Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is Coverity being run against systemd? Would it not have found these issues?


Usefulness of static code analysis beyond linting is greatly overstated (by people selling static code analysis tools).


Coverity isn't useless. It finds these kinds of buffer overflow errors easily. It's shameful that a prominent keystone FOSS project is using such outdated coding practices in the first place. Not using the free tooling available for such projects is doubly so.


Systemd uses Simmle LGTM and QL for static code analysis which is a good thing since Coverty Scan is currently down without an ETA for restoration.


the flaws have existed for years.


As proven by a large majority of C developers ignoring lint since 1979.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: