Analysis result management device, analysis result management method and program therefor

The analysis result management device addresses inefficiencies in managing static analysis results by calculating hash values based on warning-related data and code ranges, ensuring efficient and accurate handling of warnings across software versions.

DE102024136393A1Pending Publication Date: 2025-06-26DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102024136393
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing static analysis systems struggle with managing analysis results across different versions of software, leading to inefficiencies and potential duplication of work due to the reuse of previously confirmed warnings, and there is a risk of indeterminate alerts when using hash values for result management.

Method used

An analysis result management device that calculates a hash value for each warning using warning-related data and a range of code in the source code, allowing for accurate identification and differentiation of warnings across versions, even when line numbers change.

Benefits of technology

Enables efficient management and reuse of analysis results by accurately identifying and distinguishing warnings, reducing redundant checks and improving the accuracy of software development processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An analysis result management device includes: an input unit (11) that receives an input of static analysis result data, the static analysis result data including a source code and data of a plurality of warnings, the respective warnings being acquired by statically analyzing the source code; a hash value calculation unit (14) that calculates a hash value for each of the warnings using as inputs (i) warning data that is data concerning the respective warnings and (ii) a code in a plurality of lines within a predetermined range of the source code, the lines including a warning line from which the corresponding warning is acquired; a database (15) that stores the data of the respective warnings in association with the corresponding hash value; and a display unit (16) that displays the data stored in the database.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to an analysis result management apparatus that manages analysis results of a source code.

[0002] In software development, coding errors often lead to incorrect software operation. Although it is possible to prevent incorrect operation by reviewing the source code, the number of errors increases dramatically as the size and complexity of the software increases.

[0003] To detect such errors before testing the program, static analysis systems have been developed and are commercially available. Static analysis systems analyze software source files syntactically and semantically without actually executing the software source files and issue warnings describing source code that may contain errors or bugs. This type of analysis system outputs the information in such a way that a software developer can use the output to correct the source code.

[0004] The analysis system outputs an analysis result of the source code. In some cases, the analysis result contains a large number of warnings. When multiple versions of software programs are generated during software development, and a warning that has already been confirmed or checked in a previous version is issued again in a subsequent version, the software developer must reconfirm or check the warning even if the warning was already confirmed in the previous version. This can reduce work efficiency. JP 2004-126866A discloses a technique for suppressing warning messages by comparing line and column numbers of a source code, an analysis target syntax, and components included in the syntax between the previous version of the software code and the subsequent version of the software code.

[0005] A system is known that calculates a hash value for a sentence from a source code description content and a tool acquisition result, and manages the analysis result using the hash value. Using the hash value makes it easy to compare analysis results for different versions of the source code. Since the analysis results with the same hash value can be treated equally, reuse of the analysis result becomes possible. Warnings can be searched using the hash value, thereby increasing work efficiency and management accuracy.

[0006] In JP 2004 - 126 866 A, since the management of analysis results is performed manually, it is difficult to compare different versions of analysis results. Although the procedure in JP 2004 - 126 866 A can prevent warning messages, it is difficult to reuse or further analyze the analysis result.

[0007] The verification process requires each alert to be verified. In the traditional method of managing analysis results using hash values, if the alert contents are the same, the hash value is duplicated and treated as the same alert. Thus, there is a risk that indeterminate alerts remain.

[0008] In view of this, it is an object of the present invention to provide a technique capable of assigning an appropriate hash value to an alert.

[0009] According to one aspect of the present invention, an analysis result management device includes an input unit, a hash value calculation unit, a database, and a display unit. The input unit receives input of static analysis result data. The static analysis result data includes source code and data of a plurality of warnings, and each of the warnings is acquired by statically analyzing the source code. The hash value calculation unit calculates a hash value for each of the warnings using (i) warning-related data (warning data), which is data concerning the respective warnings, and (ii) code in a plurality of lines within a predetermined range of the source code as inputs. The lines include a warning-related line from which the corresponding warning is acquired. The database stores the data of each of the warnings in association with the corresponding hash value.The display unit shows the data stored in the database.

[0010] According to another aspect of the present invention, an analysis result management database includes an input unit, a hash value calculation unit, a database, and a display unit. The input unit receives an input of static analysis result data. The static analysis result data includes source code and data of a plurality of warnings, and each of the warnings is acquired by statically analyzing the source code. The hash value calculation unit calculates a hash value for each of the warnings using (i) warning-related data, which is data related to the respective warnings, (ii) a code in a warning-related line from which the corresponding warning is acquired, and (iii) a code in another line related to the warning-related line within the source code as inputs. The database stores the data of each of the warnings in association with the corresponding hash value.The display unit shows the data stored in the database.

[0011] According to another aspect of the present invention, a computer-implemented method for managing static analysis result data is performed by an analysis result management device. The static analysis result data includes source code and data of a plurality of warnings acquired by statically analyzing the source code.The management method includes: receiving, by means of the analysis result management device, an input of the static analysis result data; calculating a hash value for each of the warnings using, by means of the analysis result management device, (i) warning-related data that is data concerning the respective warnings and (ii) code in a plurality of lines within a predetermined range of the source code as inputs, the lines including a warning-related line from which the corresponding warning is acquired; storing, by means of the analysis result management device, the data of the respective warnings in a database in association with the corresponding hash value; and displaying, by means of the analysis result management device, the data stored in the database.

[0012] According to another aspect of the present invention, a computer-implemented method for managing static analysis result data is performed by an analysis result management device. The static analysis result data includes source code and data of a plurality of warnings acquired by statically analyzing the source code.The management method includes: receiving an input of the static analysis result data; calculating a hash value using (i) alert-related data, which is data concerning the respective alerts, (ii) a code in a line concerning an alert from which the corresponding alert is acquired, and (iii) a code in another line concerning the alert-related line within the source code as inputs, for each of the alerts; storing the data of the respective alerts in a database in association with the corresponding hash value; and displaying the data stored in the database.

[0013] According to another aspect of the present invention, a computer program for managing static analysis result data is executed by an analysis result management device. The static analysis result data includes source code and data of a plurality of warnings acquired by statically analyzing the source code.The computer program causes a computer to serve as: an input unit that receives an input of the static analysis result data; a hash value calculation unit that calculates a hash value for each of the alerts using (i) alert-related data that is data concerning the respective alerts and (ii) code in a plurality of lines within a predetermined range of the source code as inputs for each of the alerts, the lines containing the alert-related line from which the corresponding alert is acquired; a database that stores the data of the respective alerts in association with the corresponding hash value; and a display unit that displays the data stored in the database.

[0014] According to another aspect of the present invention, a computer program for managing static analysis result data is executed by an analysis result management device. The static analysis result data includes source code and data of a plurality of warnings acquired by statically analyzing the source code.The computer program causes a computer to serve as: an input unit that receives an input of the static analysis result data; a hash value calculation unit that calculates a hash value for each of the alerts using (ii) alert-related data that is data related to the respective alerts, (ii) a code in a line related to an alert from which the corresponding alert is acquired, and (iii) a code in another line related to the line related to an alert within the source code as inputs; a database that stores the data of the respective alerts in association with the corresponding hash value; and a display unit that displays the data stored in the database.

[0015] According to the present invention, a hash value can be correctly calculated and assigned to a warning, thereby enabling a software developer to appropriately evaluate the analysis result.

[0016] Further objects and advantages of the present invention will become apparent from the following detailed description with reference to the accompanying drawings. Fig. 1 is a diagram showing a functional configuration of an analysis result management apparatus according to a first embodiment; Fig. 2 is a diagram showing a hardware configuration of the analysis result management apparatus according to the first embodiment; Fig. 3A is a diagram showing an example of static analysis result data stored in a database; Fig. 3B is a diagram showing an example of verification result data stored in a database; Fig. 4 a diagram showing an example of source code that is a target of static analysis; Fig. 5A is a diagram showing the code used to calculate a hash value of an alert in alert line 1; Fig. 5B is a diagram showing the code used to calculate a hash value of an alert in alert line 2; Fig. 5C is a diagram showing the code used to calculate a hash value of an alert in alert line 3; Fig. 6 is a flowchart showing a calculation process performed by a hash value calculation unit; Fig. 7A is a diagram showing the code used to calculate a hash value of an alert in alert line 1; Fig. 7B is a diagram showing the code used to calculate a hash value of an alert in alert line 2; Fig. Figure 7C is a diagram showing the code used to calculate a hash value of an alert in alert line 3; Fig. 8 is a diagram showing another example of a hash value calculation performed by a hash value calculation unit; Fig. 9 is a diagram explaining a calculation process performed by a hash value calculation unit of an analysis result management apparatus according to a second embodiment; Fig. 10 is a diagram showing a functional configuration of an analysis result management apparatus according to a third embodiment; Fig. 11 is a diagram showing an example of data stored in a warning correspondence table; Fig. 12 is a diagram explaining a calculation process performed by a hash value calculation unit; Fig. 13 is a diagram showing an example of a screen displaying an analysis result managed by an analysis result managing device; Fig. 14 is a diagram explaining a calculation process performed by a hash value calculation unit of an analysis result management apparatus according to a third embodiment; and Fig. 15 is a diagram showing types of inputs used to calculate hash values ​​in different calculation methods.

[0017] Hereinafter, an analysis result management apparatus according to the present invention will be described with reference to the drawings. First EmbodimentOverall Configuration of the Analysis Result Management Device

[0018] Fig. 1 is a diagram showing a functional configuration of an analysis result management device 1 according to the present embodiment. The analysis result management device 1 receives an analysis result of a software source code managed by a static analysis tool 20 as an input and manages the received static analysis result data. The analysis result management device 1 receives multiple records of static analysis results from multiple static analysis tools 20.

[0019] Fig. 2 is a diagram showing a hardware configuration of the analysis result management device 1 according to the present embodiment. The analysis result management device 1 is arranged on a network. The analysis result management device 1 and a user terminal 40 can communicate with each other via the network. The type of network is not limited to a specific type. The network may be, for example, the Internet, an in-house intranet, or the like. In the present embodiment, for example, the analysis result management device 1 is arranged on a network. According to another example, the analysis result management device 1 may be provided by a local personal computer (hereinafter referred to as a local PC). In this case, the local PC has the functions of the analysis result management device 1 and the user terminal 40.

[0020] The analysis result management device 1 includes a controller 30 having a CPU 31, a RAM 32, and a ROM 33. The analysis result management device 1 also includes an input unit 34, an output unit 35, a memory 36, and a communication unit 37. By executing programs stored in the ROM 33, the functions of the analysis result management device 1 are implemented. The functions of the analysis result management device 1 will be described later. The programs executed by the analysis result management device 1 are also included within the scope of the present invention.

[0021] A user such as a software developer accesses the analysis result management device 1 via a web browser using the user terminal 40. The user terminal 40 transmits data of a static analysis result to the analysis result management device 1. The analysis result management device 1 manages the data of the static analysis result.

[0022] Based on Fig. 1, the functions of the analysis result management device 1 are described. The analysis result management device 1 includes a data input unit 11, a data converter 12, a database 15, a display unit 16, and a verification result input unit 17.

[0023] The data input unit 11 receives input of static analysis result data indicating a static analysis result of a source file. The static analysis result is generated by a static analysis tool 20. The static analysis result data is warning data of a source code description that may contain bugs. The static analysis result data indicates a location of a syntax error within the source code and a type of the syntax error. The data input unit 11 also receives input of source file data. The reason why the source file is input to the data input unit will be described later. The analysis result management device 1 of the present embodiment also uses the source code data to calculate a hash value.

[0024] There are various types of static analysis tools 20. The data input unit 11 receives multiple types of analysis data from different static analysis tools 20. The static analysis results vary depending on the type of static analysis tool 20. A description detected as a warning by one static analysis tool 20 may not be detected as a warning by another static analysis tool 20. This is because the specifications of the static analysis tools 20 differ from each other and different static analysis tools 20 are good at different analysis fields. By inputting multiple static analysis results from multiple static analysis tools 20, highly accurate verification can be performed. The data input unit 11 transmits the input static analysis result data to the data converter 12.The data entry unit 11 stores the source file in the database 15.

[0025] The data converter 12 includes a data format conversion unit 13 and a hash value calculation unit 14. The static analysis result data input to the data input unit 11 may have different items and formats (e.g., text data, HTML format, etc.) depending on the type of the static analysis tool 20. The data format conversion unit 13 has a function of converting different data formats of different static analysis result data into a common format.

[0026] The hash value calculation unit 14 has a function of calculating a hash value of a warning included in the static analysis result data. The hash value consists of specific data calculated based on warning-related data and a code included in a warning-related line. The warning-related data is data related to the warning, and the warning-related line is a warning-related line. The hash value is used as identification information for identifying the warning. The method for calculating the hash value will be described in detail later.

[0027] By using the hash value as the warning's identification information, the same warning can be easily identified across different versions of source files. Using the hash value can prevent re-checking a warning that has already been checked, significantly reducing the time required to review the source code.

[0028] The database 15 stores static analysis results, verification results, and source files. The data format of the static analysis result data is converted by the data converter 12. The static analysis result data is assigned a hash value calculated for the warning, and the static analysis result data assigned the hash value is stored in the database 15.

[0029] Fig. 3A is a diagram showing an example of the static analysis result data stored in the database 15. The static analysis result data includes a file name, a reviewer name, an alert message, a tool name, a severity level, a row, and a column associated with a hash value. The hash value is identification information that identifies the alert and is calculated based on the data concerning an alert and a code included in the row concerning the alert.

[0030] The file name is the name of the source file that is the target of the static analysis. The reviewer name is the name of the reviewer who detected the warning. The static analysis tool 20 has multiple review algorithms and searches for code that may contain bugs by executing the review algorithms and issues the warning. The warning message is a message to inform the user of the warning content.

[0031] The tool name is the name of the static analysis tool 20 that detected the warning. The severity level is data that represents the severity of the warning. The severity level is expressed within a numerical range from 0 to 30, and the higher the number, the more severe the warning. The row and column identify the location of the code associated with the warning. The row specifies a line number where the code associated with the warning starts. The column specifies a column number of the code associated with the warning within the file. Note that the configuration described above is an example of static analysis result data. The static analysis result data may contain different data than that in Fig. 3A shown data.

[0032] Among the Fig. 3A, the description formats of the reviewer name, warning message, tool name, and severity vary depending on the static analysis tool 20, and the same code error may be expressed in different formats.

[0033] Fig. 3B is a diagram showing an example of review result data stored in the database 15. The review result data includes a status, a reviewer, a comment, and confirmation date and time associated with a hash value. The hash value corresponds to a hash value included in the static analysis result data and identifies the alert. The status indicates a review status of the alert identified by the hash value. For example, "Confirmed" indicates that the alert has been confirmed, and "Unreviewed" indicates that the alert has not yet been reviewed. The reviewer indicates a name of a user who reviewed the alert and / or changed the status of the alert. The comment is a comment regarding what option to take regarding the alert when the alert is reviewed by the reviewer.Confirmation date and time show data regarding the date and time at which the alert contents were confirmed. Note that the configuration described above is an example of verification result data. The verification result data may contain different dates than those specified in . Fig. 3B are included.

[0034] The display unit 16 has a function of displaying the analysis result data stored in the database 15 on the user terminal 40. Specifically, in response to a request from the user terminal 40, the display unit reads the analysis result data from the database 15 and transmits the analysis result data to the user terminal 40. The user terminal 40 displays the analysis result data transmitted from the display unit 16.

[0035] When the verification result input unit 17 receives the verification result data from the user terminal 40, the verification result input unit 17 stores the received verification result in the database 15 in association with the hash value indicating the same alert. Specifically, the verification result input unit 17 updates the status, reviewer, comment, and confirmation date and time of the alert identified by the hash value. Calculating the hash value

[0036] The following describes a calculation process of the hash value by the hash value calculation unit 14. The hash value calculation unit 14 calculates a hash value using the warning-related data and the code related to the warning (hereinafter referred to as the warning-related code) as inputs. The warning-related data includes the file name of the source file, the name of the verifier who performed the analysis, and the warning message. Note that the configuration described above is an example of the warning-related data used to calculate the hash value. The warning-related data may use other warning-related data to calculate the hash value.

[0037] Fig. Figure 4 is a diagram showing an example of source code that is a target of static analysis. The hash value is calculated using the Fig. 4 is described as an example. In the Fig. In the example shown in Figure 4, there may be an error in the code "len++" that is detected as a warning. The hash value calculation unit 14 calculates a hash value using the warning-related data as well as the warning-related code "len++" as inputs.

[0038] Note that the line number is not used in calculating the hash value. Since the line number is not used in calculating the hash value, even if the line number is shifted in a different version of the source code by introducing a blank line, the hash value remains the same, and the user can understand that the hash value indicates the same warning. If the line number is not used in calculating the hash value, if the same warning exists on multiple lines, the hash value corresponding to the warnings will be the same as the hash value corresponding to a single warning.

[0039] According to Fig. 4, the codes of warning lines 1, 2, and 3 are the same. Therefore, the contents of the warning-related data (specifically, the file name of the source file, the name of the reviewer who performed the analysis, and the warning message) are the same for the warnings in warning lines 1, 2, and 3. In this case, the hash values ​​for the codes in warning lines 1 to 3 are the same, and identification information is assigned to the warnings in warning lines 1 to 3, and they are treated as a single warning. Although treating the same warnings as a single warning seems acceptable, the analysis result management device 1 of the present embodiment is designed to handle multiple warnings as separate warnings even if they have the same warning contents. The hash value calculation unit 14 calculates a hash value to distinguish the same warnings, as shown in Fig. 4 is shown.

[0040] When a hash value (hereinafter referred to as a first hash value) calculated using the warning-related data and the code included in the warning-related line as inputs is the same as any of the previously calculated hash values, the hash calculation unit 14 calculates a hash value (hereinafter referred to as a second hash value) using the code between a line where duplication of the hash value is first determined to start up to a line concerning the warning. Then, the second hash value is set as the hash value corresponding to the warning.

[0041] Fig. 5A to Fig. 5C are diagrams to explain the codes to be used in calculating the hash values ​​for the warnings in warning lines 1 to 3. In the description of the Fig. 5A to 5C, the code for calculating the hash value is used. However, as described above, the warning-related data used as input for calculating the hash value can be appropriately modified. Fig. Figure 5A shows the code used to determine the hash value of the alert in alert line 1. The code in the fourth line, circled by a box labeled a, is used as input to calculate the hash value.

[0042] Fig. Figure 5B shows the code used to determine the hash value of the warning in warning line 2. In addition to the code in box a, the code in the fifth line, enclosed by box b and located between warning line 1 and warning line 2, is used as an input for calculating the hash value. The duplication of the hash value starts from warning line 1. Fig. Figure 5C shows the code to be used to calculate the hash value of the warning in warning line 3. In addition to the code in box a, the code from lines 5 to 7 in box c, located between warning line 1 and warning line 3, is used as an input for calculating the hash value. The duplication of the hash value starts from warning line 1.

[0043] As it is in the Fig. 5A to 5C, even if the same warning is detected for the code “len++”, the hash values ​​are distinguished from each other by changing the range of the code used to calculate the hash value.

[0044] Fig. 6 is a flowchart showing a calculation process performed by the hash value calculation unit 14. The hash value calculation unit 14 first sorts all warnings in the static analysis result data according to the file name and line number of the warning (S10). Then, the hash value calculation unit 14 calculates a first hash value using the warning-related data and the code in the warning-related line as inputs (S11), and determines whether the first hash value is identical to a hash value previously calculated (S12).

[0045] If the same hash value as the first hash value exists (yes in S12), the hash value calculation unit 14 calculates the second hash value using (i) the warning-related data, (ii) the code in the warning-related line, and (iii) the code between the line where the hash value is first duplicated and the warning-related line for which it was calculated (S13). Then, the hash value calculation unit 14 sets the second hash value as the warning hash value. Here, whitespace, comments, and other parts that do not directly affect the warning may or may not be used in calculating the hash value. Subsequently, the hash value calculation unit 14 determines whether there is a remaining warning for which the hash value has not yet been calculated (S14).

[0046] If an alert for which a hash value has not yet been calculated exists (yes in S14), the process returns to S11 to calculate an initial hash value for the remaining alert.

[0047] If it is determined in S12 whether a hash value identical to the currently calculated first hash value exists, in response to determining that the same hash value does not exist (No in S12), the first hash value is used as the hash value of the alert that is the calculation target. If it is determined in S14 whether an alert for which the hash value has not yet been calculated remains, in response to determining that there is no alert for which the hash value has not yet been calculated (No in S14), the calculation process of the hash value for the corresponding static analysis result data is terminated.

[0048] The analysis result management device 1 and the analysis result management method according to the first embodiment have been described above. In the first embodiment, when the calculated first hash value is the same as a pre-existing hash value, the analysis result management device 1 can avoid duplication of the hash value by calculating the second hash value using the code from the warning line where the hash value is first duplicated or exists to the warning line corresponding to the calculation target as inputs. Since the code before the line where duplication of the first hash value occurs does not affect the calculation of the second hash value, even if a correction has been performed beforehand, it does not affect the analysis of the difference between the different versions. This configuration enables appropriate management of warnings.

[0049] Software under development is frequently changed with version upgrades. Therefore, it is important to identify changes and problems. The analysis result management device 1 of the present embodiment manages the analysis results of the source code before and after the software under development is upgraded and identifies changes and problems. By devising the method for managing the analysis results, it is possible to distinguish between different warnings and detect undetected problems.

[0050] In the first embodiment described above, when calculating the second hash value, the code from the warning line where the hash value is first duplicated or occurs to the warning line corresponding to the calculation target is used as the input. Alternatively, another code range may be used as the input for the hash value calculation. For example, the hash value can be calculated using the code from the first line of the source code to the warning line corresponding to the calculation target.

[0051] The Fig. Figures 7A to 7C are diagrams showing an example of code used in calculating the second hash value. Fig. 7A to 7C correspond to the Fig. 5A to 5C. The Fig. Figures 7A to 7C show calculations of hash values ​​for warning lines 1 to 3.

[0052] Since in Fig. 7A, the hash value of warning line 1 is not duplicated, the warning-related code in line 1 is used as an input to calculate the hash value. When calculating the hash value of warning line 2, the first hash value calculated using only the code in warning line 2 is the same as the hash value calculated for warning line 1. As shown in Fig. 7B, the hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box d, from line 1 of the source code to the warning line 2.

[0053] When calculating the hash value of warning line 3, the first hash value calculated using only the code in warning line 3 is the same as the hash value calculated for warning line 1. As shown in Fig. Thus, as shown in Figure 7C, the hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box e, from line 1 of the source code to the warning line 3, as inputs. With this configuration, it is possible to prevent duplication of hash values.

[0054] According to another example of the code range to be used to calculate the hash value, the code from the previous warning line to the warning line of the calculation target can be used as input. Fig. Figure 8 shows an example of such a calculation of the hash value. In Fig. 8, the three lines beginning with “tmp=” correspond to warning lines 1, 2, and 3.

[0055] Since in Fig. 8 If the hash value of warning line 1 is not duplicated, the code in warning line 1 is used as an input to calculate the hash value. When calculating the hash value of warning line 2, the first hash value calculated using only the code in warning line 2 is the same as the hash value calculated using the code in warning line 1. Thus, hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box f, from the line subsequent to warning line 1 to warning line 2, as inputs.

[0056] When calculating the hash value of warning line 3, the first hash value calculated using the code in warning line 3 is the same as the hash value calculated using the code in warning line 1. Thus, the hash value calculation unit 14 calculates a second hash value using the code in the area enclosed by a box g, from the line subsequent to the previous warning line 2 to warning line 3 as inputs. With this configuration, it is possible to prevent duplication of hash values. Second embodiment

[0057] The following describes an analysis result management device according to a second embodiment of the present invention. The basic configuration of the analysis result management device of the second embodiment is the same as that of the analysis result management device 1 of the first embodiment (see Fig. 1 and Fig. 2). The analysis result management apparatus according to the second embodiment differs from the analysis result management apparatus according to the first embodiment in that the analysis result management apparatus according to the second embodiment calculates the hash value by considering flow information concerning the warning line.

[0058] Fig. 9 is a diagram for explaining the calculation process performed by the hash value calculation unit 14 of the analysis result management apparatus according to the second embodiment. Fig. In Figure 9, the warning line "case 1: result=a / Zero; break;" is enclosed in box a and warns that dividing by ZERO may result in an error. Here, the fact that ZERO is equal to 0 is defined by "#define ZERO 0," as shown in box h. That is, the variable in the code enclosed in box a references the code enclosed in box h, and these two lines are related to each other. When a problem in the source code is detected as a warning, it may be necessary to consider a processing flow leading up to the point at which the problem occurred. In the present invention, such movement through the source code is referred to as "flow information."

[0059] When calculating the hash value for the warning line enclosed by box a, the hash value calculation unit 14 calculates the hash value using the code in the warning line as well as the code in the line enclosed by box h as inputs.

[0060] According to the second embodiment of the analysis result management device, the hash value is calculated taking into account not only the warning message and the source code but also the flow information related to the warning line, thereby preventing the occurrence of an unacquired warning and improving the management quality of the analysis results.

[0061] In the present embodiment, in addition to the configuration of the analysis result management device 1 of the first embodiment, the hash value is also calculated taking into account the flow information. The hash value calculation method that avoids duplication of the hash value as in the first embodiment is not necessarily required for the hash value calculation taking into account the flow information of the second embodiment. Therefore, in an analysis result management device that allows assignment of the same hash value to multiple alerts of the same type, the hash value can be calculated taking into account the flow information. Third embodiment

[0062] Fig. 10 is a diagram showing a functional configuration of an analysis result management device 3 according to a third embodiment. The basic configuration of the analysis result management device 3 of the third embodiment is similar to that of the analysis result management device 1 of the first embodiment. The analysis result management device 3 of the third embodiment includes a warning correspondence table 18. The warning correspondence table 18 is a table showing the correspondence between reviewers who detect the same type of warnings in static analysis result data generated by a plurality of static analysis tools 20.

[0063] Fig. 11 is a diagram showing an example of data stored in the warning correspondence table 18. The warning correspondence table 18 shows the correspondence between the reviewer names of the static analysis tools 20, that is, tools X, Y, and Z. In the Fig. In the example shown in Figure 11, "Division By Zero" in tool X, "core.DivideZero" in tool Y, and "Integer division by zero" in tool Z are correlated with each other. The warning correspondence table 18 correlates identification information with the reviewer name of each tool. Fig. 11, the identification information "INT31-C" is a character string for a rule that "ensures that a conversion of an integer does not result in data loss or misinterpretation," as defined in the CERT-C coding standard. In this way, a meaningful character string can be used as identification information. Alternatively, meaningless random information can be used if there is no duplication. Fig. 11, the alert correspondence table 18 stores a correspondence between the reviewer names of three analysis tools. Instead of the reviewer names of the three analysis tools, the reviewer names of two, four, or more analysis tools can be correlated using the identification information. When an analysis tool is added, the reviewer name of the new analysis tool can be registered in the alert correspondence table 18.

[0064] When calculating the hash value of the alert, the hash value calculation unit 14 determines whether the reviewer name that acquired the alert corresponding to the calculation target is recorded in the alert correspondence table 18. In response to determining that the reviewer name is recorded in the alert correspondence table 18, the identification information corresponding to this reviewer name is read out, and the hash value is calculated using the identification information as input instead of the reviewer name.

[0065] Fig. 12 is a diagram for explaining the calculation process performed by the hash value calculation unit 14. The Fig. The flow shown in Fig. 12 is a detailed process of calculating the first hash value (S11) or calculating the second hash value (S13) in the Fig. 6 shown hash value calculation process.

[0066] When calculating the hash value, the analysis result management device 3 of the third embodiment determines whether the reviewer name of the reviewer who acquired the calculation target warning exists in the warning correspondence table 18 (S20). In response to determining that the reviewer name exists in the warning correspondence table 18, the process reads the identification information from the warning correspondence table 18 (S21) and calculates the hash value using the identification information as input instead of the reviewer name of the above-described warning-related data (S23). That is, the file name of the source file and the identification information are used as warning-related data.In the analysis result management device 1 of the first embodiment, when calculating the hash value, the file name of the source file, the name of the reviewer who performed the analysis, and the warning message are used as the warning-related data. In the present embodiment, the warning message is not used.

[0067] If the name of the reviewer who acquired the calculation target warning does not exist in the warning correspondence table 18 (No in S20), the reviewer name is referenced (S22), and the hash value is calculated (S23). That is, the file name of the source file and the reviewer name are used as the warning-related data to calculate the hash value.

[0068] Fig. 13 shows a display example indicating an analysis result managed by the analysis result management device 3. In the analysis result, the hash value that identifies the warning is correlated with the file name of the source file in which the warning is acquired, the name of the reviewer who acquired the warning, the warning message, the name of the static analysis tool 20 that acquired the warning, the severity level indicating the severity of the warning, and verification result data of the warning.

[0069] In the present embodiment, warnings detected by multiple static analysis tools 20 and concerning the same code are output as a single warning. Specifically, data from three tools, i.e., tools K, L, and M, are correlated with the same hash value in the third row, as shown in Fig. 13. Although the warnings are detected by three different static analysis tools 20, they are treated as a single warning because they correspond to the same code. It is not necessary to handle warnings for each static analysis tool 20. By entering the verification result once, it is possible to set a status indicating that the warning has been handled.

[0070] Conventionally, when multiple static analysis tools 20 are used, there is a problem that some warnings are displayed multiple times, and thus, determining the same warnings is time-consuming. According to the present embodiment, it is possible to determine the results of different static analysis tools 20 as the same warning, thereby making verification more efficient.

[0071] As it is in Fig. As shown in Fig. 13, although warnings detected by static analysis tool reviewers are treated as a single warning, the warning message and tool name information remain as data for each static analysis tool 20. Thus, it is possible to refer to the static analysis result generated by each static analysis tool 20.

[0072] According to the present embodiment, in the calculation of the hash value by the analysis result management device of the first embodiment, the same hash value is assigned to the same warnings acquired by a plurality of static analysis tools by referring to the warning correspondence table 18 (see Fig. 12). The technology described in the present embodiment for detecting warnings from multiple static analysis tools as the same warning does not necessarily require the configuration of the first embodiment as a prerequisite. The hash value calculation unit 14 may calculate the hash value as shown in Fig. Calculate as shown in Figure 14.

[0073] Fig. 14 illustrates a hash value calculation process performed by the analysis result management device 3 according to the third embodiment. The hash value calculation unit 14 first sorts the source files by file name and line number (S30). Then, the hash value calculation unit determines whether the name of the reviewer who acquired the calculation target warning exists in the warning correspondence table 18 (S31). If it is determined that the reviewer name exists in the warning correspondence table 18 (Yes in S31), the hash value calculation unit reads the identification information from the warning correspondence table 18 (S31) and calculates the hash value using the identification information as input instead of the reviewer name of the warning-related data (S34).

[0074] If the name of the verifier who acquired the calculation target warning does not exist in the warning correspondence table 18 (no in S31), the verifier name is referenced (S33), and then the hash value is calculated (S34).

[0075] Subsequently, the hash value calculation unit 14 determines whether there is any alert for which the hash value has not yet been calculated (S35). If it is determined that there is any alert for which the hash value has not yet been calculated (Yes in S35), the process returns to S31 and determines whether the name of the reviewer who acquired the calculation target alert exists in the alert correspondence table 18. If it is determined that there is no alert for which the hash value has not yet been calculated (No in S35), the hash value calculation process for the corresponding static analysis result data is terminated.

[0076] The technique described in the present embodiment can also be applied to the analysis result management apparatus of the second embodiment. Modifications

[0077] The analysis result management device of the present invention has been described in detail using several embodiments. The analysis result management device of the present invention is not limited to the above-described embodiments. The analysis result management device can prepare multiple calculation methods for calculating hash values. The analysis result management device can select only one calculation method that conforms to the development concept of the product project from among multiple calculation methods.

[0078] Fig. Figure 15 is a diagram showing the types of inputs used in the calculation of the hash value in several calculation methods. Fig. In the example shown in Figure 15, three calculation methods 1, 2 and 3 are given.

[0079] Fig. Figure 15 shows the data used as input for each calculation method. Specifically, data containing the verification mark "V" is used to calculate the hash value.

[0080] The inputs used in calculation method 1 for hash value calculation include a file name, a verifier name, a warning message, a code in the warning line, and a code within a predetermined range if the hash value is duplicated. The code in the warning line indicates the code in the warning line. The inputs used in calculation method 2 for hash value calculation include a file name, a verifier name, a warning message, a code in the warning line, a code in a relevant line, and a code within a predetermined range if the hash value is duplicated. The inputs used in calculation method 3 for hash value calculation include a file name, a verifier name, a warning message, and a code in the warning line.In calculation method 3, the code within the predetermined range is not used, even though duplication of the hash value occurs. That is, calculation method 3 allows duplication of the hash value.

[0081] By preparing calculation methods 1, 2, and 3, each of which allows duplication of the hash value, the user can select a suitable calculation method from the prepared options. Specifically, data regarding calculation methods 1 to 3 is transmitted to the user terminal 40, and the calculation methods are displayed on the user terminal 40. The analysis result management device 1 includes a selection receiving unit that receives a calculation method selection. Specifically, the selection receiving unit receives the calculation method selection data input to the user terminal 40 and sets the calculation method according to the selection data.

[0082] The analysis result management device 3 of the third embodiment can provide a calculation method that uses the warning correspondence table 18 and a calculation method that does not use the warning correspondence table 18. As described above, in the warning correspondence table 18, the analysis results of a plurality of static analysis tools 20 are correlated with each other. Thus, the user can select a calculation method for calculating the hash value from the prepared options. QUOTES CONTAINED IN THE DESCRIPTION

[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature

[0000] JP 2004 - 126 866 A [0004, 0006]

Claims

[1] Analysis result management device comprising: an input unit (11) receiving an input of static analysis result data, the static analysis result data including a source code and data of a plurality of warnings, the respective warnings being detected by statically analyzing the source code; a hash value calculation unit (14) that calculates a hash value for each of the warnings using (i) warning data, which is data concerning the respective warnings, and (ii) a code in a plurality of lines within a predetermined range of the source code as inputs, the lines including a warning line from which the corresponding warning is detected; a database (15) that stores the data of the respective warnings in association with the corresponding hash value; and a display unit (16) which displays the data stored in the database. [2] The analysis result management device according to claim 1, wherein if the first hash value calculated using the warning data and the code in the warning line as inputs is the same as any of previously calculated hash values, the hash value calculation unit calculates a second hash value using the warning data and the code in multiple lines within the predetermined range of the source code as inputs and sets the second hash value as the hash value of the corresponding warning, and the rows contain the warning row from which the corresponding warning is captured. [3] The analysis result management device according to claim 2, wherein if the first hash value calculated using the warning data and the code in the warning line as inputs is the same as any of the previously calculated hash values, the hash value calculation unit calculates the second hash value using the warning data and the code in multiple lines as inputs, and the lines include the warning line at which duplication of the hash value first occurs up to the warning line corresponding to a calculation target of the hash value. [4] The analysis result management device according to claim 2 or 3, further comprising: a selection receiving unit that receives a selection of a hash value calculation method that allows or does not allow duplication of the first hash value with any of the previously calculated hash values, wherein when the selection receiving unit receives a selection of a hash value calculation method that allows duplication of the first hash value with any of the previously calculated hash values, the hash value calculation unit determines the first hash value as the hash value of the corresponding warning, even if the first hash value is the same as one of the previously calculated hash values. [5] The analysis result management device according to any one of claims 1 to 4, wherein the hash value calculation unit calculates the hash value using the warning data, the code in the warning line, and the code in another line related to the warning line within the source code as inputs. [6] The analysis result management device according to any one of claims 2 to 5, wherein the hash value calculation unit calculates the second hash value each time it is determined that the first hash value is the same as any of the previously calculated hash values. [7] Analysis result management device comprising: an input unit that receives an input of static analysis result data, the static analysis result data including a source code and data of a plurality of warnings, the respective warnings being detected by statically analyzing the source code, a hash value calculation unit that calculates a hash value for each of the alerts using as inputs (i) alert data, which is data concerning the respective alerts, (ii) a code in an alert line from which the corresponding alert is captured, and (iii) a code in another line related to the alert line within the source code; a database that stores the data of the respective warnings in association with the corresponding hash value; and a display unit that displays the data stored in the database. [8] A computer-implemented method for managing static analysis result data using an analysis result managing device, the static analysis result data including source code and data of a plurality of warnings acquired by statically analyzing the source code, the management method comprising: Receiving an input of the static analysis result data by means of the analysis result management device; Calculating a hash value for each of the warnings using (i) warning data, which is data concerning the respective warnings, and (ii) a code in a plurality of lines within a predetermined range of the source code as inputs by means of the analysis result management device, the lines including a warning line from which the corresponding warning is detected; Storing the data of the respective warnings in a database in association with the corresponding hash value by means of the analysis result management device; and Display the data stored in the database using the analysis result management device. [9] A computer-implemented method for managing static analysis result data using an analysis result managing device, the static analysis result data including source code and data of a plurality of warnings acquired by statically analyzing the source code, the management method comprising: Receiving an input of the static analysis result data; Calculating a hash value for each of the alerts using as inputs (i) alert data, which is data concerning the respective alerts, (ii) a code in an alert line from which the corresponding alert is captured, and (iii) a code in another line related to the alert line within the source code; Storing the data of the respective warnings in a database in association with the corresponding hash value; and Display the data stored in the database. [10] A computer program for managing static analysis result data using an analysis result managing device, the static analysis result data including source code and data of a plurality of warnings acquired by statically analyzing the source code, the computer program causing a computer to serve as: an input unit that receives an input of the static analysis result data; a hash value calculation unit that calculates a hash value for each of the alerts using as inputs (i) alert data, which is data concerning the respective alerts, and (ii) code in a plurality of lines within a predetermined range of the source code, the lines including an alert line from which the corresponding alert is detected; a database that stores the data of the respective warnings in association with the corresponding hash value; and a display unit that displays the data stored in the database. [11] A computer program for managing static analysis result data using an analysis result managing device, the static analysis result data including source code and data of a plurality of warnings acquired by statically analyzing the source code, the computer program causing a computer to serve as: an input unit that receives an input of the static analysis result data; a hash value calculation unit that calculates a hash value for each of the alerts using as inputs (i) alert data, which is data concerning the respective alerts, (ii) a code in an alert line from which the corresponding alert is captured, and (iii) a code in another line related to the alert line within the source code; a database that stores the data of the respective warnings in association with the corresponding hash value; and a display unit that displays the data stored in the database.

Citation Information

Patent Citations

  • Description output suppression program analysis system and description output suppression program analysis method

    JP2004126866A