diff --git a/.github/workflows/ubuntu.yml b/.github/workflows/ubuntu.yml index 2d1e7f9bc..e7d05c4b9 100644 --- a/.github/workflows/ubuntu.yml +++ b/.github/workflows/ubuntu.yml @@ -52,6 +52,13 @@ jobs: run: cmake -S . -B build -DJSON_CI=On - name: Build run: cmake --build build --target ci_infer + - name: Archive Infer report + if: always() + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: infer-report + path: ${{ github.workspace }}/build/build_infer/infer-out/report.txt + if-no-files-found: ignore ci_static_analysis_ubuntu: runs-on: ubuntu-latest diff --git a/.inferconfig b/.inferconfig new file mode 100644 index 000000000..9a5a36873 --- /dev/null +++ b/.inferconfig @@ -0,0 +1,12 @@ +{ + "_comment": "Used by the ci_infer CMake target (#5715 item 4b). fail-on-issue makes CI fail on Infer findings; disable-issue-type is a type-level baseline for the ~174 pre-existing findings (all PULSE_UNNECESSARY_COPY*/PULSE_RESOURCE_LEAK/PULSE_CONST_REFABLE, mostly in test code) triaged in run https://github.com/nlohmann/json/actions/runs/35829411620 on commit 1054b2097, so CI fails only on a NEW issue type. Remove an entry here once its findings have been fixed or explicitly accepted.", + "fail-on-issue": true, + "disable-issue-type": [ + "PULSE_UNNECESSARY_COPY_ASSIGNMENT", + "PULSE_UNNECESSARY_COPY", + "PULSE_UNNECESSARY_COPY_INTERMEDIATE", + "PULSE_UNNECESSARY_COPY_OPTIONAL", + "PULSE_RESOURCE_LEAK", + "PULSE_CONST_REFABLE" + ] +} diff --git a/cmake/ci.cmake b/cmake/ci.cmake index 63771ac80..0cb9e5e32 100644 --- a/cmake/ci.cmake +++ b/cmake/ci.cmake @@ -490,10 +490,12 @@ add_custom_target(ci_clang_tidy # Check code with Infer static analyzer. ############################################################################### +# .inferconfig (repository root) pins --fail-on-issue and the currently-triaged issue types that +# are disabled until they are addressed separately; see #5715 item 4b. add_custom_target(ci_infer COMMAND mkdir -p ${PROJECT_BINARY_DIR}/build_infer COMMAND cd ${PROJECT_BINARY_DIR}/build_infer && ${INFER_TOOL} compile -- ${CMAKE_COMMAND} -DCMAKE_BUILD_TYPE=Debug ${PROJECT_SOURCE_DIR} -DJSON_BuildTests=ON - COMMAND cd ${PROJECT_BINARY_DIR}/build_infer && ${INFER_TOOL} run -- make + COMMAND cd ${PROJECT_BINARY_DIR}/build_infer && ${INFER_TOOL} run --project-root ${PROJECT_SOURCE_DIR} -- make COMMENT "Check code with Infer" )