value duplication is allowed may also be prepared in advance, and the user may be allowed to select which calculation method to use. Specifically, the data of calculation methods 1 to 3 is transmitted to the user terminal 40, and the calculation methods are displayed on the user terminal 40. Moreover, the analysis result management apparatus 1 includes a selection acceptance unit that accepts the selection of the calculation method, and the selection acceptance unit receives the selection data of the calculation method input by the user terminal 40, and sets the calculation method according to the selection data.
[0102] Similarly, in the analysis result management apparatus 3 of the third embodiment, a calculation method that uses the warning correspondence table 18 of the analysis results of a plurality of static analysis tools 20 and a calculation method that does not use it may also be prepared in advance, and the user may be allowed to select which calculation method to use.
Claims
1. An analysis result management device, wherein: have: An input unit receives input of static analysis result data, wherein the static analysis result data includes source code and data of a plurality of warnings detected by statically analyzing the source code; a hash value calculation unit that calculates a hash value by taking as input data related to the warning and codes of a plurality of lines within a prescribed range including the line involved in the warning; A database stores the warning data and the hash value in correspondence with each other; as well as The display unit displays the data stored in the database.
2. The analysis result management device according to claim 1, wherein: When a first hash value calculated by taking data related to the warning and a code of a row involved in the warning as inputs overlaps with any of the calculated hash values, the hash value calculation unit calculates a second hash value by taking data related to the warning and a plurality of codes of rows within a specified range including the row involved in the warning as inputs, and uses the second hash value as the hash value for the warning.
3. The analysis result management device according to claim 2, wherein: When a first hash value calculated by taking data related to the warning and a code of a row involved in the warning as inputs overlaps with any of the calculated hash values, the hash value calculation unit calculates a second hash value by taking data related to the warning and a plurality of codes of rows from the row involved in the warning where the initial hash value overlaps to the row involved in the warning that is a calculation target as inputs.
4. The analysis result management device according to claim 2, wherein: A selection accepting unit is provided, wherein the selection accepting unit accepts a selection of whether to allow the first hash value to be repeated with any one of the calculated hash values in relation to the hash value calculation method. When the duplication permission is selected, the hash value calculation unit obtains the first hash value as the hash value of the warning even when the first hash value overlaps with any of the calculated hash values.
5. The analysis result management device according to claim 2, wherein: The hash value calculation unit calculates a hash value by taking as input data related to the warning, a line related to the warning, and codes of other lines associated with the line related to the warning in the source code.
6. The analysis result management device according to claim 2, wherein: The hash value calculation unit calculates the second hash value each time it is determined that the first hash value overlaps with any of the calculated hash values.
7. An analysis result management device, wherein: have: An input unit receives input of static analysis result data, wherein the static analysis result data includes source code and data of a plurality of warnings detected by statically analyzing the source code; a hash value calculation unit that calculates a hash value by taking as input data related to the warning, code of the line involved in the warning, and code of other lines associated with the line involved in the warning in the source code; A database stores the warning data and the hash value in correspondence with each other; as well as The display unit displays the data stored in the database.
8. An analysis result management method, which is a method for managing static analysis result data using an analysis result management device, wherein the static analysis result data includes source code and data of multiple warnings detected by statically analyzing the source code, wherein: The analysis result management method has the following features: The step of the analysis result management device accepting input of the static analysis result data; The analysis result management device calculates a hash value by taking as input data related to the warning and codes of a plurality of lines within a prescribed range including the line involved in the warning; The analysis result management device stores the warning data and the hash value in a database in correspondence with each other; as well as The analysis result management device displays the data stored in the database.
9. An analysis result management method, which is a method for managing static analysis result data using an analysis result management device, wherein the static analysis result data includes source code and data of multiple warnings detected by statically analyzing the source code, wherein: The analysis result management method has the following features: The step of accepting input of the static analysis result data; A step of calculating a hash value by taking data related to the warning, code of the line involved in the warning, and code of other lines associated with the line involved in the warning in the source code as input; The step of storing the data related to the warning in a database in correspondence with the hash value; as well as The step of displaying the data stored in the database.
10. A program product for managing static analysis result data, the static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, wherein: The program product causes a computer to function as: An input unit, receiving input of the static analysis result data; a hash value calculation unit that calculates a hash value by taking as input data related to the warning and codes of a plurality of lines within a prescribed range including the line involved in the warning; A database stores the warning data and the hash value in correspondence with each other; as well as The display unit displays the data stored in the database.
11. A program product for managing static analysis result data, the static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, wherein: The program product causes a computer to function as: An input unit, receiving input of the static analysis result data; a hash value calculation unit that calculates a hash value by taking as input data related to the warning, code of the line involved in the warning, and code of other lines associated with the line involved in the warning in the source code; A database stores the warning data and the hash value in correspondence with each other; as well as The display unit displays the data stored in the database.
Citation Information
Patent Citations
Description output suppression program analysis system and description output suppression program analysis method
JP2004126866A