From 589dda809fb59a18c7f6b7a1353ee3e215335785 Mon Sep 17 00:00:00 2001 From: Niels Lohmann Date: Wed, 30 Sep 2026 18:17:37 +0200 Subject: [PATCH] Make Infer fail on findings, with a type-level baseline for the ~174 pre-existing ones (#5715 item 4b) ci_infer ran `infer run` without --fail-on-issue, so the job passed regardless of what Pulse found; the last recorded run (35829411620, commit 1054b2097) logged "Found 174 issues" and still went green. report.txt was also never uploaded, so the full finding list was only ever visible in the truncated 5-issue console excerpt. Add a repository-root .inferconfig (auto-discovered by Infer; passing --project-root on the `infer run` invocation makes sure it is found even though the analysis runs from build/build_infer) that sets fail-on-issue and disables the six PULSE issue types that made up all 174 findings in that run: PULSE_UNNECESSARY_COPY_ASSIGNMENT (129), PULSE_UNNECESSARY_COPY (22), PULSE_UNNECESSARY_COPY_INTERMEDIATE (15), PULSE_RESOURCE_LEAK (5), PULSE_CONST_REFABLE (2), and PULSE_UNNECESSARY_COPY_OPTIONAL (1). This is a deliberate, narrower fix than "triage and fix everything in this PR": the visible sample is entirely doctest-macro copies in test code (for example tests/src/unit-algorithms.cpp:141 and tests/src/unit-bjdata.cpp:3706), but 169 of the 174 findings were never uploaded anywhere and this PR cannot respectably claim to have fixed issues it never saw, including the resource-leak and const-refable ones that are the most likely to be genuine bugs. Disabling by issue type is a coarser baseline than a per-finding one (Infer has no built-in per-finding baseline short of the two-run `infer reportdiff` workflow, which this repository does not have the CI infrastructure for), but it has the same effect today: the job goes from always green to green-only-when-clean-of-everything-else, so CI now fails the moment a *new* issue type appears, and report.txt is uploaded as a workflow artifact on every run (including failures) so the six disabled types can be triaged and re-enabled incrementally in follow-up PRs. #5715 item 4b. 4a (scan-build) and 4c (IWYU) are handled in separate commits. Verified: .inferconfig parses as JSON, ubuntu.yml still parses as YAML. Infer itself is not available in this environment (v1.3.0 tar.xz requires a Linux x86_64 runner), so CI must confirm that `infer run --project-root ... -- make` picks up .inferconfig, that fail-on-issue takes effect, and that the six disabled types actually suppress the existing findings without also hiding an unrelated new one. Signed-off-by: Niels Lohmann --- .github/workflows/ubuntu.yml | 7 +++++++ .inferconfig | 12 ++++++++++++ cmake/ci.cmake | 4 +++- 3 files changed, 22 insertions(+), 1 deletion(-) create mode 100644 .inferconfig diff --git a/.github/workflows/ubuntu.yml b/.github/workflows/ubuntu.yml index 2d1e7f9bc..e7d05c4b9 100644 --- a/.github/workflows/ubuntu.yml +++ b/.github/workflows/ubuntu.yml @@ -52,6 +52,13 @@ jobs: run: cmake -S . -B build -DJSON_CI=On - name: Build run: cmake --build build --target ci_infer + - name: Archive Infer report + if: always() + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: infer-report + path: ${{ github.workspace }}/build/build_infer/infer-out/report.txt + if-no-files-found: ignore ci_static_analysis_ubuntu: runs-on: ubuntu-latest diff --git a/.inferconfig b/.inferconfig new file mode 100644 index 000000000..9a5a36873 --- /dev/null +++ b/.inferconfig @@ -0,0 +1,12 @@ +{ + "_comment": "Used by the ci_infer CMake target (#5715 item 4b). fail-on-issue makes CI fail on Infer findings; disable-issue-type is a type-level baseline for the ~174 pre-existing findings (all PULSE_UNNECESSARY_COPY*/PULSE_RESOURCE_LEAK/PULSE_CONST_REFABLE, mostly in test code) triaged in run https://github.com/nlohmann/json/actions/runs/35829411620 on commit 1054b2097, so CI fails only on a NEW issue type. Remove an entry here once its findings have been fixed or explicitly accepted.", + "fail-on-issue": true, + "disable-issue-type": [ + "PULSE_UNNECESSARY_COPY_ASSIGNMENT", + "PULSE_UNNECESSARY_COPY", + "PULSE_UNNECESSARY_COPY_INTERMEDIATE", + "PULSE_UNNECESSARY_COPY_OPTIONAL", + "PULSE_RESOURCE_LEAK", + "PULSE_CONST_REFABLE" + ] +} diff --git a/cmake/ci.cmake b/cmake/ci.cmake index 63771ac80..0cb9e5e32 100644 --- a/cmake/ci.cmake +++ b/cmake/ci.cmake @@ -490,10 +490,12 @@ add_custom_target(ci_clang_tidy # Check code with Infer static analyzer. ############################################################################### +# .inferconfig (repository root) pins --fail-on-issue and the currently-triaged issue types that +# are disabled until they are addressed separately; see #5715 item 4b. add_custom_target(ci_infer COMMAND mkdir -p ${PROJECT_BINARY_DIR}/build_infer COMMAND cd ${PROJECT_BINARY_DIR}/build_infer && ${INFER_TOOL} compile -- ${CMAKE_COMMAND} -DCMAKE_BUILD_TYPE=Debug ${PROJECT_SOURCE_DIR} -DJSON_BuildTests=ON - COMMAND cd ${PROJECT_BINARY_DIR}/build_infer && ${INFER_TOOL} run -- make + COMMAND cd ${PROJECT_BINARY_DIR}/build_infer && ${INFER_TOOL} run --project-root ${PROJECT_SOURCE_DIR} -- make COMMENT "Check code with Infer" )