Skip to content

Add more documentation - #1629

Merged
swissiety merged 16 commits into
developfrom
improve_documentation
Sep 29, 2026
Merged

swissiety merged 16 commits into
developfrom
improve_documentation

Conversation

@swissiety

Copy link
Copy Markdown
Collaborator

Adds analysis examples and how to start a shareable analysis tool.

@swissiety
swissiety force-pushed the improve_documentation branch from b50c5e7 to a333ad2 Compare June 17, 2026 15:40
@swissiety
swissiety force-pushed the improve_documentation branch from a333ad2 to 0d7c38c Compare June 17, 2026 15:42
SootUp ships JimpleIDESolver/DefaultJimpleIDETabulationProblem but had no IDE
test, example or docs; write_analyses.md pointed at examples that don't exist.

New docs/analysis-typestate.md walks through configuring Heros step by step:
zero fact, seeds, meet lattice, 4 flow functions, 4 edge functions, ICFG, solve.
Backed by sootup.examples/.../typestate, so snippets are compiled and CI-gated.

Ported from API_ASSIST IsolatedTypeStateAnalysis, simplified: dropped listener/
history-tree machinery; edge functions rewritten as a finite transfer table
instead of mutate-and-trigger composeWith, so composition is pure and equalTo
is decidable (terminates in loops).

Gotcha documented: seed zero fact carries lattice bottom, not top, so
generating edge functions must be constant.

Also: glossary entries for IFDS/IDE vocabulary, nav entry, gitignore negation
for sootup.examples test binaries.
*.class is gitignored repo-wide; sootup.examples had no negation, so these
were never committed. LiveVariableAnalysisTest and ConstantPropagationTest
load these dirs via PathBasedAnalysisInputLocation and fail on a fresh clone.
Address review of #1369:
- docs/taint-analysis-example.md no longer copies code; every Java block is
  included from TaintAnalysisTest.java via named `--8<--` sections, so the
  tutorial always shows compiled and tested code. check_paths fails the docs
  build if a section goes missing.
- Use pymdownx.snippets (already enabled, shipped with mkdocs-material)
  instead of the codeinclude plugin, which the docs CI does not install.
- Remove CodeBlockExtractor and the sync-examples workflow (out of scope).
- Update TaintAnalysisTest to the current SootUp API, propagate taint through
  call sites with a return value (b = id(a)) and assert the expected leak /
  no-leak verdict per scenario instead of swallowing all results.
- Split the tutorial into small sections, each with an explanation; fix the
  dependency snippet.
Moves the tutorial next to the other analysis examples under "How to.."
and keeps base_path/check_paths while adding dedent_subsections.
- Manage commons-cli in the parent pom again; develop dropped it together
  with the qilin CLI, but the tool setup example still uses it.
- SootUpConfiguration: identifier factories are no longer singletons and
  signature constructors are not public anymore. Build the entry point
  signature from the view's IdentifierFactory after the view is created and
  include that step in tool_setup.md.
- write_analyses.md: link the new taint analysis tutorial as the IFDS example.
- Reformat TypestateEdgeFunction with develop's formatter.
@github-actions

Copy link
Copy Markdown
Contributor

@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.59%. Comparing base (1001d5f) to head (c5015d0).

Additional details and impacted files
@@              Coverage Diff              @@
##             develop    #1629      +/-   ##
=============================================
- Coverage      72.64%   72.59%   -0.05%     
  Complexity       238      238              
=============================================
  Files            488      488              
  Lines          20820    20820              
  Branches        3400     3400              
=============================================
- Hits           15124    15115       -9     
- Misses          4385     4390       +5     
- Partials        1311     1315       +4     
Components Coverage Δ
core 66.51% <ø> (ø)
java.core 74.04% <ø> (ø)
java.bytecode.frontend 80.46% <ø> (ø)
jimple.frontend 70.70% <ø> (ø)
apk.frontend 76.99% <ø> (-0.37%) ⬇️
interceptors 73.56% <ø> (ø)
callgraph 85.42% <ø> (ø)
codepropertygraph 74.35% <ø> (ø)
analysis.intraprocedural 63.86% <ø> (ø)
analysis.interprocedural 68.26% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@swissiety
swissiety marked this pull request as ready for review September 24, 2026 14:38
@swissiety
swissiety enabled auto-merge September 24, 2026 14:40
@swissiety
swissiety added this pull request to the merge queue Sep 29, 2026
Merged via the queue into develop with commit ba55658 Sep 29, 2026
12 checks passed
@swissiety
swissiety deleted the improve_documentation branch September 29, 2026 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants