Re: checking source with pvs-studio

2018-10-03 Thread Todd C. Miller
On Wed, 03 Oct 2018 18:07:00 +0100, Tom Smyth wrote: > I was thinking ... it might be possible to examine > a copy of the code out of band on a different OS system ... > and deal with the bugs that are flagged > as part of the normal OpenBSD development process, It is possible to generate pre-pro

Re: checking source with pvs-studio

2018-10-03 Thread Tom Smyth
Hi Todd, I was thinking ... it might be possible to examine a copy of the code out of band on a different OS system ... and deal with the bugs that are flagged as part of the normal OpenBSD development process, if the license is not permissible then I suppose my suggestion was entirely academic :

Re: checking source with pvs-studio

2018-10-03 Thread Todd C. Miller
On Wed, 03 Oct 2018 17:42:16 +0100, Tom Smyth wrote: > ... is it just 750 for a License ? > If one were to donate a License ? would that work for the project ? No, it would not. Their licensing model simply won't work for us. Even if it did, it's not like we could run it natively on OpenBSD.

Re: checking source with pvs-studio

2018-10-03 Thread Tom Smyth
... is it just 750 for a License ? If one were to donate a License ? would that work for the project ? Thanks Tom Smyth On Wed, 3 Oct 2018 at 17:33, Todd C. Miller wrote: > > On Wed, 03 Oct 2018 10:20:45 +0200, Ingo Schwarze wrote: > > > Which is of course trivial to do - you write a script to d

Re: checking source with pvs-studio

2018-10-03 Thread Todd C. Miller
On Wed, 03 Oct 2018 10:20:45 +0200, Ingo Schwarze wrote: > Which is of course trivial to do - you write a script to do a > checkout, run "sed -i", run the tool, collect the the results, > and delete the checkout. So the harassment by the author is not > even effective for his intended purpose. T

Re: checking source with pvs-studio

2018-10-03 Thread Ingo Schwarze
Hi, Aaron Mason wrote on Wed, Oct 03, 2018 at 09:07:40AM +1000: > Apparently you've got to go through your source code > and plug the product in every single non-header file. Which is of course trivial to do - you write a script to do a checkout, run "sed -i", run the tool, collect the the resul

Re: checking source with pvs-studio

2018-10-02 Thread Aaron Mason
On Sun, Sep 30, 2018 at 3:42 AM Theo de Raadt wrote: > > Sergey Bronnikov wrote: > > > Hello! > > > > openbsd source code was checked by various static analyzers (coverity, > > cppcheck, clang analyzer etc). Have someone tried PVS-Studio? > > It became free to use for opensource projects [1]. > >

Re: checking source with pvs-studio

2018-09-29 Thread Theo de Raadt
Sergey Bronnikov wrote: > Hello! > > openbsd source code was checked by various static analyzers (coverity, > cppcheck, clang analyzer etc). Have someone tried PVS-Studio? > It became free to use for opensource projects [1]. > > [1] https://www.viva64.com/en/b/0457/ which means you can roll up