Analysis result management device, analysis result management method, and program
The analysis result management device addresses the inefficiencies in managing static analysis results by calculating unique hash values based on warning data and surrounding code, enhancing the accuracy and efficiency of software development processes.
Patent Information
- Application Number
- JP2023219694
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-26
- Publication Date
- 2025-07-08
AI Technical Summary
Existing systems struggle with efficiently managing and reusing static analysis results across different versions of software code, as they often require manual comparison and can lead to unjudged warnings due to hash value overlap.
An analysis result management device that calculates a unique hash value using data related to warnings and surrounding code, allowing for efficient storage and display of analysis results, distinguishing between similar warnings across different versions.
Enables accurate and efficient management of static analysis results, reducing redundant reviews and improving verification efficiency by uniquely identifying and managing warnings across different software versions.
Smart Images

Figure 2025102333000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an analysis result management device that manages analysis results of source code, etc.
Background Art
[0002] In software development, due to coding errors, there are often problems where the software does not operate properly. Although this type of error can be prevented by reviewing the source code, as the scale of the software increases and the content becomes more complex, the number of problems increases rapidly.
[0003] For the purpose of detecting such errors before the execution test of the program, a static analysis system has been developed and sold that analyzes the source file of the software syntactically or semantically without actually executing it and outputs a warning for the description of the source code that may contain bugs. Such an analysis system outputs information that can be corrected by software developers.
[0004] The analysis system outputs the result of analyzing the source code, but the number of warnings included in the result is often enormous. In software development, multiple versions are created. If a warning that has been confirmed in a previous version is warned again, reconfirmation is required despite being confirmed, which is inefficient. Patent Document 1 discloses a technique for suppressing warning messages by comparing the line and column numbers of the source code, the syntax of the analysis target, and the components in the syntax between the previous and subsequent versions.
[0005] Conventionally, a system is also known that calculates a hash value for a set of the source code description content and the tool detection result and manages the analysis result using the hash value. By using the hash value, the analysis results for different versions of the source code can be easily compared. Since analysis results with the same hash value can be treated as the same, the reuse of analysis results is also possible. In addition, it is possible to search for warnings using the hash value, enabling efficient and accurate management.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0007] In Patent Document 1, since the analysis results are manually managed, it is difficult to compare the results of different versions. Further, the method of Patent Document 1 can suppress warning messages, but it is difficult to reuse and analyze the analysis results.
[0008] In the verification process, it is necessary to confirm each warning. However, in the conventional method of managing the analysis results by hash values, when the contents of the warnings are the same, the hash values overlap and are treated as the same warning, so there is a possibility that unjudged warnings remain.
[0009] In view of the above background, an object of the present invention is to provide a technique capable of assigning an appropriate hash value to a warning.
Means for Solving the Problems
[0010] In order to solve the above problems, the present invention employs the following technical means. The claims and the reference numerals in parentheses described in this section are an example showing the correspondence with the specific means described in the embodiments described later as one aspect, and do not limit the technical scope of the present invention.
[0011] The analysis result management device (1) of the present invention includes an input unit (11) that receives an input of static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, a hash value calculation unit (14) that calculates a hash value using, as inputs, data related to the warning and a plurality of lines of code within a predetermined range including the line related to the warning, a database (15) that stores the warning data in association with the hash value, and a display unit (16) that displays the data stored in the database.
[0012] The analysis result management device according to another aspect of the present invention includes an input unit that receives an input of static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, a hash value calculation unit that calculates a hash value using, as inputs, data related to the warning, the code of the line related to the warning, and the code of other lines related to the line related to the warning in the source code, a database that stores the warning data in association with the hash value, and a display unit that displays the data stored in the database.
[0013] The analysis result management method of the present invention is a method for managing, by an analysis result management device, static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, the method including: a step in which the analysis result management device receives an input of the static analysis result data; a step in which the analysis result management device calculates a hash value using, as inputs, data related to the warning and a plurality of lines of code within a predetermined range including the line related to the warning; a step in which the analysis result management device stores the warning data in a database in association with the hash value; and a step in which the analysis result management device displays the data stored in the database.
[0014] The analysis result management method according to another aspect of the present invention is a method for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code by an analysis result management device, the method comprising: receiving an input of the static analysis result data; calculating a hash value using, as inputs, data related to the warning, code of the line related to the warning, and code of other lines related to the line related to the warning in the source code; storing the data related to the warning in association with the hash value in a database; and displaying the data stored in the database.
[0015] The program according to the present invention is a program for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, the program causing a computer to function as an input unit that receives an input of the static analysis result data, a hash value calculation unit that calculates a hash value using, as inputs, data related to the warning and code of a plurality of lines within a predetermined range including the line related to the warning, a database that stores the data of the warning in association with the hash value, and a display unit that displays the data stored in the database.
[0016] The program according to another aspect of the present invention is a program for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, the program causing a computer to function as an input unit that receives an input of the static analysis result data, a hash value calculation unit that calculates a hash value using, as inputs, data related to the warning, code of the line related to the warning, and code of other lines related to the line related to the warning in the source code, a database that stores the data of the warning in association with the hash value, and a display unit that displays the data stored in the database.
Advantages of the Invention
[0017] According to the present invention, an appropriate hash value can be assigned to a warning, and a software developer can appropriately judge the analysis result.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Embodiments for Carrying Out the Invention
[0019] Hereinafter, the analysis result management device according to the present embodiment will be described with reference to the drawings. Note that the following description shows only an example of a preferred embodiment and is not intended to limit the invention described in the claims.
[0020] (First Embodiment) [Overall Configuration of Analysis Result Management Device] FIG. 1 is a diagram showing the functional configuration of the analysis result management device 1 according to the present embodiment. The analysis result management device 1 receives the input of the result obtained by analyzing the software source code by the static analysis tool 20 and manages the static analysis result data. The analysis result management device 1 receives the input of the static analysis results by a plurality of static analysis tools 20.
[0021] FIG. 2 is a diagram showing the hardware configuration of the analysis result management device 1 according to the present embodiment. The analysis result management device 1 is arranged on the network, and communication between the analysis result management device 1 and the user terminal 40 is possible via the network. Here, the type of the network is not limited, and for example, the Internet, an intranet within the company, etc. may be used. Also, in the present embodiment, an example of arranging the analysis result management device 1 on the network is shown, but the analysis result management device 1 may be realized by a local PC. In this case, the local PC will have the functions of the analysis result management device 1 and the user terminal 40.
[0022] The analysis result management device 1 includes a control unit 30 having a CPU 31, a RAM 32, and a ROM 33, an input unit 34, an output unit 35, a storage unit 36, and a communication unit 37. By executing the program stored in the ROM 33, the functions of the analysis result management device 1 described later are realized. Such a program is also included in the scope of the present invention.
[0023] Users such as software developers access the analysis result management device 1 from the user terminal 40 through a web browser. The static analysis result data is transmitted from the user terminal 40 to the analysis result management device 1. The analysis result management device 1 manages the static analysis result data.
[0024] Returning to FIG. 1, the functions of the analysis result management device 1 will be described. The analysis result management device 1 includes a data input unit 11, a data converter 12, a database 15, a display unit 16, and a review result input unit 17.
[0025] The data input unit 11 receives the input of the static analysis result data of the source file by the static analysis tool 20. The static analysis result data is data of warnings regarding descriptions of the source code that may contain bugs. It is data indicating where in the source code there are syntax errors and what kind of syntax errors there are. Also, the data input unit 11 receives the input of the source file data. The reason for inputting the source file is that, as will be described later, the analysis result management device 1 of the present embodiment also uses the source code data for hash value calculation.
[0026] There are various tools as the static analysis tool 20. The data input unit 11 receives the input of data analyzed by different static analysis tools 20. The results of static analysis differ depending on the static analysis tool 20. For example, a description detected as a warning by one static analysis tool 20 may not be detected as a warning by another static analysis tool 20. This is due to the specifications of the static analysis tool 20, because the fields in which the static analysis tool 20 is good at analysis are different. By incorporating the static analysis results of multiple static analysis tools 20, a highly accurate review can be performed. The data input unit 11 passes the input static analysis result data to the data converter 12. Also, the data input unit 11 stores the source file in the database 15.
[0027] The data converter 12 has a data format conversion unit 13 and a hash value calculation unit 14. The static analysis result data input to the data input unit 11 has different items or different formats (for example, text data, HTML format, etc.) depending on the static analysis tool 20. The data format conversion unit 13 has a function of converting different data formats into a common format according to the static analysis result data.
[0028] The hash value calculation unit 14 has a function of calculating the hash value of the warning included in the static analysis result data. The hash value is unique data calculated based on the data related to the warning and the code of the line related to the warning, and is used as identification information for identifying the warning. Details of the hash value calculation method will be described later.
[0029] By using the hash value as identification information, the same warning can be easily identified between source files with different versions. As a result, the trouble of reviewing the warnings that have already been reviewed can be saved, and the review time of the source code can be significantly reduced.
[0030] The database 15 stores the static analysis results, the review results, and the source files. The data of the static analysis results is the data of the static analysis results whose data format has been converted by the data converter 12 and a hash value has been given to the warnings.
[0031] Figure 3(a) is a diagram showing an example of the data of the static analysis results stored in the database 15. The data of the static analysis results has data of file name, checker name, warning message, tool name, severity, line, and column associated with the hash value. The hash value is identification information for specifying a warning and is calculated based on the data of the warning and the data of the code of the line related to the warning.
[0032] The file name is the file name of the source file that is the target of the static analysis. The checker name is the name of the checker that detected the warning. One static analysis tool 20 has a plurality of checker algorithms, searches for code that may have bugs by executing the checker algorithms, and outputs warnings. The warning message is a message for notifying the user of the content of the warning.
[0033] The tool name is the name of the static analysis tool 20 that detected the warning. The severity is data representing the severity of the warning. It is represented by a numerical value from 0 to 30, and the larger the number, the more serious the content of the warning. The line and column are data for specifying the location of the code related to the warning. The line represents the line number where the warning starts, and the column indicates the column number within the file. Note that what is shown here is an example, and the data of the static analysis results may include data other than that shown in Figure 3(a).
[0034] Among the static analysis result data shown in Figure 3(a), the notations of the data of checker name, warning message, tool name, and severity are different depending on the static analysis tool 20, and different notations are made for the same code error.
[0035] FIG. 3(b) is a diagram showing an example of the review result data stored in the database 15. The review result data has data on status, reviewer, comment, and confirmation date and time, associated with a hash value. The hash value corresponds to the hash value included in the static analysis result data and identifies a warning. The status is the status of the review situation for the warning identified by the hash value. For example, "confirmed" indicates that it has been confirmed, and "unreviewed" indicates that the review has not yet been performed. The reviewer is the name of the user who reviewed the warning and changed the status. The comment is a comment on what action was taken for the warning when the warning has been reviewed. The confirmation date and time is the data of the date and time when the content of the warning was confirmed. Note that what is shown here is just an example, and the review result data may include data other than that shown in FIG. 3(b).
[0036] The display unit 16 has a function of displaying the analysis result data stored in the database 15 on the user terminal 40. Specifically, in response to a request from the user terminal 40, the analysis result data is read from the database 15, the analysis result data is transmitted to the user terminal 40, and the user terminal 40 is caused to display the analysis result data.
[0037] When the review result data is transmitted from the user terminal 40, the review result input unit 17 stores the transmitted review result in the database 15 in association with the hash value indicating the corresponding warning. Specifically, the review result input unit 17 updates the status, reviewer, comment, and confirmation date and time of the warning identified by the hash value.
[0038] [Calculation of Hash Value] Next, the calculation process of the hash value by the hash value calculation unit 14 will be described. The hash value calculation unit 14 calculates a hash value using the data related to the warning and the code related to the warning as inputs. As the data related to the warning, the file name of the source file, the name of the checker that performed the analysis, and the warning message are used. Note that what is shown here is an example of the data related to the warning used for the calculation of the hash value, and of course, other data related to the warning can also be used for the calculation of the hash value.
[0039] FIG. 4 is a diagram showing an example of the source code to be statically analyzed, and the calculation of the hash value will be described using the code shown in FIG. 4 as an example. In the example shown in FIG. 4, there may be an error in the code "len++", and it is detected as a warning. The hash value calculation unit 14 calculates the hash value using, in addition to the data related to the warning, the code "len++" which is the code related to the warning as an input.
[0040] Note that line numbers are not used in the calculation of the hash value. By adopting a configuration in which line numbers are not included in the calculation of the hash value, even when the line numbers are shifted due to, for example, blank lines being inserted in source codes with different versions, the hash values will be the same, and it can be recognized that they are the same warning. However, by adopting a configuration in which line numbers are not used in the calculation of the hash value, when the same warning exists in multiple lines, their hash values will be the same value.
[0041] Referring to FIG. 4, the codes of warning line 1 to warning line 3 are the same. Therefore, the content of the data related to the warning (specifically, the file name of the source file, the name of the checker that performed the analysis, and the warning message) is also the same. Then, the hash values for the codes of warning line 1 to warning line 3 will be the same, the same identification information will be assigned to the warnings of warning line 1 to warning line 3, and they will be treated as one warning. Although there is an idea that such handling is acceptable, in the analysis result management device 1 of the present embodiment, even if a plurality of warnings have the same content, they are treated as different warnings. The hash value calculation unit 14 calculates the hash value so as to distinguish the same warnings as shown in FIG. 4.
[0042] When the hash value calculation unit 14 calculates the hash value (referred to as the "first hash value" for convenience of explanation) using the data related to the warning and the code of the line related to the warning as inputs, and the calculated hash value overlaps with any of the already calculated hash values, the hash value (referred to as the "second hash value" for convenience of explanation) is calculated using, as inputs, the codes of a plurality of lines from the line related to the warning where the hash value first overlapped to the line related to the warning, and the second hash value is used as the hash value for the warning.
[0043] FIG. 5 is a diagram for explaining the code used to calculate the hash values of the warnings of warning lines 1 to 3. In the explanation using FIG. 5, although the focus is on the code, it is as described above that data related to the warning is used as an input for hash value calculation. FIG. 5(a) shows the code used to obtain the hash value of the warning of warning line 1. The code on the fourth line surrounded by frame a is used as an input.
[0044] FIG. 5(b) shows the code used to obtain the hash value of the warning of warning line 2. In addition to the code surrounded by frame a, the code on the fifth line surrounded by frame b from warning line 1 to warning line 2, where the hash value was first determined to overlap, is used as an input. FIG. 5(c) shows the code used to obtain the hash value of the warning of warning line 3. In addition to the code surrounded by frame a, the codes on the fifth to seventh lines surrounded by frame c from warning line 1 to warning line 3, where the hash value was first determined to overlap, are used as inputs.
[0045] As shown in FIGS. 5(a) to 5(c), even when the same warning is detected for the code "len++", the hash values can be distinguished by changing the range of the code used for hash value calculation.
[0046] FIG. 6 is a flowchart showing the calculation process by the hash value calculation unit 14. First, the hash value calculation unit 14 sorts all the warnings in the static analysis result data by the warning file name and line number (S10). Subsequently, the hash value calculation unit 14 calculates the first hash value by using the data related to the warning and the code of the line related to the warning as inputs (S11), and determines whether the same hash value as the obtained first hash value already exists (S12).
[0047] When the same hash value exists (YES in S12), in addition to the data related to the warning and the code of the line related to the warning, the hash value calculation unit 14 calculates the second hash value by using the code from the line where the hash value first duplicates to the warning line to be calculated (S13), and sets the second hash value as the hash value for the warning. At this time, for parts such as blanks and comments that have no direct influence on the warning, they may or may not be used in the calculation of the hash value. Subsequently, the hash value calculation unit 14 determines whether there are still warnings for which the hash value has not been calculated (S14). If there are still warnings for which the hash value has not been calculated (YES in S14), it returns to step S11 to calculate the first hash value for the warning.
[0048] In the determination of whether the same hash value as the first hash value already exists (S12), if it is determined that the same hash value does not exist (NO in S12), the first hash value is set as the hash value of the warning to be calculated. In the determination of whether there are still warnings for which the hash value has not been calculated (S14), if there are no warnings for which the hash value has not been calculated (NO in S14), the calculation process of the hash value for the corresponding static analysis result data is terminated.
[0049] The analysis result management device 1 and the analysis result management method according to the first embodiment have been described above. When the first hash value overlaps with an existing hash value, the analysis result management device 1 according to the first embodiment calculates a second hash value using, as input, the code from the warning line where the hash value first overlapped to the warning line to be calculated, thereby avoiding hash value duplication. Since the code before the hash value first overlaps does not affect the calculation of the second hash value, even if there were modifications before that, it does not affect the differential analysis between versions. As a result, warnings can be appropriately managed.
[0050] Software under development is frequently changed due to version upgrades and the like. Therefore, it is important to identify the points of change and problems. According to the analysis result management device 1 of this embodiment, by devising a method for managing the analysis results of the source code before and after the software under development and a method for managing the analysis results, different warnings can be distinguished and undetected problems can be improved.
[0051] In the above-described first embodiment, when calculating the second hash value, the code from the warning line where the hash value first overlapped to the warning line to be calculated was used as input, but it is also possible to use the code in another range as input. For example, the hash value may be calculated using the code from the first line of the source code to the warning line to be calculated as input.
[0052] FIG. 7 is a diagram showing an example of the code used for calculating the second hash value. FIGS. 7(a) to 7(c) respectively correspond to FIGS. 5(a) to 5(c) and show an example of obtaining the hash values of warning lines 1 to 3.
[0053] In Fig. 7(a), since the hash values of warning line 1 do not overlap, the hash value is calculated using the code related to warning line 1 as the input. When calculating the hash value of warning line 2, since the first hash value obtained using only the code of warning line 2 overlaps with the hash value of warning line 1, the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame d from the first line of the source code to warning line 2 as shown in Fig. 7(b).
[0054] When calculating the hash value of warning line 3, since the first hash value obtained using only the code of warning line 3 overlaps with the hash value of warning line 1, the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame e from the first line of the source code to warning line 3 as shown in Fig. 7(c). With such a configuration, it is also possible to avoid overlapping of hash values.
[0055] Also, as another example of the range of code used for calculating the hash value, the code from the previous warning line to the warning line to be calculated may be used as the input. Fig. 8 is a diagram showing an example of performing such a calculation. In Fig. 8, the three lines starting with "tmp=" are warning lines 1 to 3.
[0056] In Fig. 8, since the hash values of warning line 1 do not overlap, the hash value is calculated using the code related to warning line 1 as the input. When calculating the hash value of warning line 2, since the first hash value obtained using only the code of warning line 2 overlaps with the hash value of warning line 1, the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame f from the line next to warning line 1 to warning line 2.
[0057] When calculating the hash value of warning line 3, since the first hash value obtained using only the code of warning line 3 overlaps with the hash value of warning line 1, the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame g from the line next to the previous warning line 2 to warning line 3. With such a configuration, it is also possible to reduce the overlapping of hash values.
[0058] (Second Embodiment) Next, an analysis result management device according to the second embodiment will be described. The basic configuration of the analysis result management device according to the second embodiment is the same as that of the analysis result management device 1 according to the first embodiment (see FIGS. 1 and 2), but the second analysis result management device is different in that it calculates a hash value in consideration of flow information related to a warning line.
[0059] FIG. 9 is a diagram for explaining the calculation process performed by the hash value calculation unit 14 of the analysis result management device according to the second embodiment. In FIG. 9, the warning line is "case 1:result=a / ZERO;break;" surrounded by frame a, warning that there is a possibility of an error in dividing a by ZERO. Here, it is defined in "#define ZERO 0" surrounded by frame h that ZERO is 0. That is, the variables in the code surrounded by frame a refer to the code surrounded by frame h, and these two lines are related. In the source code, when a certain problem is found as a warning, it may be necessary to view the processing flow up to the location where the problem occurred. In this document, such movement on the source code is called "flow information".
[0060] When calculating the hash value of the warning line surrounded by frame a, the hash value calculation unit 14 calculates the hash value using, as input, not only the code of the warning line but also the code of the line surrounded by frame h.
[0061] According to the analysis result management device according to the second embodiment, by calculating the hash value in consideration of not only the warning message and the source code but also the flow information related to the warning line, the occurrence of undetected warnings can be suppressed, and the quality of management of the analysis results can be improved.
[0062] In addition, in this embodiment, in addition to the configuration of the analysis result management device 1 of the first embodiment, the calculation of the hash value considering the flow information has been described. However, the calculation of the hash value considering the flow information described in the second embodiment does not assume the hash value calculation method for avoiding the duplication of the hash values described in the first embodiment. Therefore, in an analysis result management device that allows the same hash value to be assigned to the same type of warning, the calculation of the hash value considering the flow information may be performed.
[0063] (Third Embodiment) FIG. 10 is a diagram showing a functional configuration of the analysis result management device 3 of the third embodiment. The basic configuration of the analysis result management device 3 of the third embodiment is the same as that of the analysis result management device 1 of the first embodiment. However, the analysis result management device 3 of the third embodiment includes a warning response table 18. The warning response table 18 is a table showing the correspondence relationship of checkers that detect the same type of warning in the static analysis result data by a plurality of static analysis tools 20.
[0064] FIG. 11 is a diagram showing an example of data stored in the warning response table 18. The warning response table 18 shows the correspondence of checker names of tools X, Y, and Z, which are static analysis tools 20. In the example shown in FIG. 11, "Division By Zero" in tool X, "core.DivideZero" in tool Y, and "Integer division by zero" in tool Z correspond to each other. The warning response table 18 associates identification information with the checker name of each tool. Here, the identification information "INT31-C" is a character string assigned to the rule of "ensuring that data loss or misinterpretation does not occur due to integer conversion" in the CERT C coding standard. Although a meaningful character string may be used as the identification information in this way, random information without duplication may also be used. Note that in FIG. 11, the warning response table 18 stores the correspondence of checker names of three analysis tools, but the checker names of four or more analysis tools may also be associated. When the number of analysis tools increases, the checker name of the new analysis tool may be registered in the warning response table 18.
[0065] When calculating the hash value of a warning, the hash value calculation unit 14 determines whether the checker name of the warning to be calculated is recorded in the warning response table 18. If the checker name is recorded in the warning response table 18, the identification information corresponding to the checker name is read, and the hash value is calculated using the identification information as the input instead of the checker name.
[0066] FIG. 12 is a diagram for explaining the calculation process by the hash value calculation unit 14. The flow shown in FIG. 12 is positioned as the specific process of the first hash value calculation (S11) or the second hash value calculation (S13) in the hash value calculation flow shown in FIG. 6.
[0067] When calculating the hash value, the analysis result management device 3 according to the third embodiment first determines whether the checker name of the checker that detected the warning to be calculated exists in the warning response table 18 (S20). As a result of this determination, if the checker name exists in the warning response table 18, the identification information is read from the warning response table 18 (S21), and the hash value is calculated using the identification information as the input instead of the checker name among the data related to the warning (S23). That is, the file name of the source file and the identification information are used as the data related to the warning. In the analysis result management device 1 according to the first embodiment, when calculating the hash value, the file name of the source file, the name of the checker that performed the analysis, and the warning message are used as the information related to the warning, but the warning message is not used in this embodiment.
[0068] If the checker name of the checker that detected the warning to be calculated is not recorded in the warning response table 18 (NO in S20), the checker name is referred to (S22), and the hash value is calculated (S23). That is, the file name of the source file and the checker name are used as the data related to the warning.
[0069] FIG. 13 is a diagram showing an example of a screen for outputting the analysis results managed by the analysis result management device 3. The analysis results include, in association with the hash value for specifying the warning, the file name of the source file in which the warning was detected, the checker name that detected the warning, the warning message, the tool name of the static analysis tool 20 that detected the warning, the severity indicating the seriousness of the warning, and the data of the review result for the warning.
[0070] In this embodiment, when warnings detected by a plurality of static analysis tools 20 are warnings for the same code, they are output as one warning. Specifically, the hash value in the third line of FIG. 13 is associated with data of three tools, namely tool K, tool L, and tool M. Although they are warnings detected by each of the three static analysis tools 20, since they are warnings for the same code, they are treated as one warning. It is not necessary to handle the warnings for each static analysis tool 20. By inputting the review result once, it can be set that the handling of the warnings is completed.
[0071] Conventionally, when using a plurality of static analysis tools 20, there has been a problem that warnings may be displayed repeatedly, which takes time for judgment. However, according to this embodiment, it becomes possible to determine that the results of different static analysis tools 20 are the same warning, and the verification efficiency is improved.
[0072] Also, as shown in FIG. 13, although it is treated as one warning, the information of the static message and the tool name retains the data for each static analysis tool 20, so the static analysis results by each static analysis tool 20 can be referred to.
[0073] Note that in this embodiment, in the calculation of the hash value in the analysis result management device of the first embodiment, an example of referring to the warning response table 18 and assigning the same hash value to the same warning detected by a plurality of static analysis tools has been described (see FIG. 12). However, the technique of recognizing the warnings of a plurality of static analysis tools described in this embodiment as the same warning does not necessarily assume the configuration of the first embodiment. The hash value calculation unit 14 may calculate the hash value as shown in FIG. 14.
[0074] FIG. 14 is a diagram showing the process of hash value calculation by the analysis result management apparatus 3 according to the third embodiment. First, the hash value calculation unit 14 sorts the source files by file name and line number (S30). Subsequently, it is determined whether the checker name of the checker that detected the warning to be calculated exists in the warning response table 18 (S31). As a result of this determination, if the checker name exists in the warning response table 18 (YES in S31), the identification information is read from the warning response table 18 (S32), and the hash value is calculated using the identification information as the input instead of the checker name in the data related to the warning (S34).
[0075] If the checker name of the checker that detected the warning to be calculated is not recorded in the warning response table 18 (NO in S31), the checker name is referred to (S33), and the hash value is calculated (S34).
[0076] Subsequently, the hash value calculation unit 14 determines whether there are still warnings for which the hash value has not been calculated (S35). If there are still warnings for which the hash value has not been calculated (YES in S35), the process returns to step S31 of determining whether the checker name of the checker that detected the warning to be calculated exists in the warning response table 18. If there are no remaining warnings for which the hash value has not been calculated (NO in S35), the calculation process of the hash value for the corresponding static analysis result data is terminated.
[0077] Also, the technology described in this embodiment can of course be applied to the analysis result management apparatus of the second embodiment.
[0078] (Modification example) As described above, the embodiments of the analysis result management apparatus of the present invention have been described in detail. However, the analysis result management apparatus of the present invention is not limited to the above-described embodiments. The analysis result management apparatus may prepare a plurality of calculation methods regarding the calculation of the hash value and be able to select a calculation method suitable for the development policy of the product project or the like from among them.
[0079] FIG. 15 is a diagram showing the types of inputs used for calculating hash values in a plurality of calculation methods. In the example shown in FIG. 15, three calculation methods, namely, calculation methods 1 to 3, are described. FIG. 15 shows the data used as input for each calculation method. Specifically, the data described as "RE" is used for calculating the hash value.
[0080] The inputs used for calculating the hash value in calculation method 1 are the file name, the checker name, the warning message, and the code of the corresponding line. When the hash values overlap, codes within a predetermined range are used. The inputs used for calculating the hash value in calculation method 2 are the file name, the checker name, the warning message, the code of the corresponding line, and the code of the related line. When the hash values overlap, codes within a predetermined range are used. In contrast, the inputs used for calculating the hash value in calculation method 3 are the file name, the checker name, the warning message, and the code of the corresponding line. In calculation method 3, codes within a predetermined range are not used even when hash value duplication occurs. That is, in calculation method 3, duplication of hash values is allowed.
[0081] It is also possible to prepare calculation methods 1 to 3 that allow duplication of hash values as described above, and let the user select which calculation method to use. Specifically, data of calculation methods 1 to 3 is transmitted to the user terminal 40, and the calculation methods are displayed on the user terminal 40. Then, the analysis result management device 1 includes a selection reception unit that receives the selection of the calculation method, receives the selection data of the calculation method input by the user terminal 40 at the selection reception unit, and sets the calculation method according to the selection data.
[0082] Similarly, in the analysis result management device 3 of the third embodiment, it is also possible to prepare a calculation method that uses the warning response table 18 of the analysis results of the plurality of static analysis tools 20 and a calculation method that does not use it, and let the user select which calculation method to use.
[0083] Embodiments of the present invention may have the following configuration. (Aspect 1) The analysis result management device of aspect 1 includes an input unit that receives an input of static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, a hash value calculation unit that calculates a hash value using, as inputs, data related to the warning and code of a plurality of lines within a predetermined range including the line related to the warning, a database that stores the data of the warning in association with the hash value, and a display unit that displays the data stored in the database.
[0084] (Aspect 2) In the analysis result management device of aspect 1, when the first hash value calculated using, as inputs, data related to the warning and the code of the line related to the warning overlaps with any of the already calculated hash values, the hash value calculation unit may calculate a second hash value using, as inputs, the data related to the warning and code of a plurality of lines within a predetermined range including the line related to the warning, and use the second hash value as the hash value for the warning.
[0085] (Aspect 3) In the analysis result management device of aspect 2, when the first hash value calculated using, as inputs, data related to the warning and the code of the line related to the warning overlaps with any of the already calculated hash values, the hash value calculation unit may calculate a second hash value using, as inputs, the data related to the warning and code of a plurality of lines from the line related to the warning where the hash value first overlapped to the line related to the warning for which calculation is to be performed.
[0086] (Aspect 4) In the analysis result management device of aspect 2 or aspect 3, a selection reception unit that receives a selection as to whether to allow the first hash value calculated to overlap with any of the already calculated hash values is provided for the hash value calculation method, and when it is selected to allow overlap, the hash value calculation unit may obtain the first hash value as the hash value of the warning even when the first hash value overlaps with any of the already calculated hash values.
[0087] (Aspect 5) In the analysis result management device according to any one of Aspects 1 to 4, the hash value calculation unit may calculate a hash value by using, as inputs, data related to the warning, the line related to the warning, and codes of other lines related to the line related to the warning in the source code.
[0088] (Aspect 6) In the analysis result management device according to any one of Aspects 2 to 5, the hash value calculation unit may calculate the second hash value each time it is determined that the second hash value overlaps with any of the calculated first hash values.
[0089] (Aspect 7) The analysis result management device according to Aspect 7 includes an input unit that receives an input of static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, a hash value calculation unit that calculates a hash value by using, as inputs, data related to the warning, the code of the line related to the warning, and codes of other lines related to the line related to the warning in the source code, a database that stores the warning data in association with the hash value, and a display unit that displays the data stored in the database.
[0090] (Aspect 8) The analysis result management method according to Aspect 8 is a method for managing, by an analysis result management device, static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, and includes a step in which the analysis result management device receives an input of the static analysis result data, a step in which the analysis result management device calculates a hash value by using, as inputs, data related to the warning and codes of a plurality of lines within a predetermined range including the line related to the warning, a step in which the analysis result management device stores the warning data in a database in association with the hash value, and a step in which the analysis result management device displays the data stored in the database.
[0091] (Aspect 9) The analysis result management method of Aspect 9 is a method for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code by an analysis result management device, and includes steps of receiving input of the static analysis result data, calculating a hash value using, as inputs, data related to the warning, code of a line related to the warning, and code of other lines related to the line related to the warning in the source code, storing the warning data in a database in association with the hash value, and displaying data stored in the database.
[0092] (Aspect 10) The program of Aspect 10 is a program for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, and causes a computer to function as an input unit that receives input of the static analysis result data, a hash value calculation unit that calculates a hash value using, as inputs, data related to the warning and code of a plurality of lines within a predetermined range including the line related to the warning, a database that stores the warning data in association with the hash value, and a display unit that displays data stored in the database.
[0093] (Aspect 11) The program of Aspect 11 is a program for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, and causes a computer to function as an input unit that receives input of the static analysis result data, a hash value calculation unit that calculates a hash value using, as inputs, data related to the warning, code of a line related to the warning, and code of other lines related to the line related to the warning in the source code, a database that stores the warning data in association with the hash value, and a display unit that displays data stored in the database.
Explanation of Signs
[0094] 1, 3 ··· Analysis result management device, 11 ··· Data input unit 12... Data converter, 13... Data format conversion unit, 14... Hash value calculation unit, 15... Database, 16... Display unit, 17... Review result input unit, 18... Warning response table, 20... Static analysis tool, 30... Control unit, 31... CPU, 32... RAM, 33... ROM, 34... Input unit, 35... Output unit, 36... Storage unit, 37... Communication unit, 40... User terminal.
Claims
1. An input unit (11) that receives an input of static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code; A hash value calculation unit (14) that calculates a hash value using, as inputs, data related to the warning and a plurality of lines of code within a predetermined range including the line related to the warning; A database (15) that stores the warning data in association with the hash value; A display unit (16) that displays the data stored in the database; An analysis result management device (1) comprising the above.
2. The analysis result management device according to claim 1, wherein when the first hash value calculated using, as inputs, the data related to the warning and the code of the line related to the warning overlaps with any of the already calculated hash values, the hash value calculation unit calculates a second hash value using, as inputs, the data related to the warning and a plurality of lines of code within a predetermined range including the line related to the warning, and sets the second hash value as the hash value for the warning.
3. The analysis result management device according to claim 2, wherein when the first hash value calculated using, as inputs, the data related to the warning and the code of the line related to the warning overlaps with any of the already calculated hash values, the hash value calculation unit calculates a second hash value using, as inputs, the data related to the warning and a plurality of lines of code from the line related to the warning where the hash value first overlapped to the line related to the warning for which calculation is to be performed.
4. A selection reception unit that receives a selection as to whether or not to allow the first hash value, which has already been calculated, to overlap with any of the already calculated hash values, with respect to the method of calculating the hash value, The analysis result management device according to claim 2, wherein when it is selected to allow overlapping, the hash value calculation unit obtains the first hash value as the hash value of the warning even if the first hash value overlaps with any of the already calculated hash values.
5. The analysis result management device according to claim 2, wherein the hash value calculation unit calculates a hash value using, as inputs, the data related to the warning, the line related to the warning, and the code of other lines related to the line related to the warning in the source code.
6. The analysis result management device according to claim 2, wherein the hash value calculation unit calculates the second hash value each time it is determined that the first hash value overlaps with any of the already calculated hash values.
7. An input unit that receives an input of source code and static analysis result data including data of a plurality of warnings detected by statically analyzing the source code; A hash value calculation unit that calculates a hash value using, as inputs, data related to the warning, the code of the line related to the warning, and the codes of other lines related to the line related to the warning in the source code; A database that stores the warning data in association with the hash value; A display unit that displays the data stored in the database; An analysis result management device comprising the above.
8. A method for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code by an analysis result management device, comprising: A step in which the analysis result management device receives an input of the static analysis result data; A step in which the analysis result management device calculates a hash value using, as inputs, data related to the warning and a plurality of lines of code within a predetermined range including the line related to the warning; A step in which the analysis result management device stores the warning data in a database in association with the hash value; A step in which the analysis result management device displays the data stored in the database; An analysis result management method comprising the above.
9. A method for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code by an analysis result management device, comprising: A step of receiving an input of the static analysis result data; A step of calculating a hash value using, as inputs, data related to the warning, the code of the line related to the warning, and the codes of other lines related to the line related to the warning in the source code; A step of storing the warning data in a database in association with the hash value; A step of displaying the data stored in the database; An analysis result management method comprising the above.
10. A program for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, causing a computer to function as: An input unit that receives an input of the static analysis result data; A hash value calculation unit that calculates a hash value using, as inputs, data related to the warning and a plurality of lines of code within a predetermined range including the line related to the warning; A database that stores the warning data in association with the hash value; A display unit that displays data stored in the database A program that functions as
11. A program for managing static analysis result data including source code and data of a plurality of warnings detected by statically analyzing the source code, the computer being configured to An input unit that receives an input of the static analysis result data A hash value calculation unit that calculates a hash value using, as inputs, data related to the warning, the code of the line related to the warning, and the code of other lines related to the line related to the warning in the source code A database that stores the warning data in association with the hash value A display unit that displays data stored in the database A program that functions as
Citation Information
Patent Citations
Programming assist system and programming assist method
JP2020190973A
Information processing system, information processing method, development apparatus and program of development apparatus
JP2021039394A
Detecting mistyped identifiers and suggesting corrections using other program identifiers
US20170329697A1
Description output suppression program analysis system and description output suppression program analysis method
JP2004126866A