Re: PVS-Studio Analyzer Spots Bugs In the FreeBSD 2017 edition

2017-04-07 Thread Warner Losh
On Fri, Apr 7, 2017 at 3:50 PM, Tommi Pernila  wrote:
> Hi all,
>
> just a heads up if you haven't yet seen this blog post from Andrey Karpov
> from PVS-Studio.
> It's a quite a long read.
> https://www.viva64.com/en/b/0496/
>
> Here's a few highlights (with some paraphrasing).
>
>>PVS-Studio fixed errors where it's clear how to fix them without digging
> deep into the algorithms.
>>That's why FreeBSD authors should really do a deeper analysis themselves,
>>not just review that limited number of errors that we presented.
>
>>Andrey Karpov is ready to provide a temporary license key and also help to
> eliminate false positives that may hinder their work.
>
> Anyone up for this task?

There's folks that have contacted him. It's not quite as simple as he
said in his post to give access to a run, since they need to filter
things appropriately. It should be published next week, we're told, so
we can make easy use of the results.

Warner
___
freebsd-current@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscr...@freebsd.org"


PVS-Studio Analyzer Spots Bugs In the FreeBSD 2017 edition

2017-04-07 Thread Tommi Pernila
Hi all,

just a heads up if you haven't yet seen this blog post from Andrey Karpov
from PVS-Studio.
It's a quite a long read.
https://www.viva64.com/en/b/0496/

Here's a few highlights (with some paraphrasing).

>PVS-Studio fixed errors where it's clear how to fix them without digging
deep into the algorithms.
>That's why FreeBSD authors should really do a deeper analysis themselves,
>not just review that limited number of errors that we presented.

>Andrey Karpov is ready to provide a temporary license key and also help to
eliminate false positives that may hinder their work.

Anyone up for this task?


>FreeBSD code is regularly checked by Coverity (which is now a part of
Synopsys).
>Still, it didn't prevent me from finding 56 potential vulnerabilities and
10 more real bugs in one evening by running PVS-Studio on this code.


Br,

Tommi
___
freebsd-current@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscr...@freebsd.org"