Re: nginx 1.20.0 coverity errors

2023-12-07 Thread Maxim Konovalov
FWIW, you can find daily nginx Coverity scan results (and even be subscribed to updates) here https://scan.coverity.com/projects/nginx Thanks to Synopsys and Coverity team for the great service. Maxim On 07.12.2023 06:57, Richard Stanway via nginx wrote: This is like reading a book, not under

Re: nginx 1.20.0 coverity errors

2023-12-07 Thread Richard Stanway via nginx
This is like reading a book, not understanding some words and then complaining to the author to fix their spelling. Please don't rely on SAST analysis without understanding the code. I would expect the vast majority of these are false positives - provide evidence that these are real bugs if you wan

Re: nginx 1.20.0 coverity errors

2023-12-06 Thread Xavier Beaudouin via nginx
Hello Bill, > We have a coverity testing on nginx 1.20.0 and we got some errors. > Have any plan to resolve these errors? Maybe you should try same thing on 1.24.0 ? Because AFAIK 1.20.0 has been released on 20 Apr 2021 and there is more than 2 years of development in between. So you tested o

nginx 1.20.0 coverity errors

2023-12-06 Thread BILL
Hi, We have a coverity testing on nginx 1.20.0 and we got some errors. Have any plan to resolve these errors? Checker Number ARRAY_VS_SINGLETON 3 BAD_FREE 3 BUFFER_SIZE 1 CHECKED_RETURN 10 COPY_PASTE_ERROR 1 DC.WEAK_CRYPTO 18 DEADCODE 8 FORWARD_NULL 49 MISSING_RESTORE 1 NO_EFFECT 8 NULL_RETURNS