Skip to content

About

Hybrid static analysis engine (AST + regex) with zero mandatory third-party dependencies. Runs standalone as a CLI, integrates as a LangChain tool into the Programozó Ágens project, and exposes a Flask REST API.

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

misra-checker

MISRA C:2012 / MISRA C++:2023 / MISRA Python:2024 compliance checker

Hybrid static analysis engine (AST + regex) with zero mandatory third-party dependencies. Runs standalone as a CLI, integrates as a LangChain tool into the Programozó Ágens project, and exposes a Flask REST API.

CI Python License: MIT


Features

MISRA C:2012 MISRA C++:2023 MISRA Python:2024
Rule count 30+ 25+ 30+
Analysis method Hybrid regex + token Hybrid regex + token AST (ast module) + regex
Severity levels mandatory / required / advisory ✓ ✓
Inline suppression // MISRA-suppress: RULE_ID reason ✓ # MISRA-suppress: RULE_ID reason
Output formats text / JSON / SARIF 2.1.0 ✓ ✓
LangChain tool ✓ ✓ ✓
Flask endpoint ✓ ✓ ✓
GitHub Code Scanning ✓ (SARIF upload) ✓ ✓

Quick start

# Install (core – no third-party deps required)
pip install .

# Check a C file
misra-checker main.c

# Check a Python file
misra-checker app.py

# Check an entire directory recursively
misra-checker src/ --recursive

# Force a standard
misra-checker lib.h --standard MISRA_C_2012

# Output as JSON
misra-checker main.py --output json

# Output SARIF (for GitHub Code Scanning)
misra-checker src/ --output sarif --out results.sarif

# Only show mandatory + required violations
misra-checker main.c --severity mandatory required

# Disable specific rules
misra-checker main.py --disable-rules PY2024-5.4 PY2024-8.3

# List all known rules
misra-checker --list-rules
misra-checker --list-rules --standard MISRA_PY_2024

Python API

from misra_checker import MISRAChecker, Standard, Severity

# Auto-detect standard from filename
checker = MISRAChecker()
report = checker.check_file("main.c")
print(report.summary())

# Force standard, filter severity
checker = MISRAChecker(
    standard=Standard.PY2024,
    severity_filter=["mandatory", "required"],
    disabled_rules=["PY2024-5.4"],
)
report = checker.check_string(source_code, filename="app.py")

# Structured access
for v in report.active_violations:
    print(f"[{v.severity.value}] {v.rule_id} @ line {v.line}: {v.message}")

print("Compliant:", report.is_compliant)
print(report.to_json())          # JSON string
print(report.to_sarif())         # SARIF dict

Inline suppression

Add a comment on the violating line to suppress a specific rule:

// C / C++
goto cleanup;  // MISRA-suppress: C2012-15.1 hardware driver requirement

// Python
from os import *  # MISRA-suppress: PY2024-1.1 legacy compatibility shim

Suppressed violations are still included in reports (flagged as suppressed: true) but do not affect is_compliant and do not trigger CI failure.


Integration with Programozó Ágens

Option A – LangChain tool (recommended)

pip install -e /path/to/misra-checker[agent]

In programozo_agent.py, inside build_agent():

try:
    from misra_checker.integration import make_langchain_tool
    tools.append(make_langchain_tool())
except ImportError:
    pass  # misra-checker not installed – skip silently

The agent can then be prompted:

python programozo_agent.py "Írd meg a main.c-t, majd ellenőrizd MISRA C:2012 szerint"
python programozo_agent.py "Generálj egy Python modult, ellenőrizd MISRA szabályoknak megfelelően"

Option B – Flask blueprint (REST API)

pip install -e /path/to/misra-checker[server]

In agent_server.py, inside create_app():

try:
    from misra_checker.integration import make_flask_blueprint
    app.register_blueprint(make_flask_blueprint(), url_prefix="/misra")
except ImportError:
    pass

New endpoints available:

POST /misra/check
Body: {"code": "...", "filename": "main.c", "standard": "MISRA_C_2012"}

POST /misra/check-file
Body: {"path": "output/main.py"}

GET  /misra/rules?standard=MISRA_PY_2024

Option C – Standalone function

from misra_checker.integration import check_code

result = check_code(source_code, filename="output/main.c")
print(result["summary"])
print(result["compliant"])

Supported rules (summary)

MISRA C:2012 (selected)

Rule ID Severity Title
C2012-15.1 advisory goto shall not be used
C2012-15.2 required goto shall jump forward only
C2012-15.6 required Bodies shall be compound statements (braces)
C2012-15.7 required if-else-if shall end with else
C2012-17.1 mandatory <stdarg.h> shall not be used
C2012-17.2 required No recursion
C2012-17.4 mandatory Non-void functions shall return a value
C2012-17.7 required Return values shall be used
C2012-14.1 required Loop counter shall not be floating-point
C2012-13.6 mandatory sizeof operand shall have no side effects
C2012-22.1 required Allocated memory shall be freed
C2012-20.4 mandatory Macros shall not redefine keywords

MISRA C++:2023 (selected)

Rule ID Severity Title
CPP2023-12.4.1 required Dynamic memory (new/delete) prohibited
CPP2023-15.0.2 required Catch exceptions by const reference
CPP2023-15.0.4 required Destructors shall not throw
CPP2023-10.0.1 required No recursion
CPP2023-10.6.1 mandatory <cstdarg> shall not be used
CPP2023-19.0.1 required errno shall not be used
CPP2023-9.5.1 advisory goto shall not be used
CPP2023-7.0.2 required auto shall not hide types

MISRA Python:2024 (selected)

Rule ID Severity Title
PY2024-1.1 required No wildcard imports
PY2024-3.1 required Use is None, not == None
PY2024-5.1 required All parameters and return types shall be annotated
PY2024-5.2 required No mutable default arguments
PY2024-5.3 required No recursion
PY2024-6.1 required No bare except:
PY2024-8.1 required eval() / exec() prohibited
PY2024-8.2 required global statement prohibited
PY2024-7.1 advisory Cyclomatic complexity ≤ 10
PY2024-7.2 advisory Nesting depth ≤ 4

Run misra-checker --list-rules for the full list.


Output formats

Text (default)

MISRA Compliance Report – MISRA_PY_2024
=======================================================
Files checked : 1
Violations    : 4 (mandatory=0, required=3, advisory=1)
Status        : NON-COMPLIANT ✗

Violations:
-------------------------------------------------------
[REQUIRED] PY2024-1.1 (Wildcard imports shall not be used) @ demo.py:1
  from os import *
...

JSON

{
  "standard": "MISRA_PY_2024",
  "compliant": false,
  "counts": { "mandatory": 0, "required": 3, "advisory": 1, "total": 4 },
  "violations": [
    {
      "rule_id": "PY2024-1.1",
      "severity": "required",
      "file": "demo.py",
      "line": 1,
      "message": "Wildcard import 'from X import *' is prohibited"
    }
  ]
}

SARIF 2.1.0

Compatible with GitHub Code Scanning, VS Code SARIF Viewer, Azure DevOps.


GitHub Actions integration

Add .github/workflows/ci.yml (already included):

  • Runs tests on Python 3.10 / 3.11 / 3.12
  • Lint with ruff + mypy
  • Generates SARIF report and uploads to GitHub Code Scanning
  • Uploads JSON report as a CI artifact

Project structure

misra-checker/
├── misra_checker/
│   ├── __init__.py          # Public API
│   ├── checker.py           # MISRAChecker orchestrator
│   ├── models.py            # Standard, Severity, Violation, CheckReport
│   ├── cli.py               # CLI entry point (misra-checker command)
│   ├── integration.py       # LangChain tool + Flask blueprint
│   ├── rules/
│   │   ├── __init__.py
│   │   └── registry.py      # All rule metadata (C + C++ + Python)
│   └── languages/
│       ├── __init__.py
│       ├── base.py          # BaseAnalyser
│       ├── c_analyser.py    # MISRA C:2012 – regex + token
│       ├── cpp_analyser.py  # MISRA C++:2023 – regex + token
│       └── python_analyser.py  # MISRA Python:2024 – AST + regex
├── tests/
│   ├── conftest.py
│   └── test_misra.py        # 40+ test cases
├── examples/
│   ├── bad_c_example.c
│   ├── bad_cpp_example.cpp
│   ├── bad_python_example.py
│   └── agent_integration_example.py
├── docs/
├── .github/workflows/ci.yml
├── setup.py
├── pytest.ini
└── README.md

Development

# Clone and set up
git clone https://github.com/YOUR_ORG/misra-checker.git
cd misra-checker
python -m venv venv
source venv/bin/activate   # Windows: venv\Scripts\activate
pip install -e ".[dev]"

# Run tests
pytest tests/ -v

# Run tests with coverage
pytest tests/ --cov=misra_checker --cov-report=term-missing

# Lint
ruff check misra_checker/
mypy misra_checker/ --ignore-missing-imports

Limitations

  • C/C++ analysis uses hybrid regex + token scanning. A full AST requires a C parser (e.g. libclang). Rules that need deep type information (e.g. exact type of every expression) are approximated.
  • Python analysis uses ast for accurate structural checks; regex is only used for simple line-pattern rules.
  • No cross-file (TU-level) analysis – each file is checked independently.

A future [clang] extra will add libclang-based C/C++ analysis for higher precision.


License

MIT – see LICENSE.

About

Hybrid static analysis engine (AST + regex) with zero mandatory third-party dependencies. Runs standalone as a CLI, integrates as a LangChain tool into the Programozó Ágens project, and exposes a Flask REST API.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages