In this live talk, PVS-Studio's Developer Advocate walks through Go's built-in tools and code-parsing capabilities, explains the basics of static analysis, unpacks what a semantic model is, shows how to build a syntax tree, and much more.
Why build a custom analyzer?
Go already includes static analysis via go vet, but it can't detect every issue. Real-world projects contain errors that may look obvious to a developer yet remain invisible to standard tools. Other tools can also produce false positives or miss errors. A custom analyzer lets you focus on problems specific to your code and control exactly what the tool checks. The trade-off is that it needs to be maintained and tested. The diagnostic rules also need to be refined to minimize false positives and negatives.
Syntax and semantics
Static analysis relies on two main sources of information: syntax and semantics. The syntax tree shows the code structure and can reveal issues based on this structure. However, some cases require understanding what expressions and identifiers mean. Go/types provide this semantic information, including expression types and the declarations they refer to.
Building an analyzer
The Go analysis framework handles routine work such as collecting files, parsing them, and checking types. The analysis pass provides parsed files, type information, the current package, diagnostic rules, and source positions. A rule can then traverse the syntax tree, inspect relevant nodes, and report issues to the user.
From rule to diagnostic
The speaker demonstrates this process with a rule that detects empty if statements and then applies the same approach to a more complex value-receiver case. The result is a custom diagnostic rule tailored to a specific problem that existing tools may miss.
Want more?
If you want to watch the full talk, follow this link.
And if you'd like to learn more about PVS-Studio analyzer, check out our website.
See ya!
Top comments (0)