static-analysis: make cppcheck analyse every source file - #497
Open
yosuke-wolfssl wants to merge 1 commit into
Open
yosuke-wolfssl wants to merge 1 commit into
yosuke-wolfssl wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
cppcheck execution failures are still suppressed, allowing false-successful analysis runs.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Improves cppcheck coverage and reliability across all provider source files.
Changes:
- Adds cppcheck compatibility definitions and parallel analysis.
- Fails when files have no valid configuration.
- Documents the updated failure behavior.
| File | Description |
|---|---|
.github/workflows/static-analysis.yml |
Expands cppcheck coverage and detects skipped files. |
.github/workflows/README.md |
Documents cppcheck failure conditions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- cppcheck defines the unix64 integer limits, undefines __has_include, and excludes the OpenSSL and wolfSSL include directories from configuration checking. - cppcheck runs with -j and --cppcheck-build-dir in a fresh cppcheck-build directory. - noValidConfiguration is no longer suppressed or filtered from the displayed output; the step fails and lists any file cppcheck could not analyse. - cppcheck's exit status is saved to cppcheck-rc.txt, and the step fails when it is non-zero. - The workflows README lists both failure conditions, and adds a troubleshooting row for a file cppcheck cannot analyse.
yosuke-wolfssl
force-pushed
the
fix/ci-cppcheck
branch
from
October 2, 2026 07:56
4814160 to
d1949eb
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #497
No scan targets match the changed files in this PR. Review skipped.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Problem
The
cppcheckstatic-analysis job analysed only 2 of 51src/*.cfiles, and was cancelled at its 30-minute timeout in 8 of the last 27 nightlies.<limits.h>, soUCHAR_MAXis undefined andwolfssl/wolfcrypt/sp_int.hhits#error "Size of unsigned char not detected".#error, so cppcheck reportsnoValidConfiguration("This file is not analyzed"). The job suppressed that message.alg_funcs.hwas skipped. The 25–42 s per file went into building configurations that all fail, which is why the job sat at the timeout while reporting 0 findings.Fix (
.github/workflows/static-analysis.yml)-D*_MAXgives the unix64 integer limits thatsp_int.hneeds. No wolfProvider#ifor code uses these macros.-U__has_includedrops the one configuration cppcheck 2.10 cannot evaluate. The fallback branch defines the sameWP_*_HEADERmacros.--config-excludeon the OpenSSL and wolfSSL include dirs stops library#ifdefs from multiplying configurations.--forcestill checks all of wolfProvider's own.-j "$(nproc)"runs the files in parallel.noValidConfigurationis no longer suppressed. The step fails and lists any file cppcheck could not analyse.Verification
Run locally in
debian:bookwormwith cppcheck 2.10 and the same OpenSSL/wolfSSL as CI:wp_rsa_kmgmt.c-j 4src/findings-Dlines makes the step fail and list the 49 files.Not in this PR: upgrading cppcheck in the test-deps image, after which the
-D/-Uworkaround can go, and awp_dec_pem2der.cfailure-path issue the now-working check reports.