correlating static analysis results with known crashes

David Malcolm dmalcolm at redhat.com
Tue Oct 29 15:10:32 UTC 2013


On Tue, 2013-10-29 at 16:05 +0100, Martin Milata wrote:
> On Tue, Oct 22, 2013 at 11:27:45 -0400, Paul Tagliamonte wrote:
> > Thrilling stuff, nice work!
> > 
> > I'll soon have a corpus of checks being run against Debian packages,
> > I'll be sure to forward you data points (if y'all have the same
> > source/version pair in Fedoraland)
> 
> Thanks! It would be interesting to run the analysis on those, though the
> possible differences between Debian and Fedora sources could pose a
> problem. E.g. a patch in one package and not the other might cause the
> line numbers to disagree. I have no idea how often this is the case.

That in itself might be something we could track using firehose,
perhaps?   i.e. have an <info> element that says that the code is
patched downstream by a particular distribution.  Then the UI can render
those elements (though which version of the source would you render in
such a situation), and one can run a query showing patches across
multiple distros and packages.

(Not sure if this is a good idea, but I thought I'd share it)

Dave



More information about the firehose-devel mailing list