-
Notifications
You must be signed in to change notification settings - Fork 1
Add static analysis CI: -Wall, ASAN, UBSAN, and Valgrind #362
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
Copilot
wants to merge
10
commits into
main
Choose a base branch
from
copilot/improve-ci-procedures
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…is CI workflow Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
…redundant EXTRA_CFLAGS Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
… export VALGRIND_OPTS Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Enhance CI procedures with stricter compile checks
Add static analysis CI: -Wall, ASAN, UBSAN, and Valgrind
Dec 22, 2025
Member
|
@copilot CI did not pass because of CMake errors |
…ject() Co-authored-by: AarC10 <30483634+AarC10@users.noreply.github.com>
Contributor
Author
Fixed in commit 9c280b7. The issue was that |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Implements stricter code quality enforcement as requested: compiler warnings, runtime sanitizers, and memory checking in CI.
New CI workflow (
.github/workflows/static-analysis.yml):compiler-warnings- builds with-Wallasan-build- Address Sanitizer (memory errors, leaks, use-after-free)ubsan-build- Undefined Behavior Sanitizer (integer overflows, null derefs, invalid casts)valgrind-test- Valgrind with Zephyr-specific suppressionsAll jobs run on
native_sim, triggered on push/PR/weekly.Global enforcement:
-Wallenabled for all builds directly in rootCMakeLists.txtafterproject()declaration.Reusable snippets for local development:
Created
snippets/{asan,ubsan,compiler-warnings}with corresponding helper functions incmake/Snippets.cmake.Documentation in
.github/STATIC_ANALYSIS.md. Valgrind suppressions in.github/valgrind-zephyr.supp.CMake fix: Resolved CI build errors by placing
zephyr_compile_options(-Wall)directly in rootCMakeLists.txtwhere Zephyr functions are available, rather than in a separate include file.Type of change
How Has This Been Tested?
CI workflow validated through code review and CodeQL security analysis (0 alerts). Individual snippets follow patterns from existing samples using ASAN/UBSAN. CMake fix verified to resolve build errors in CI.
Test Configuration:
native_sim(Linux only)Checklist:
Original prompt
💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.