Newly introduced findings

List of Findings

Error: GCC_ANALYZER_WARNING (CWE-476): [#def1]
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2670:25: warning[-Wanalyzer-null-dereference]: dereference of NULL ‘error_all’
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2632:1: enter_function: entry to ‘fu_firmware_new_from_gtypes’
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2640:27: release_memory: ‘error_all’ is NULL
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2642:9: branch_false: following ‘false’ branch (when ‘stream’ is non-NULL)...
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2642:9: branch_false: ...to here
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2656:12: branch_false: following ‘false’ branch...
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2656:12: branch_false: ...to here
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2665:27: branch_true: following ‘true’ branch...
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2666:31: branch_true: ...to here
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2668:35: release_memory: ‘error_all’ is NULL
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2669:22: call_function: calling ‘fu_firmware_parse_stream’ from ‘fu_firmware_new_from_gtypes’
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2669:22: return_function: returning to ‘fu_firmware_new_from_gtypes’ from ‘fu_firmware_parse_stream’
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2669:20: branch_true: following ‘true’ branch...
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2670:25: branch_true: ...to here
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2670:25: release_memory: ‘error_all’ is NULL
fwupd-2.0.19/libfwupdplugin/fu-firmware.c:2670:25: danger: dereference of NULL ‘error_local’
# 2668|   		g_autoptr(GError) error_local = NULL;
# 2669|   		if (!fu_firmware_parse_stream(firmware, stream, offset, flags, &error_local)) {
# 2670|-> 			g_debug("@0x%x %s", (guint)offset, error_local->message);
# 2671|   			if (error_all == NULL) {
# 2672|   				g_propagate_error(&error_all, g_steal_pointer(&error_local));

Scan Properties

analyzer-version-clippy1.92.0
analyzer-version-cppcheck2.19.1
analyzer-version-gcc16.0.0
analyzer-version-gcc-analyzer16.0.0
analyzer-version-shellcheck0.11.0
analyzer-version-unicontrol0.0.2
diffbase-analyzer-version-clippy1.92.0
diffbase-analyzer-version-cppcheck2.19.1
diffbase-analyzer-version-gcc16.0.0
diffbase-analyzer-version-gcc-analyzer16.0.0
diffbase-analyzer-version-shellcheck0.11.0
diffbase-analyzer-version-unicontrol0.0.2
diffbase-enabled-pluginsclippy, cppcheck, gcc, shellcheck, unicontrol
diffbase-exit-code0
diffbase-hostip-172-16-1-61.us-west-2.compute.internal
diffbase-known-false-positives/usr/share/csmock/known-false-positives.js
diffbase-known-false-positives-rpmknown-false-positives-0.0.0.20250521.132812.g8eff701.main-1.el9.noarch
diffbase-mock-configfedora-rawhide-x86_64
diffbase-project-namefwupd-2.0.16-1.fc43
diffbase-store-results-to/tmp/tmp5ycvrph7/fwupd-2.0.16-1.fc43.tar.xz
diffbase-time-created2026-01-08 16:11:31
diffbase-time-finished2026-01-08 16:23:19
diffbase-toolcsmock
diffbase-tool-args'/usr/bin/csmock' '-r' 'fedora-rawhide-x86_64' '-t' 'gcc,cppcheck,clippy,shellcheck,unicontrol' '-o' '/tmp/tmp5ycvrph7/fwupd-2.0.16-1.fc43.tar.xz' '--gcc-analyze' '--unicontrol-notests' '--unicontrol-bidi-only' '--install' 'pam' '--gcc-analyzer-bin=/usr/bin/gcc' '/tmp/tmp5ycvrph7/fwupd-2.0.16-1.fc43.src.rpm'
diffbase-tool-versioncsmock-3.8.3.20251215.161544.g62de9a5-1.el9
enabled-pluginsclippy, cppcheck, gcc, shellcheck, unicontrol
exit-code0
hostip-172-16-1-61.us-west-2.compute.internal
known-false-positives/usr/share/csmock/known-false-positives.js
known-false-positives-rpmknown-false-positives-0.0.0.20250521.132812.g8eff701.main-1.el9.noarch
mock-configfedora-rawhide-x86_64
project-namefwupd-2.0.19-1.fc44
store-results-to/tmp/tmpj0zpgpgt/fwupd-2.0.19-1.fc44.tar.xz
time-created2026-01-08 16:23:51
time-finished2026-01-08 16:35:51
titleNewly introduced findings
toolcsmock
tool-args'/usr/bin/csmock' '-r' 'fedora-rawhide-x86_64' '-t' 'gcc,cppcheck,clippy,shellcheck,unicontrol' '-o' '/tmp/tmpj0zpgpgt/fwupd-2.0.19-1.fc44.tar.xz' '--gcc-analyze' '--unicontrol-notests' '--unicontrol-bidi-only' '--install' 'pam' '--gcc-analyzer-bin=/usr/bin/gcc' '/tmp/tmpj0zpgpgt/fwupd-2.0.19-1.fc44.src.rpm'
tool-versioncsmock-3.8.3.20251215.161544.g62de9a5-1.el9