Skip to content

ci(cppcheck): analyse one pinned configuration instead of up to twelve - #654

Merged
singaraiona merged 1 commit into
devfrom
ci/cppcheck-one-config
Sep 30, 2026
Merged

singaraiona merged 1 commit into
devfrom
ci/cppcheck-one-config

Conversation

@singaraiona

Copy link
Copy Markdown
Collaborator

The CI half of #649, redone as its own change as asked in that review, and fixed at the root rather than by narrowing what gets checked.

Problem

The advisory static-analysis job has taken 40–50 minutes on nearly every run for the last two days. The cause is cppcheck's configuration enumeration. Given no -D, it analyses each file once per combination of the #ifdef branches it finds (platform, DEBUG, endianness, fuzzing), up to 12. Most files hit that cap: Too many #ifdef configurations - cppcheck only checks 12 configurations.

Fix

  • CPPCHECK_DEFS (Makefile) pins the one configuration CI compiles: gcc, x86-64, Linux, debug. Each file is analysed once.
  • timeout-minutes: 30 on the job, so a regression in analysis time can't hold a runner for hours.

Measured with cppcheck 2.13.0, the version the runner installs:

before after
src/lang/format.c 449 s 57 s
src/lang/eval.c 568 s 78 s
src/ops/pivot.c 325 s 42 s
whole tree, -j 4 ~50 min on the runner 632 s locally, exit 0

Findings are unchanged: the single-file cross-TU warning in eval.c still reports with the pin.

Compared with #649's version

This keeps what makes the job worth running:

  • the whole tree: no changed-files-only pass, and group.c, query.c and agg_engine.c are no longer skipped;
  • --error-exitcode=1: a finding still fails the job, which stays advisory via continue-on-error.

What the pin gives up is analysing the Windows/macOS/WASM #ifdef branches. Those were only ever sampled within the 12-configuration cap anyway.

The advisory static-analysis job has taken 40-50 minutes on nearly every
run.  The cause is cppcheck's configuration enumeration: given no -D, it
analyses each file once per combination of the #ifdef branches it finds
(platform, DEBUG, endianness, fuzzing), up to 12, and most files hit that
cap ("Too many #ifdef configurations").

CPPCHECK_DEFS pins the gcc / x86-64 / Linux debug configuration CI
compiles.  Measured with cppcheck 2.13.0 (the version the runner installs):
format.c 449 s -> 57 s, eval.c 568 s -> 78 s, pivot.c 325 s -> 42 s, and
the whole tree at -j 4 in 632 s, exit 0.  Findings are unchanged: the
single-file cross-TU warning in eval.c still reports with the pin.

Unlike the CI half of #649, this keeps what made the job worth running:
the whole tree (no changed-files-only pass, no skipped translation units)
and --error-exitcode=1, so a finding still fails the advisory job.  What
the pin gives up is analysis of the Windows/macOS/WASM #ifdef branches,
which were only ever sampled within the 12-configuration cap anyway.

The job also gets a 30-minute timeout so a regression in analysis time
cannot hold a runner for hours.
@singaraiona
singaraiona merged commit bd31dbd into dev Sep 30, 2026
10 checks passed
@singaraiona
singaraiona deleted the ci/cppcheck-one-config branch September 30, 2026 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant