On Sun, Dec 09, 2018 at 08:56:17AM +0800, PanBian wrote:
> Yes. I write a static analysis tool. It can find functions that release
> memory or other resources. Let's call them free-like functions. With such
> free-like functions, the tool then performs data flow analysis to find
> use-after-free bugs. Of course, we can feed those free-like functions to
> other static analyzers such as Coverity. I believe it will work too.
Interesting. Did you release this stuff in the open? I could be very
interesting to get that plugged in more easily with Postgres. Community
runs Coverity as well. The reports are not public still if that helps
in reporting real issues and not only false positives that would be
nice.
--
Michael