static analysis of C/C++ code
Go to file
Ken-Patrick Lehrmann 24211cf8b9 Fix crashes in valueflow (#2236)
* Fix crashes in valueflow

http://cppcheck1.osuosl.org:8000/crash.html

For instance in http://cppcheck1.osuosl.org:8000/styx
```
==19651==ERROR: AddressSanitizer: SEGV on unknown address 0x00000000001c (pc 0x556f21abc3df bp 0x7ffc140d2720 sp 0x7ffc140d2710 T0)
==19651==The signal is caused by a READ memory access.
==19651==Hint: address points to the zero page.
    #0 0x556f21abc3de in Variable::isGlobal() const ../lib/symboldatabase.h:342
    #1 0x556f221f801a in valueFlowForwardVariable ../lib/valueflow.cpp:2471
    #2 0x556f22208130 in valueFlowForward ../lib/valueflow.cpp:3204
    #3 0x556f221e9e14 in valueFlowReverse ../lib/valueflow.cpp:1892
    #4 0x556f221f1a43 in valueFlowBeforeCondition ../lib/valueflow.cpp:2200
    #5 0x556f2223dbb5 in ValueFlow::setValues(TokenList*, SymbolDatabase*, ErrorLogger*, Settings const*) ../lib/valueflow.cpp:6521
    #6 0x556f220e5991 in Tokenizer::simplifyTokens1(std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const&) ../lib/tokenize.cpp:2342
    #7 0x556f21d8d066 in CppCheck::checkFile(std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const&, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const&, std::istream&) ../lib/cppcheck.cpp:508
    #8 0x556f21d84cd3 in CppCheck::check(std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const&) ../lib/cppcheck.cpp:192
    #9 0x556f21a28796 in CppCheckExecutor::check_internal(CppCheck&, int, char const* const*) ../cli/cppcheckexecutor.cpp:884
    #10 0x556f21a24be8 in CppCheckExecutor::check(int, char const* const*) ../cli/cppcheckexecutor.cpp:198
    #11 0x556f22313063 in main ../cli/main.cpp:95
```

* Add test case for crash in valueflow
2019-10-16 20:54:07 +02:00
Cppcheck.xcodeproj Fix xcode project file 2015-11-23 23:00:21 +03:00
addons Add check for MISRA-C 2012 rule 3.2 and test cases. (#2269) 2019-10-16 11:31:42 +02:00
cfg std.cfg: Add support for C11 functions thrd_*() and mtx_*() (#2270) 2019-10-16 12:13:16 +02:00
cli ExprEngine: Add --debug-verify, fixed handling of global arrays 2019-09-29 15:00:54 +02:00
cmake Set version to 1.89.99/1.90 dev 2019-09-02 15:44:40 +02:00
cve-test-suite cve test suite: Add a download script 2018-10-06 11:36:54 +02:00
democlient democlient: Fixed override 2019-02-09 13:31:50 +01:00
externals bump simplecpp (#2245) 2019-10-08 10:38:22 +02:00
gui Add impossible values to ValueFlow (#2186) 2019-09-20 15:06:37 +02:00
htmlreport Update cppcheck-htmlreport (#1858) 2019-05-30 10:37:52 +02:00
lib Fix crashes in valueflow (#2236) 2019-10-16 20:54:07 +02:00
man Add missing ending tag in XML example (#2187) 2019-09-20 16:46:57 +02:00
oss-fuzz Update include path 2019-06-24 20:53:19 +02:00
platforms #8424 Supply platform files for each platform instead of generic ones. Supply platform file for AIX ppc64 2019-01-01 16:04:02 +01:00
rules Format rules files as well 2019-09-26 19:58:39 +02:00
samples Try to fix Travis 2019-08-20 22:00:50 +02:00
snap Fix permissions of certain non-executable files (#1083) 2018-02-09 19:46:38 +01:00
test Fix crashes in valueflow (#2236) 2019-10-16 20:54:07 +02:00
tools Fix #9299 (Makefile: tools/matchcompiler.py is executed via Python 2) (#2247) 2019-10-08 10:55:40 +02:00
win_installer Set version to 1.89.99/1.90 dev 2019-09-02 15:44:40 +02:00
.astylerc Move astyle options to a separate file. That way keeping it in sync b… (#1468) 2018-11-09 09:55:34 +01:00
.codacy.yml Codacy: Try to exclude all addon test files 2018-10-18 09:29:38 +02:00
.gitignore Feature/ros naming check (#1511) 2019-01-09 18:16:51 +01:00
.mailmap
.travis.yml print stack trace for UBSAN errors / enabled detect_stack_use_after_return for ASAN (#2252) 2019-10-16 13:46:23 +02:00
.travis_llvmcheck_suppressions Travis: updated the .travis_llvmcheck_suppressions file, * is not allowed 2018-11-19 15:42:40 +01:00
.travis_suppressions Fix false negatives in checkBitwiseOnBoolean (#2220) 2019-10-06 09:57:31 +02:00
AUTHORS Updated AUTHORS 2019-09-14 14:40:39 +02:00
CMakeLists.txt Compiling/Installing : The CFGDIR parameter was removed. Use FILESDIR instead. 2019-08-17 10:53:07 +02:00
COPYING
Makefile Fix #9299 (Makefile: tools/matchcompiler.py is executed via Python 2) (#2247) 2019-10-08 10:55:40 +02:00
appveyor.yml appveyor.yml: Add Cygwin build and tests (#2006) 2019-07-17 10:22:08 +02:00
benchmarks.txt benchmarks: Added CImg. Removed old stuff. 2019-03-04 07:05:40 +01:00
build-pcre.txt Updated/Improved several readme files 2015-11-06 15:19:08 +01:00
build.bat
console_common.pri
cppcheck-errors.rng cppcheck-errors.rng: added column attribute 2019-08-18 14:06:16 +02:00
cppcheck.cbp
cppcheck.cppcheck Add cppcheck.cppcheck build dir 2018-02-23 22:16:49 +01:00
cppcheck.sln Updated to Visual Studio 2019 2019-07-06 12:11:19 +02:00
createrelease removed manual.docbook 2019-09-12 20:48:20 +02:00
doxyfile Fix typos (#1568) 2019-01-06 17:15:57 +01:00
generate_coverage_report Adjust options for lcov/genhtml to unmangled symbols and HTML frames 2016-02-02 12:23:33 +01:00
naming.json Travis: Check the naming conventions again 2019-07-15 20:58:07 +02:00
philosophy.md Added a philosophy.md document. 2018-09-06 20:14:55 +02:00
pylintrc_travis .travis.yml: Check more Python scripts with pylint (#2019) 2019-07-24 21:09:53 +02:00
readme.md Compiling/Installing : The CFGDIR parameter was removed. Use FILESDIR instead. 2019-08-17 10:53:07 +02:00
readme.txt Compiling/Installing : The CFGDIR parameter was removed. Use FILESDIR instead. 2019-08-17 10:53:07 +02:00
readmeja.md Update readmeja (#2108) 2019-08-22 22:15:09 +02:00
requirements.txt Update pcre version since the link is broken (#2089) 2019-08-15 20:48:10 +02:00
runastyle Format rules files as well 2019-09-26 19:58:39 +02:00
runastyle.bat Move astyle options to a separate file. That way keeping it in sync b… (#1468) 2018-11-09 09:55:34 +01:00
webreport.sh webreport: skip simian 2017-12-26 12:04:42 +01:00

readme.md

Cppcheck

Linux Build Status Windows Build Status Coverity Scan Build Status
Linux Build Status Windows Build Status Coverity Scan Build Status

About the name

The original name of this program was "C++check", but it was later changed to "Cppcheck".

Despite the name, Cppcheck is designed for both C and C++.

Manual

A manual is available online.

Compiling

Any C++11 compiler should work. For compilers with partial C++11 support it may work. If your compiler has the C++11 features that are available in Visual Studio 2013 / GCC 4.6 then it will work.

To build the GUI, you need Qt.

When building the command line tool, PCRE is optional. It is used if you build with rules.

There are multiple compilation choices:

  • qmake - cross platform build tool
  • cmake - cross platform build tool
  • Windows: Visual Studio (VS 2013 and above)
  • Windows: Qt Creator + mingw
  • gnu make
  • g++ 4.6 (or later)
  • clang++

cmake

Example, compiling Cppcheck with cmake:

mkdir build
cd build
cmake ..
cmake --build .

If you want to compile the GUI you can use the flag -DBUILD_GUI=ON

For rules support (requires pcre) use the flag -DHAVE_RULES=ON

For release builds it is recommended that you use: -DUSE_MATCHCOMPILER=ON

qmake

You can use the gui/gui.pro file to build the GUI.

cd gui
qmake
make

Visual Studio

Use the cppcheck.sln file. The file is configured for Visual Studio 2019, but the platform toolset can be changed easily to older or newer versions. The solution contains platform targets for both x86 and x64.

To compile with rules, select "Release-PCRE" or "Debug-PCRE" configuration. pcre.lib (pcre64.lib for x64 builds) and pcre.h are expected to be in /externals then. A current version of PCRE for Visual Studio can be obtained using vcpkg.

Qt Creator + MinGW

The PCRE dll is needed to build the CLI. It can be downloaded here: http://software-download.name/pcre-library-windows/

GNU make

Simple, unoptimized build (no dependencies):

make

The recommended release build is:

make MATCHCOMPILER=yes FILESDIR=/usr/share/cppcheck HAVE_RULES=yes CXXFLAGS="-O2 -DNDEBUG -Wall -Wno-sign-compare -Wno-unused-function"

Flags:

  1. MATCHCOMPILER=yes Python is used to optimise cppcheck. The Token::Match patterns are converted into C++ code at compile time.

  2. FILESDIR=/usr/share/cppcheck Specify folder where cppcheck files are installed (addons, cfg, platform)

  3. HAVE_RULES=yes Enable rules (PCRE is required if this is used)

  4. CXXFLAGS="-O2 -DNDEBUG -Wall -Wno-sign-compare -Wno-unused-function" Enables most compiler optimizations, disables cppcheck-internal debugging code and enables basic compiler warnings.

g++ (for experts)

If you just want to build Cppcheck without dependencies then you can use this command:

g++ -o cppcheck -std=c++11 -Iexternals -Iexternals/simplecpp -Iexternals/tinyxml -Ilib cli/*.cpp lib/*.cpp externals/simplecpp/simplecpp.cpp externals/tinyxml/*.cpp

If you want to use --rule and --rule-file then dependencies are needed:

g++ -o cppcheck -std=c++11 -lpcre -DHAVE_RULES -Ilib -Iexternals -Iexternals/simplecpp -Iexternals/tinyxml cli/*.cpp lib/*.cpp externals/simplecpp/simplecpp.cpp externals/tinyxml/*.cpp

MinGW

mingw32-make LDFLAGS=-lshlwapi

Other Compiler/IDE

  1. Create an empty project file / makefile.
  2. Add all cpp files in the cppcheck cli and lib folders to the project file / makefile.
  3. Add all cpp files in the externals folders to the project file / makefile.
  4. Compile.

Cross compiling Win32 (CLI) version of Cppcheck in Linux

sudo apt-get install mingw32
make CXX=i586-mingw32msvc-g++ LDFLAGS="-lshlwapi" RDYNAMIC=""
mv cppcheck cppcheck.exe

Webpage

http://cppcheck.sourceforge.net/