A Comprehensive Approach to Finding Resource Leaks via Static Analysis

Nikita Malyshev, Alexey Evgenevich Borodin, Andrey Andreevich Belevantsev · 2024

In the last 15 years many dedicated leak detection tools utilizing novel approaches were designed. Unfortunately, most of them are hard to implement and fully utilize in the scope of a multi-purpose industrial analyzer. In this paper we present a full-fledged approach to static analysis through the lens of resource leak detection. We show how general analysis architecture without much of a focus for specific defects can still be effective at finding leaks both in terms of performance and number of warnings. We briefly describe an overall structure of the Svace static analyzer and how it achieves context and path sensitivities as well as interprocedurality, while allowing for checking many program properties and being highly extensible. We also show how to use this system to implement leak detection algorithm with including a few unique extensions that we have never seen in other instruments. Our test results show a low false positive rate, relatively good performance for a multi-detector static analyzer and great scalability potential both in terms of adding new algorithms and analyzing millions of lines of code.

Read the paper · More papers on PaperTik