ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise open source Toolkit

Open source coders' speed astounds Coverity

Joris Evers CNET News.com

Published: 05 Apr 2006 09:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Developers have quickly fixed many bugs in popular open source packages that were flagged as part of a US government-sponsored bug hunt.

More than 900 flaws were repaired in the two weeks after Coverity, which makes tools to analyse source code, announced the results of its first scan of 32 open source projects. As a result, some of the software is now entirely bug free, Coverity said in a statement on Monday.

"My impression is that the open source community is producing software defect patches at an extremely fast rate," Ben Chelf, the chief technology officer at Coverity, said in the statement.

The open source bug hunt is part of a three-year Open Source Hardening Project, dedicated to helping make such software as secure as possible. In January, the US Department of Homeland Security awarded $1.24m (£713,000) to Stanford University, Coverity and Symantec to find vulnerabilities in open source projects.

In its initial analysis on 6 March, Coverity scanned more than 17.5 million lines of code from 32 open source projects. On average, 0.434 bugs per 1,000 lines of code were found, the company said at the time.

More than 200 developers registered for access to the online defect database in the week after the first results were published. Since then, programmers for the Samba, Amanda and XMMS projects eliminated all the defects that the initial analysis detected, Coverity said on Monday.

Samba, a popular open source project used to connect Linux and Microsoft Windows networks, showed the fastest developer response, Coverity said. The number of flaws was reduced from 216 to 18 in one week and to zero in two weeks.

Amanda, a backup tool, was the worst performer in Coverity's first analysis. It had the highest number of bugs per 1,000 lines of code, with a bug density of 1.237. The Amanda developers fixed 108 defects in a couple of weeks, according to Coverity.

XMMS, an audio player, had the lowest bug density, with 0.051 defects per 1,000 lines of code. A total of six holes have now been fixed, Coverity said.

As part of the government-funded effort, Stanford and Coverity have built a system that does daily scans of the code contributed to popular open source projects. The resulting database of bugs is accessible to developers, so they can get the details they need to fix the flaws, Coverity said.

Open-source project

Defect count
(6 March)

Defect count
(20 March)

Amanda

108

0

XMMS

6

0

Samba

216

0

Ethereal

143

19

Icecast

12

2

SQLite

31

6

Gcc

140

97

Gaim

113

51

Net-SNMP

148

61

Source: Coverity

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
92 out of 207 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

C++ Architect - Equities - Investment Bank - London - 600

Responsibilities will include development of the next generation order management architecture and its integration into multiple business lines and ...

Leading Investment Bank seeks Senior C#/C++ developer to join team

This is a large systems which consists of 600.000 lines of code so someone looking for a real challenge would be ideal. You will be working in a team ...

C++ / Linux Developers Reading - Urgent 50-70k

You will join a small team in a prestigeous organisation where you will work on large scale applications with over 50,000+ lines of code. C++ / Linux ...

Featured Talkback

Its the applications and device drivers that run on windows that cement its dominance. How many people would fork out hundreds of pounds for Vista if Linux ran all the software and kit they wanted to use.

By: pround

Read full story:
Windows' dominance stifles demand for Linux

Discussions

dwr50 dwr50

MS WSBS

Thursday 24 July 2008, 5:46 PM

1 comment