# Coverity analysis options that are passed to cov-analyze command line
analyze:
checkers:
all: true # Enables all checkers except a few which need to be explicitly enabled. See: https://documentation.blackduck.com/bundle/coverity-docs/page/commands/topics/cov-analyze.html#ariaid-title11
rule: true # Enables "rule" checkers. See: https://documentation.blackduck.com/bundle/coverity-docs/page/commands/topics/cov-analyze.html#refsection_dgq_pf2_4qb__list-checkers
checker-config:
# --- Disabled checkers ---
# These checkers generate overwhelming noise with near-zero confirmed-bug
# yield in MongoDB's codebase. Each has been evaluated against historical
# Coverity data before being disabled.
# Reports deeply recursive or large stack frames. MongoDB's recursive
# algorithms are intentional; this produced only false positives.
STACK_USE:
enabled: false
# Flags places where std::move could be used instead of copy. Performance
# hint only — not a correctness issue, and MongoDB's style already uses
# move semantics where it matters.
COPY_INSTEAD_OF_MOVE:
enabled: false
# Enforces the Rule of Zero/Three/Five. MongoDB's class hierarchy
# intentionally diverges from this rule in many places; confirmed-bug
# yield was near zero.
RULE_OF_ZERO_THREE_FIVE:
enabled: false
# Reports functions with control-flow paths that have no return statement.
# The C++ compiler already enforces this; Coverity produces false positives
# on noreturn functions it cannot resolve.
MISSING_RETURN:
enabled: false
# Flags calls to sleep() in production code. MongoDB uses sleep
# intentionally in retry loops and test infrastructure.
SLEEP:
enabled: false
# Recommends passing large objects by const reference instead of by value.
# Performance hint only — not a correctness issue.
PASS_BY_VALUE:
enabled: false
# Warns about non-trivial initialization order of global/static objects.
# MongoDB's initialization patterns are intentional and reviewed; this
# produced only noise.
GLOBAL_INIT_ORDER:
enabled: false
# Flags functions that may propagate exceptions into a noexcept context.
# MongoDB uses noexcept extensively and intentionally, but this checker is
# too noisy: Coverity conservatively assumes exception propagation through
# many idioms that are safe in practice, yielding near-zero confirmed bugs.
UNCAUGHT_EXCEPT:
enabled: false
# Reports classes with a copy constructor but no assignment operator (or
# vice versa). In C++20 this is almost always intentional. Historical data
# showed 9,129 occurrences with zero confirmed bugs.
COPY_WITHOUT_ASSIGN:
enabled: false
# Similar to COPY_WITHOUT_ASSIGN — classes missing one of the Rule of
# Three members. Historical data showed 3,384 occurrences, 138 classified
# as Intentional, and zero confirmed bugs.
MISSING_COPY_OR_ASSIGN:
enabled: false
# --- Explicitly enabled checkers ---
# Some checkers are off by default and must be turned on explicitly.
# Detects reads beyond the end of an array when the overrun direction is
# reversed (e.g. negative index). Not enabled by --all; enabled here
# because MongoDB has had confirmed bugs of this class.
REVERSE_OVERRUN:
enabled: true
# --- Checkers with customized options ---
# Fires when an assertion macro contains a side-effectful expression that
# is not evaluated in release builds (e.g. assert(++i > 0)). MongoDB's own
# always-evaluating assertion macros are excluded via macro_name_lacks:
# fassert, iassert, massert, tassert, uassert, and invariant always
# evaluate their arguments regardless of build type.
# Note: dassert is intentionally NOT excluded — it is a debug-only macro
# that expands to nothing in release builds, so side effects inside it
# are genuine bugs that this checker should report.
ASSERT_SIDE_EFFECT:
enabled: true
options:
macro_name_lacks: ^([fimtu]assert|invariant)
# Reports callers that ignore a return value that indicates success/failure.
# stat_threshold:80 requires 80% of call sites to check the return value
# before the checker fires, reducing noise on functions where ignoring the
# return is idiomatic.
CHECKED_RETURN:
enabled: true
options:
stat_threshold: "80"
# Finds unreachable or redundant code paths. no_dead_default suppresses
# findings on intentional default cases in switch statements.
# report_redundant_tests catches always-true/always-false conditions.
DEADCODE:
enabled: true
options:
no_dead_default: "true"
report_redundant_tests: "true"
# Reports functions that can return null but whose callers dereference the
# result without a null check. stat_threshold:50 requires at least 50% of
# callers to check for null before firing, balancing sensitivity with noise.
NULL_RETURNS:
enabled: true
options:
stat_threshold: "50"
# CodeXM custom checkers. This is the schema-native key for specifying .cxm
# files (preferred over the equivalent --codexm flag in cov-analyze-args).
# See etc/coverity_models/codexm/CODEXM_LESSONS_LEARNED.md for authoring guidance.
codexm:
# Detects network-supplied uncompressedSize passed to SharedBuffer::allocate
# without bounds validation (CVE-2025-14847 class).
# See etc/coverity_models/codexm/network_size_unchecked_alloc.cxm for details.
- etc/coverity_models/codexm/network_size_unchecked_alloc.cxm
# Runs an additional false-path pruner (FPP) pass after the main analysis.
# This eliminates findings that are only reachable via infeasible paths (e.g.
# contradictory conditions), at the cost of ~5-10% longer analysis time.
constraint-fpp: true
# Builds models for function-pointer call targets that the analysis cannot
# resolve statically. Improves precision for callbacks and vtable-heavy code.
c-cpp-fnptr: true
# Resolves virtual function calls to their concrete overrides. Without this,
# Coverity treats virtual calls conservatively and misses bugs in overrides.
c-cpp-virtual: true
# Emits per-function callgraph metrics into the idir. Used for transparency
# reporting; does not affect which defects are found.
callgraph-metrics: true
cov-analyze-args:
# Filters parse-phase warnings through a named config file, allowing
# specific RW.* and PW.* diagnostics to be suppressed without disabling
# the underlying checker. See etc/coverity_parse_warnings.conf for the list.
- --parse-warnings-config
- etc/coverity_parse_warnings.conf
# User model file teaching Coverity about MongoDB-specific assertion and
# initialization patterns. See etc/coverity_models/mongo_models.cpp for details.
# coverity_build.sh compiles mongo_models.cpp into xmldb format via cov-make-library
# and places it at <covIdir>/config/user_models.xmldb, which is the default location
# cov-analyze checks automatically (no --model-file flag required).
# Exclude Bazel cache paths that contain external dependencies (e.g. Abseil, gRPC) fetched
# to the CI agent's working directory. These are not MongoDB source and produce false positives.
- --tu-pattern
- "!file('/data/mci/*')"
# Exclude findings whose translation unit is the MongoDB toolchain (GCC STL,
# libstdc++, etc.). --tu-pattern suppresses *defect reports* in those TUs;
# it does NOT prevent Coverity from following them for type and template
# resolution. Template instantiations triggered by MongoDB source (e.g.
# std::make_unique<Foo>()) are still analysed — only native toolchain-header
# defects are filtered out.
- --tu-pattern
- "!file('/opt/mongodbtoolchain/*')"
commit:
connect:
# url is required by the schema but injected at runtime by the devprod_coverity
# module (evergreen/coverity_tasks.yml). This placeholder satisfies schema
# validation; it is overridden before cov-commit-defects runs.
url: https://placeholder.coverity.invalid
stream: mongo.master
project: "MongoDB master"