# Firmware Static Analysis with CodeChecker | Interrupt

**URL:** <https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410>\
**Category:** Blog\
**Created:** [May 19, 2021, 7:30am UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410 "2021-05-19T07:30:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![discobot](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.memfault.com/discobot/32/1_2.png) [@discobot](https://community.memfault.com/u/discobot)\
**Post date:** [May 19, 2021, 7:30am UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/1 "2021-05-19T07:30:59Z")

</div>

The pitfalls of C programming are well known: undefined behavior abounds, uninitialized variables lie in wait, memory leaks, and buffers overflow.

* * *
This is a companion discussion topic for the original entry at [https://interrupt.memfault.com/blog/static-analysis-with-codechecker](https://interrupt.memfault.com/blog/static-analysis-with-codechecker)

---

<div class="post-metadata">

**Author:** ![devprodest](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@devprodest](https://community.memfault.com/u/devprodest)\
**Post date:** [May 19, 2021, 8:21pm UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/2 "2021-05-19T20:21:31Z")

</div>

For personal projects use pvs-studio

> **[PVS-Studio is a solution to enhance code quality, security (SAST), and safety](https://pvs-studio.com/en/)**

What do you think about this?

---

<div class="post-metadata">

**Author:** ![discobot](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.memfault.com/discobot/32/1_2.png) [@discobot](https://community.memfault.com/u/discobot)\
**Post date:** [May 19, 2021, 8:21pm UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/3 "2021-05-19T20:21:32Z")

</div>



---

<div class="post-metadata">

**Author:** ![francois](https://avatars.discourse-cdn.com/v4/letter/f/77aa72/32.png) [@francois](https://community.memfault.com/u/francois)\
**Post date:** [May 19, 2021, 10:20pm UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/4 "2021-05-19T22:20:26Z")

</div>

PVS Studio has a lot going for it, but it does not do cross-translation-unit analysis at this time (though it is on their roadmap). Additionally, it is a commercial product which requires license management & payment to use on non personal / OSS projects.

---

<div class="post-metadata">

**Author:** ![hellgheast](https://avatars.discourse-cdn.com/v4/letter/h/7ea924/32.png) [@hellgheast](https://community.memfault.com/u/hellgheast)\
**Post date:** [August 30, 2021, 4:19pm UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/5 "2021-08-30T16:19:30Z")

</div>

Hi ! I’ve tried today the tutorial proposed by Interrupt and unfortunately it seems that the --ctu option and any interception done by CodeChecker has disappeared.  
Which leads CodeChecker to not process any file at all when ChibiOS is compiling.

**CodeChecker version in usage**  
6.17.0

Would you mind to check if the article is still applicable today ?  
Should I move back to a specific version of CodeChecker ?

Many thanks,  
hellgheast.

---

<div class="post-metadata">

**Author:** ![francois](https://avatars.discourse-cdn.com/v4/letter/f/77aa72/32.png) [@francois](https://community.memfault.com/u/francois)\
**Post date:** [August 30, 2021, 8:38pm UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/6 "2021-08-30T20:38:55Z")

</div>

Hey @hellgheast, I probably won’t be able to fire this up for a few days, but looking at their latest docs, the `--ctu` option should still be there. See [Quick Howto - CodeChecker](https://codechecker.readthedocs.io/en/latest/usage/).

Could you share the command you tried to run, and what the error message was?

---

<div class="post-metadata">

**Author:** ![hellgheast](https://avatars.discourse-cdn.com/v4/letter/h/7ea924/32.png) [@hellgheast](https://community.memfault.com/u/hellgheast)\
**Post date:** [September 1, 2021, 9:11am UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/7 "2021-09-01T09:11:30Z")

</div>

Hi @francois, Sure let me know whenever you have time.

I followed the steps of the article until the CC\_LOGGER\_GCC\_LIKE step with redefinition to arm-none-eabi-gcc.

CodeChecker log -b “make VERBOSE=1 -f make/stm32f769\_discovery.make” -o compilation.json --verbose debug

It outputed the compilation of the ChibiOS files

```auto
...
Compiling ffunicode.c
...
Compiling main.c

```

unfortunately the compilation.json is just empty, which means the intercept-build doesn’t seem to intercept compilation calls.

---

<div class="post-metadata">

**Author:** ![francois](https://avatars.discourse-cdn.com/v4/letter/f/77aa72/32.png) [@francois](https://community.memfault.com/u/francois)\
**Post date:** [September 1, 2021, 9:59pm UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/8 "2021-09-01T21:59:34Z")

</div>

This is likely due to a conflict with SIP on MacOS or another configuration issue. See “What to do if compilation.json is empty?” at [Quick Howto - CodeChecker](https://codechecker.readthedocs.io/en/latest/usage/#step-1-integrate-codechecker-into-your-build-system).

This is not an issue with `--ctu`.

---

<div class="post-metadata">

**Author:** ![hellgheast](https://avatars.discourse-cdn.com/v4/letter/h/7ea924/32.png) [@hellgheast](https://community.memfault.com/u/hellgheast)\
**Post date:** [September 2, 2021, 8:28am UTC](https://community.memfault.com/t/firmware-static-analysis-with-codechecker-interrupt/410/9 "2021-09-02T08:28:01Z")

</div>

Hello,  
I already disabled SIP.

What I discovered it seems, is that the CC\_LOGGER\_GCC\_LIKE redifition doesn’t seem to be taken in account when compiling ChibiOS. It might be a problem specific to the latest version of CodeChecker.

Please let me know whenever you tested with the latest build of CodeChecker if the --ctu option is still here. On my side when I tried to analyze using the --ctu option, it showed me an error as it’s an unknown option in the current version.

Let me know when you’ve done your tests and thanks for the help !
