Analysis result management device, analysis result management method, and program
The analysis result management device addresses the issue of duplicate warnings from multiple static analysis systems by associating and hashing warnings, enabling efficient and accurate management of software development analysis results.
Patent Information
- Application Number
- JP2023219695
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-26
- Publication Date
- 2025-07-08
AI Technical Summary
In software development, using multiple static analysis systems leads to an increase in duplicate warnings for the same code errors, making it difficult for developers to efficiently manage and review analysis results.
An analysis result management device that associates different warning notations from various static analysis tools, calculates a unique hash value for each warning using identification information, and stores the results in a database for efficient display and review.
Suppresses duplicate warnings and allows developers to appropriately judge analysis results, improving review efficiency by treating identical warnings as a single entity.
Smart Images

Figure 2025102334000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an analysis result management device that manages the analysis results of source code, etc.
Background Art
[0002] In software development, due to coding errors, there are often problems where the software does not operate properly. Although this type of error can be prevented by reviewing the source code, as the scale of the software increases and the content becomes more complex, the number of problems increases rapidly.
[0003] For the purpose of detecting such errors before the program execution test, a static analysis system has been developed and sold that analyzes the source file of the software syntactically or semantically without actually executing it and outputs a warning for the description of the source code that may contain bugs. Such an analysis system outputs information that can be corrected by software developers.
[0004] The analysis system outputs the result of analyzing the source code, but the number of warnings included in the result is often enormous. In software development, multiple versions are created, and if a warning that has been confirmed in a previous version is warned again, it is necessary to reconfirm it despite being confirmed, which is inefficient. Patent Document 1 discloses a technique for suppressing warning messages by comparing the line and column numbers of the source code, the syntax of the analysis target, and the components in the syntax between the previous and subsequent versions.
[0005] Also, conventionally, a system is known that calculates a hash value for a set of the source code description content and the tool detection result and manages the analysis result using the hash value. By using the hash value, it is possible to easily compare the analysis results for different versions of the source code. Since analysis results with the same hash value can be treated as the same, the reuse of analysis results is also possible. In addition, it is possible to search for warnings using the hash value, enabling efficient and accurate management.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0007] When analyzing source code, multiple static analysis systems may be used. Since multiple static analysis systems can perform analysis from different viewpoints, the detection accuracy of source code errors can be improved.
[0008] However, when using multiple static analysis systems, for the same code error, multiple warnings are pointed out as different warnings, so the number of warnings increases accordingly, and it may become increasingly difficult for software developers to check the warning contents.
[0009] In view of the above background, an object of the present invention is to provide a technique capable of appropriately judging analysis results.
Means for Solving the Problems
[0010] The present invention adopts the following technical means to solve the above problems. The claims and the reference numerals in parentheses described in this section are an example showing the correspondence relationship with the specific means described in the embodiments to be described later as one aspect, and do not limit the technical scope of the present invention.
[0011] The analysis result management device of the present invention is an analysis result management device that manages a plurality of static analysis result data obtained by analyzing source code with different analysis tools, and includes a table that associates different warning notations and identification information output by the different analysis tools for the same type of warning, an input unit that receives inputs of the plurality of static analysis results of the source code, and a hash value calculation unit that calculates a hash value of the warning using data related to the warning as an input. When there is identification information corresponding to the warning notation that is the target of hash value calculation by referring to the table, the hash value calculation unit reads out the identification information and calculates the hash value using the read identification information instead of the warning notation, a database that stores the warning data in association with the hash value, and a display unit that displays the data stored in the database.
[0012] The analysis result management method of the present invention is an analysis result management method in which a plurality of static analysis result data obtained by analyzing source code with different analysis tools are managed by an analysis result management device. The method includes steps of: the analysis result management device preparing a table that associates different warning notations and identification information output by the different analysis tools for the same type of warning; the analysis result management device receiving inputs of the plurality of static analysis results of the source code; the analysis result management device calculating a hash value of the warning using data related to the warning as an input, and when there is identification information corresponding to the warning notation that is the target of hash value calculation by referring to the table, reading out the identification information and calculating the hash value using the read identification information instead of the warning notation; storing the warning data in association with the hash value in a database; and displaying the data stored in the database.
[0013] The program of the present invention is a program for managing a plurality of static analysis result data obtained by analyzing source code with different analysis tools, and causes a computer to perform the following operations: a table that associates different warning notations and identification information output by the different analysis tools for the same type of warning; an input unit that receives input of the plurality of static analysis results of the source code; a hash value calculation unit that calculates a hash value of the warning using data related to the warning as input, and reads the identification information corresponding to the warning notation that is the target of hash value calculation with reference to the table, and calculates the hash value using the read identification information instead of the warning notation; a database that stores the data of the warning in association with the hash value; and a display unit that functions to display the data stored in the database.
Effect of the Invention
[0014] According to the present invention, in the static analysis results by a plurality of analysis tools, the display of duplicate warnings is suppressed, and software developers can appropriately judge the analysis results.
Brief Description of the Drawings
[0015]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
[0016] Hereinafter, the analysis result management device according to the present embodiment will be described with reference to the drawings. Note that the following description shows only an example of a preferred aspect and is not intended to limit the invention described in the claims.
[0017] (First Embodiment) [Overall Configuration of Analysis Result Management Device] FIG. 1 is a diagram showing the functional configuration of the analysis result management apparatus 1 according to the present embodiment. The analysis result management apparatus 1 receives an input of the result of analyzing the source code of software by the static analysis tool 20 and manages the static analysis result data. The analysis result management apparatus 1 receives inputs of static analysis results from a plurality of static analysis tools 20.
[0018] FIG. 2 is a diagram showing the hardware configuration of the analysis result management apparatus 1 according to the present embodiment. The analysis result management apparatus 1 is arranged on a network, and the analysis result management apparatus 1 and the user terminal 40 can communicate via the network. Here, the type of the network is not limited, and for example, the Internet, an intranet within a company, or the like may be used. In the present embodiment, an example in which the analysis result management apparatus 1 is arranged on a network is shown, but the analysis result management apparatus 1 may be realized by a local PC. In this case, the local PC has the functions of the analysis result management apparatus 1 and the user terminal 40.
[0019] The analysis result management apparatus 1 includes a control unit 30 having a CPU 31, a RAM 32, and a ROM 33, an input unit 34, an output unit 35, a storage unit 36, and a communication unit 37. By executing the program stored in the ROM 33, the functions of the analysis result management apparatus 1 described later are realized. Such a program is also included in the scope of the present invention.
[0020] A user such as a software developer accesses the analysis result management apparatus 1 from the user terminal 40 through a web browser. The static analysis result data is transmitted from the user terminal 40 to the analysis result management apparatus 1. The analysis result management apparatus 1 manages the static analysis result data.
[0021] Returning to FIG. 1, the functions of the analysis result management apparatus 1 will be described. The analysis result management apparatus 1 includes a data input unit 11, a data converter 12, a database 15, a display unit 16, and a review result input unit 17.
[0022] The data input unit 11 receives the input of data of the static analysis results of the source file by the static analysis tool 20. The static analysis result data is data of warnings regarding the descriptions of the source code that may contain bugs. It is data indicating where in the source code there are syntax errors and what kinds of syntax errors there are. Also, the data input unit 11 receives the input of the data of the source file. The reason for inputting the source file is that, as will be described later, the analysis result management device 1 of the present embodiment also uses the data of the source code for calculating the hash value.
[0023] There are various tools as the static analysis tool 20. The data input unit 11 receives the input of data analyzed by different static analysis tools 20. The results of the static analysis differ depending on the static analysis tool 20. There may be descriptions that are detected as warnings by a certain static analysis tool 20 but not detected as warnings by another static analysis tool 20. This is due to the specifications of the static analysis tool 20, because the fields in which the static analysis tool 20 is good at analysis are different. By incorporating the static analysis results of a plurality of static analysis tools 20, a highly accurate review can be performed. The data input unit 11 passes the input static analysis result data to the data converter 12. Also, the data input unit 11 stores the source file in the database 15.
[0024] The data converter 12 has a data format conversion unit 13 and a hash value calculation unit 14. The static analysis result data input to the data input unit 11 has different items or different formats (for example, text data, HTML format, etc.) depending on the static analysis tool 20. The data format conversion unit 13 has a function of converting different data formats into a common format according to the static analysis result data.
[0025] The hash value calculation unit 14 has a function of calculating the hash value of the warnings included in the static analysis result data. The hash value is unique data calculated based on the data regarding the warnings and the code of the line related to the warnings, and is used as identification information for specifying the warnings. Details of the hash value calculation method will be described later.
[0026] By using the hash value as identification information, the same warning can be easily identified among source files with different versions. This can save the effort of reviewing warnings that have already been reviewed, and significantly reduce the review time of the source code.
[0027] The database 15 stores the static analysis results, review results, and source files. The data of the static analysis results has its data format converted by the data converter 12 and stores the data of the static analysis results with hash values assigned to the warnings.
[0028] Figure 3(a) is a diagram showing an example of the data of the static analysis results stored in the database 15. The data of the static analysis results has data of file name, checker name, warning message, tool name, severity, line, and column associated with the hash value. The hash value is identification information for identifying the warning and is calculated based on the data related to the warning and the data of the code of the line related to the warning.
[0029] The file name is the file name of the source file that is the target of the static analysis. The checker name is the name of the checker that detected the warning. One static analysis tool 20 has a plurality of checker algorithms, explores code that may have bugs by executing the checker algorithms, and outputs warnings. The warning message is a message for notifying the user of the content of the warning.
[0030] The tool name is the name of the static analysis tool 20 that detected the warning. The severity is data representing the severity of the warning. It is represented by a numerical value from 0 to 30, and the greater the number, the more serious the content of the warning. The line and column are data for specifying the location of the code related to the warning. The line represents the line number where the warning starts, and the column indicates the column number within the file. Note that this is just an example, and the data of the static analysis results may include data other than those shown in Figure 3(a).
[0031] Among the static analysis result data shown in FIG. 3(a), the notations of checker name, warning message, tool name, and severity data differ depending on the static analysis tool 20, and different notations are made for the same code error.
[0032] FIG. 3(b) is a diagram showing an example of the review result data stored in the database 15. The review result data has data of status, reviewer, comment, and review date and time associated with the hash value. The hash value corresponds to the hash value included in the static analysis result data and identifies the warning. The status is the status of the review situation for the warning identified by the hash value. For example, "confirmed" indicates that it has been confirmed, and "unreviewed" indicates that the review has not yet been performed. The reviewer is the name of the user who reviewed the warning and changed the status. The comment is a comment on what action was taken for the warning when the warning has been reviewed. The review date and time is the data of the date and time when the content of the warning was confirmed. Note that what is shown here is just an example, and the review result data may include data other than that shown in FIG. 3(b).
[0033] The display unit 16 has a function of displaying the analysis result data stored in the database 15 on the user terminal 40. Specifically, in response to a request from the user terminal 40, the analysis result data is read from the database 15, the analysis result data is transmitted to the user terminal 40, and the analysis result data is displayed on the user terminal 40.
[0034] When the review result data is transmitted from the user terminal 40, the review result input unit 17 stores the transmitted review result in the database 15 in association with the hash value indicating the corresponding warning. Specifically, the review result input unit 17 updates the status, reviewer, comment, and review date and time of the warning specified by the hash value.
[0035] [Calculation of Hash Value] Next, the calculation process of the hash value by the hash value calculation unit 14 will be described. The hash value calculation unit 14 calculates the hash value using the data related to the warning and the code related to the warning as inputs. As the data related to the warning, the file name of the source file, the name of the checker that performed the analysis, and the warning message are used. Note that what is shown here is an example of the data related to the warning used for calculating the hash value, and of course, other data related to the warning can also be used for calculating the hash value.
[0036] FIG. 4 is a diagram showing an example of the source code to be statically analyzed, and the calculation of the hash value will be described using the code shown in FIG. 4 as an example. In the example shown in FIG. 4, there may be an error in the code "len++", and it is detected as a warning. The hash value calculation unit 14 calculates the hash value using, in addition to the data related to the warning, the code "len++" which is the code related to the warning as an input.
[0037] Note that line numbers are not used in the calculation of the hash value. By adopting a configuration that does not include line numbers in the calculation of the hash value, even if the line numbers shift due to, for example, blank lines being inserted in source codes with different versions, the hash values will be the same, and it can be recognized that they are the same warning. However, by adopting a configuration that does not use line numbers in the calculation of the hash value, when the same warning exists in multiple lines, their hash values will be the same value.
[0038] Referring to FIG. 4, the codes of warning line 1 to warning line 3 are the same. Therefore, the contents of the data related to the warning (specifically, the file name of the source file, the name of the checker that performed the analysis, and the warning message) are also the same. Then, the hash values for the codes of warning line 1 to warning line 3 will be the same, and the same identification information will be assigned to the warnings of warning line 1 to warning line 3, and they will be treated as one warning. Although there is a way of thinking that such a treatment is acceptable, in the analysis result management device 1 of the present embodiment, even if multiple warnings have the same content, they are treated as separate warnings. The hash value calculation unit 14 calculates the hash value so as to distinguish the same warnings as shown in FIG. 4.
[0039] When the hash value calculation unit 14 calculates a hash value (for the sake of convenience of explanation, referred to as the "first hash value") using the data related to the warning and the code of the line related to the warning as inputs, and the calculated hash value overlaps with any of the already calculated hash values, the hash value (for the sake of convenience of explanation, referred to as the "second hash value") is calculated using, as inputs, the codes of a plurality of lines from the line related to the warning where the hash value first overlapped to the line related to the warning, and the second hash value is used as the hash value for the warning.
[0040] FIG. 5 is a diagram for explaining the codes used for calculating the hash values of the warnings of warning lines 1 to 3. In the explanation using FIG. 5, the focus is on the codes, but as described above, data related to the warning is used as an input for hash value calculation. FIG. 5(a) shows the codes used for obtaining the hash value of the warning of warning line 1. The code on the 4th line surrounded by frame a is used as an input.
[0041] FIG. 5(b) shows the codes used for obtaining the hash value of the warning of warning line 2. In addition to the code surrounded by frame a, the code on the 5th line surrounded by frame b from warning line 1 to warning line 2, where the hash value was first determined to overlap, is used as an input. FIG. 5(c) shows the codes used for obtaining the hash value of the warning of warning line 3. In addition to the code surrounded by frame a, the codes on the 5th to 7th lines surrounded by frame c from warning line 1 to warning line 3, where the hash value was first determined to overlap, are used as inputs.
[0042] As shown in FIGS. 5(a) to 5(c), even when the same warning is detected for the code "len++", the hash values can be distinguished by changing the range of the codes used for calculating the hash values.
[0043] FIG. 6 is a flowchart showing the calculation process by the hash value calculation unit 14. First, the hash value calculation unit 14 sorts all the warnings in the data of the static analysis results by the warning file name and line number (S10). Subsequently, the hash value calculation unit 14 calculates the first hash value by using the data related to the warning and the code of the line related to the warning as inputs (S11), and determines whether the same hash value as the obtained first hash value already exists (S12).
[0044] When the same hash value exists (YES in S12), the hash value calculation unit 14 calculates the second hash value by using, in addition to the data related to the warning and the code of the line related to the warning, the code from the line where the hash value first duplicates to the warning line to be calculated (S13), and sets the second hash value as the hash value for the warning. At this time, for parts such as blanks and comments that have no direct impact on the warning, they may or may not be used in the calculation of the hash value. Subsequently, the hash value calculation unit 14 determines whether there are still warnings for which the hash value has not been calculated (S14). If there are still warnings for which the hash value has not been calculated (YES in S14), it returns to step S11 to calculate the first hash value for the warning.
[0045] In the determination of whether the same hash value as the first hash value already exists (S12), if it is determined that the same hash value does not exist (NO in S12), the first hash value is set as the hash value of the warning to be calculated. In the determination of whether there are still warnings for which the hash value has not been calculated (S14), if there are no warnings for which the hash value has not been calculated (NO in S14), the calculation process of the hash value for the corresponding static analysis result data is terminated.
[0046] The analysis result management device 1 and the analysis result management method of the first embodiment have been described above. When the first hash value overlaps with an existing hash value, the analysis result management device 1 of the first embodiment calculates a second hash value using the code from the warning line where the hash value first overlapped to the warning line to be calculated as input, thereby avoiding hash value duplication. Since the code before the first hash value overlap does not affect the calculation of the second hash value, even if there were previous modifications, it does not affect the differential analysis between versions. As a result, warnings can be appropriately managed.
[0047] Software under development is frequently changed due to version upgrades and the like. Therefore, it is important to identify the points of change and problems. According to the analysis result management device 1 of this embodiment, by devising a method for managing the analysis results of the source code before and after the software under development and a method for managing the analysis results, different warnings can be distinguished and undetected problems can be improved.
[0048] In the first embodiment described above, when calculating the second hash value, the code from the warning line where the hash value first overlapped to the warning line to be calculated was used as input, but it is also possible to use the code in another range as input. For example, the hash value may be calculated using the code from the first line of the source code to the warning line to be calculated as input.
[0049] FIG. 7 is a diagram showing an example of the code used for calculating the second hash value. FIGS. 7(a) to 7(c) respectively correspond to FIGS. 5(a) to 5(c), and show an example of obtaining the hash values of warning lines 1 to 3.
[0050] In Fig. 7(a), since the hash values of warning line 1 do not overlap, the hash value is calculated using the code related to warning line 1 as the input. When calculating the hash value of warning line 2, the first hash value obtained using only the code of warning line 2 overlaps with the hash value of warning line 1. Therefore, as shown in Fig. 7(b), the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame d from the first line of the source code to warning line 2 as the input.
[0051] When calculating the hash value of warning line 3, the first hash value obtained using only the code of warning line 3 overlaps with the hash value of warning line 1. Therefore, as shown in Fig. 7(c), the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame e from the first line of the source code to warning line 3 as the input. Even with such a configuration, overlapping of hash values can be avoided.
[0052] Also, as another example of the range of code used for calculating the hash value, the code from the previous warning line to the warning line to be calculated may be used as the input. Fig. 8 is a diagram showing an example of performing the calculation in this way. In Fig. 8, the three lines starting with "tmp=" are warning lines 1 to 3.
[0053] In Fig. 8, since the hash values of warning line 1 do not overlap, the hash value is calculated using the code related to warning line 1 as the input. When calculating the hash value of warning line 2, the first hash value obtained using only the code of warning line 2 overlaps with the hash value of warning line 1. Therefore, the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame f from the line next to warning line 1 to warning line 2 as the input.
[0054] When calculating the hash value of warning line 3, the first hash value obtained using only the code of warning line 3 overlaps with the hash value of warning line 1. Therefore, the hash value calculation unit 14 calculates the second hash value using the code in the range enclosed by the frame g from the line next to the previous warning line 2 to warning line 3 as the input. Even with such a configuration, overlapping of hash values can be reduced.
[0055] (Second Embodiment) Next, an analysis result management device according to the second embodiment will be described. The basic configuration of the analysis result management device according to the second embodiment is the same as that of the analysis result management device 1 according to the first embodiment (see FIGS. 1 and 2), but the second analysis result management device calculates a hash value in consideration of flow information related to the warning line, which is different.
[0056] FIG. 9 is a diagram for explaining the calculation process performed by the hash value calculation unit 14 of the analysis result management device according to the second embodiment. In FIG. 9, the warning line is "case 1:result=a / ZERO;break;" enclosed by frame a, warning that there is a possibility of an error in dividing a by ZERO. Here, it is defined in "#define ZERO 0" enclosed by frame h that ZERO is 0. That is, the variables in the code enclosed by frame a refer to the code enclosed by frame h, and these two lines are related. In the source code, when a certain problem is found as a warning, it may be necessary to view the processing flow up to the location where the problem occurred. In this document, such movement on the source code is called "flow information".
[0057] When calculating the hash value of the warning line enclosed by frame a, the hash value calculation unit 14 calculates the hash value using, as input, the code of the line enclosed by frame h in addition to the code of the warning line.
[0058] According to the analysis result management device according to the second embodiment, by calculating the hash value in consideration of not only the warning message and the source code but also the flow information related to the warning line, the occurrence of undetected warnings can be suppressed, and the quality of management of the analysis results can be improved.
[0059] Note that in this embodiment, in addition to the configuration of the analysis result management device 1 of the first embodiment, the calculation of the hash value considering the flow information has been described. However, the calculation of the hash value considering the flow information described in the second embodiment is not premised on the hash value calculation method for avoiding hash value duplication described in the first embodiment. Therefore, in an analysis result management device that allows the same hash value to be assigned to the same type of warning, the calculation of the hash value considering the flow information may be performed.
[0060] (Third Embodiment) FIG. 10 is a diagram showing a functional configuration of the analysis result management device 3 of the third embodiment. The basic configuration of the analysis result management device 3 of the third embodiment is the same as that of the analysis result management device 1 of the first embodiment. However, the analysis result management device 3 of the third embodiment includes a warning response table 18. The warning response table 18 is a table showing the correspondence relationship of checkers that detect the same type of warning in the static analysis result data by a plurality of static analysis tools 20.
[0061] FIG. 11 is a diagram showing an example of data stored in the warning response table 18. The warning response table 18 shows the correspondence of checker names of tools X, Y, and Z, which are static analysis tools 20. In the example shown in FIG. 11, "Division By Zero" in tool X, "core.DivideZero" in tool Y, and "Integer division by zero" in tool Z correspond to each other. The warning response table 18 associates identification information with the checker name of each tool. Here, the identification information "INT31-C" is a character string assigned to the rule of "ensuring that data loss or misinterpretation does not occur due to integer conversion" in the CERT C coding standard. Although a meaningful character string may be used as the identification information in this way, random information without duplication may also be used. Note that in FIG. 11, the warning response table 18 stores the correspondence of checker names of three analysis tools, but the checker names of four or more analysis tools may also be associated. When the number of analysis tools increases, the checker name of the new analysis tool may be registered in the warning response table 18.
[0062] When calculating the hash value of a warning, the hash value calculation unit 14 determines whether the checker name of the warning to be calculated is recorded in the warning response table 18. If the checker name is recorded in the warning response table 18, the identification information corresponding to the checker name is read out, and the hash value is calculated using the identification information as the input instead of the checker name.
[0063] FIG. 12 is a diagram for explaining the calculation process by the hash value calculation unit 14. The flow shown in FIG. 12 is positioned as the specific process of the first hash value calculation (S11) or the second hash value calculation (S13) in the hash value calculation flow shown in FIG. 6.
[0064] When calculating the hash value, the analysis result management device 3 according to the third embodiment first determines whether the checker name of the checker that detected the warning to be calculated exists in the warning response table 18 (S20). As a result of this determination, if the checker name exists in the warning response table 18, the identification information is read from the warning response table 18 (S21), and the hash value is calculated using the identification information as the input instead of the checker name among the data related to the warning (S23). That is, the file name of the source file and the identification information are used as the data related to the warning. In the analysis result management device 1 according to the first embodiment, when calculating the hash value, the file name of the source file, the name of the checker that performed the analysis, and the warning message were used as the information related to the warning, but the warning message is not used in this embodiment.
[0065] If the checker name of the checker that detected the warning to be calculated is not recorded in the warning response table 18 (NO in S20), the checker name is referred to (S22), and the hash value is calculated (S23). That is, the file name of the source file and the checker name are used as the data related to the warning.
[0066] FIG. 13 is a diagram showing an example of a screen that outputs the analysis results managed by the analysis result management device 3. The analysis results include, in association with the hash value for specifying the warning, the file name of the source file in which the warning was detected, the checker name that detected the warning, the warning message, the tool name of the static analysis tool 20 that detected the warning, the severity indicating the severity of the warning, and the data of the review result for the warning.
[0067] In this embodiment, when warnings detected by a plurality of static analysis tools 20 are warnings for the same code, they are output as one warning. Specifically, the hash value in the third line in FIG. 13 is associated with data from three tools, namely tool K, tool L, and tool M. Although the warnings are detected by each of the three static analysis tools 20, since they are warnings for the same code, they are treated as one warning. It is not necessary to handle the warnings for each static analysis tool 20. By inputting the review result once, it can be set that the handling of the warnings is completed.
[0068] Conventionally, when using a plurality of static analysis tools 20, there has been a problem that warnings may be displayed repeatedly, which takes time for judgment. However, according to this embodiment, it becomes possible to determine that the results of different static analysis tools 20 are the same warning, and the verification efficiency can be improved.
[0069] Also, as shown in FIG. 13, although it is treated as one warning, the information of the static message and the tool name remains the data for each static analysis tool 20, so the static analysis results by each static analysis tool 20 can be referred to.
[0070] In this embodiment, an example has been described in which, during the calculation of the hash value in the analysis result management device of the first embodiment, with reference to the warning response table 18, the same hash value is assigned to the same warning detected by a plurality of static analysis tools (see FIG. 12). However, the technique of recognizing the warnings of a plurality of static analysis tools described in this embodiment as the same warning does not necessarily assume the configuration of the first embodiment. The hash value calculation unit 14 may calculate the hash value as shown in FIG. 14.
[0071] FIG. 14 is a diagram showing the process of hash value calculation by the analysis result management device 3 according to the third embodiment. First, the hash value calculation unit 14 sorts the source files by file name and line number (S30). Subsequently, it is determined whether the checker name of the checker that detected the warning to be calculated exists in the warning response table 18 (S31). As a result of this determination, if the checker name exists in the warning response table 18 (YES in S31), the identification information is read from the warning response table 18 (S32), and the hash value is calculated using the identification information as the input instead of the checker name among the data related to the warning (S34).
[0072] If the checker name of the checker that detected the warning to be calculated is not recorded in the warning response table 18 (NO in S31), the checker name is referred to (S33), and the hash value is calculated (S34).
[0073] Subsequently, the hash value calculation unit 14 determines whether there are still warnings for which the hash value has not been calculated (S35). If there are still warnings for which the hash value has not been calculated (YES in S35), the process returns to step S31 where it is determined whether the checker name of the checker that detected the warning to be calculated exists in the warning response table 18. If there are no remaining warnings for which the hash value has not been calculated (NO in S35), the calculation process of the hash value for the corresponding static analysis result data is terminated.
[0074] Also, the technology described in this embodiment can of course be applied to the analysis result management device of the second embodiment.
[0075] (Modification example) As described above, the embodiments of the analysis result management device of the present invention have been described in detail with examples, but the analysis result management device of the present invention is not limited to the above-described embodiments. Regarding the calculation of the hash value, the analysis result management device may prepare a plurality of calculation methods and be able to select a calculation method that suits the development policy of the product project, etc. from among them.
[0076] FIG. 15 is a diagram showing the types of inputs used for calculating hash values in a plurality of calculation methods. In the example shown in FIG. 15, three calculation methods, namely calculation methods 1 to 3, are described. FIG. 15 shows the data used as inputs in each calculation method. Specifically, the data with "レ" described is used for calculating the hash value.
[0077] The inputs used for hash value calculation in calculation method 1 are the file name, checker name, warning message, and code of the corresponding line. When the hash values overlap, codes within a predetermined range are used. The inputs used for hash value calculation in calculation method 2 are the file name, checker name, warning message, code of the corresponding line, and code of the related line. When the hash values overlap, codes within a predetermined range are used. In contrast, the inputs used for hash value calculation in calculation method 3 are the file name, checker name, warning message, and code of the corresponding line. In calculation method 3, codes within a predetermined range are not used even if hash value duplication occurs. That is, in calculation method 3, duplication of hash values is allowed.
[0078] It is also possible to prepare calculation methods 1 to 3 that allow duplication of hash values as described above, and let the user select which calculation method to use. Specifically, the data of calculation methods 1 to 3 is transmitted to the user terminal 40, and the calculation methods are displayed on the user terminal 40. Then, the analysis result management device 1 includes a selection reception unit that receives the selection of the calculation method, receives the selection data of the calculation method input by the user terminal 40 at the selection reception unit, and sets the calculation method according to the selection data.
[0079] Similarly, in the analysis result management device 3 of the third embodiment, it is also possible to prepare a calculation method that uses the warning response table 18 of the analysis results of the plurality of static analysis tools 20 and a calculation method that does not use it, and let the user select which calculation method to use.
[0080] Embodiments of the present invention may have the following configuration. (Aspect 1) The analysis result management device of Aspect 1 is an analysis result management device that manages a plurality of static analysis result data obtained by analyzing source code using different analysis tools. The device includes a table that associates different warning notations and identification information output by the different analysis tools for the same type of warning, an input unit that receives inputs of the plurality of static analysis results of the source code, and a hash value calculation unit that calculates a hash value using data related to the warning as an input. When there is identification information corresponding to the warning notation that is the target of hash value calculation by referring to the table, the hash value calculation unit reads out the identification information and calculates the hash value using the read identification information instead of the warning notation. The device also includes a database that stores the warning data in association with the hash value, and a display unit that displays the data stored in the database.
[0081] (Aspect 2) The analysis result management device of Aspect 1 may include a review result input unit that receives an input of a review result for a warning, and the review result input unit may store the review result data in the database in association with the hash value corresponding to the warning.
[0082] (Aspect 3) In the analysis result management device of Aspect 1 or Aspect 2, the display unit may display warning notations of a plurality of analysis tools in association with one hash value for warnings having the same hash value.
[0083] (Aspect 4) The analysis result management device according to any one of Aspects 1 to 3 includes a selection reception unit that receives a selection as to whether to make different static analysis results common in terms of the hash value calculation method, and the hash value calculation unit may calculate a hash value using, as an input, data related to warnings included in the static analysis result input from the analysis tool without referring to the table.
[0084] (Aspect 5) In the analysis result management device according to any one of Aspects 1 to 4, the hash value calculation unit calculates a hash value by using, as inputs, the data related to the warning, the line related to the warning, and the codes of other lines related to the line in the source code. The analysis result management device according to claim 1.
[0085] (Aspect 6) The analysis result management method of Aspect 6 is an analysis result management method in which a plurality of static analysis result data obtained by analyzing source code by different analysis tools are managed by an analysis result management device. The method includes: preparing a table in which the analysis result management device associates different warning notations and identification information output by the different analysis tools for the same type of warning; receiving, by the analysis result management device, inputs of a plurality of the static analysis results of the source code; calculating, by the analysis result management device, a hash value of the warning by using, as an input, the data related to the warning, the step of reading the identification information corresponding to the warning notation to be the target of hash value calculation with reference to the table and performing hash value calculation by using the read identification information instead of the warning notation when there is the identification information; storing, in a database, the data of the warning in association with the hash value; and displaying the data stored in the database.
[0086] (Aspect 7) The program of aspect 7 is a program for managing a plurality of static analysis result data obtained by analyzing source code with different analysis tools. The program causes a computer to function as a table that associates different warning notations output by the different analysis tools for the same type of warning with identification information, an input unit that receives input of the plurality of static analysis results of the source code, a hash value calculation unit that calculates a hash value of the warning using the data related to the warning as input, and when there is identification information corresponding to the warning notation targeted for hash value calculation by referring to the table, reads out the identification information and calculates the hash value using the read-out identification information instead of the warning notation, a database that stores the warning data in association with the hash value, and a display unit that displays the data stored in the database.
Explanation of Signs
[0087] 1, 3 ··· Analysis result management device, 11 ··· Data input unit, 12 ··· Data converter, 13 ··· Data format conversion unit, 14 ··· Hash value calculation unit, 15 ··· Database, 16 ··· Display unit, 17 ··· Review result input unit, 18 ··· Warning correspondence table, 20 ··· Static analysis tool, 30 ··· Control unit, 31 ··· CPU, 32 ··· RAM, 33 ··· ROM, 34 ··· Input unit, 35 ··· Output unit, 36 ··· Storage unit, 37 ··· Communication unit, 40 ··· User terminal.
Claims
1. An analysis result management device for managing a plurality of static analysis result data obtained by analyzing source code using different analysis tools, a table (18) associating different warning notations and identification information output by the different analysis tools for the same type of warning, an input unit (11) for receiving input of a plurality of the static analysis results of the source code, a hash value calculation unit that calculates a hash value using data related to the warning as input, and when there is identification information corresponding to the warning notation that is the target of hash value calculation by referring to the table, reads out the identification information and calculates the hash value using the read identification information instead of the warning notation, the hash value calculation unit (14), a database (15) that stores the data related to the warning in association with the hash value, a display unit (16) that displays the data stored in the database, and an analysis result management device (3) comprising the same.
2. comprising a review result input unit for receiving input of a review result for a warning, wherein the review result input unit stores the review result data in the database in association with the hash value corresponding to the warning, the analysis result management device according to claim 1.
3. wherein the display unit displays warning notations of a plurality of analysis tools in association with one hash value for warnings having the same hash value, the analysis result management device according to claim 2.
4. comprising a selection reception unit for receiving a selection as to whether to make the commonization of different static analysis results for the calculation method of the hash value, wherein the hash value calculation unit calculates a hash value using data related to the warning included in the static analysis result input from the analysis tool as input without referring to the table, the analysis result management device according to claim 2.
5. wherein the hash value calculation unit calculates a hash value using the data related to the warning, the line related to the warning, and the code of other lines related to the line in the source code as input, the analysis result management device according to claim 2.
6. An analysis result management method for managing a plurality of static analysis result data obtained by analyzing source code using different analysis tools by an analysis result management device, the step of the analysis result management device preparing a table associating different warning notations and identification information output by the different analysis tools for the same type of warning, A step in which a parsing result management device receives an input of a plurality of the static parsing results of source code; A step in which a parsing result management device calculates a hash value of a warning using data related to the warning as an input, and when there is identification information corresponding to a warning notation that is a target of hash value calculation by referring to the table, reads out the identification information and calculates the hash value using the read identification information instead of the warning notation; A step of storing the warning data in a database in association with the hash value; A step of displaying the data stored in the database; A parsing result management method comprising the above.
7. A program for managing a plurality of static parsing result data obtained by parsing source code using different parsing tools, causing a computer to A table associating different warning notations and identification information output by the different parsing tools for the same type of warning; An input unit that receives an input of a plurality of the static parsing results of source code; A hash value calculation unit that calculates a hash value of a warning using data related to the warning as an input, and when there is identification information corresponding to a warning notation that is a target of hash value calculation by referring to the table, reads out the identification information and calculates the hash value using the read identification information instead of the warning notation; A database that stores the warning data in association with the hash value; A display unit that displays the data stored in the database; A program that functions as the above.
Citation Information
Patent Citations
Analysis result output device and analysis result output method
JP2009169573A
Description output suppression program analysis system and description output suppression program analysis method
JP2004126866A