tags:

views:

931

answers:

1

I am in the process of evaluating FindBugs and am trying to make use of the excludeFilter so that the tool does not process the test packages or the generated ejb stubs.

I have tried the following:

<FindBugsFilter>
<!-- Match any test packages -->
<Match>
    <Package name="~.*\.test"/>
</Match>
<Match>
    <Or>
     <Class name="~.*\.^_*"/>
     <Class name="~.*EJS*"/>
    </Or>
    <Bug pattern="MALICIOUS_CODE"/>
</Match>

The generated EJB's are still being looked at. Can someone provide some better direction on this.

I want to exclude out all classes that start with "_"

Example:

com/mycompany/business/admin/ejb/_AdminRemoteHome_Stub.java

com/mycompany/business/admin/ejb/_EJSRemoteStatelessAdminHome_054d51b9_Tie.java

Updated filter file.

I change the filter file to the following structure using the suggested regx changes and now things are working as expected:

<FindBugsFilter>
<!-- Match any test packages -->
<Match>
    <Package name="~.*\.test"/>
</Match>
<Match>
 <Class name="~.*\._.*"/>
</Match>
<Match>
 <Class name="~.*?EJS.*"/>     
</Match>

Looks like I need to go back and brush up on my regx.

+3  A: 

Regarding FindBugFilter,

(just to be sure) are you sure your are considering the compiled class files directoriesa, and not the sourcePath? (as mentioned in this SO answer)

If the name attribute of Class, Method or Field starts with the ~ character the rest of attribute content is interpreted as a Java regular expression that is matched against the names of the Java element in question.

Would the following regex be more accurate?

    <Class name="~.*\._.*"/>
    <Class name="~.*?EJS.*"/>
  • ".*\._.*" instead of ".*\.^_*" because the anchor is supposed to match at the start of the string the regex pattern is applied to.

  • ".*?EJS.*" instead of ".*EJS*" because the ? quantifier makes the matching lazy, avoiding to 'eat' EJS. (Plus "S*" means "0 or n S", which does not help here)

VonC
I just used your suggestion but the classes are still showing up in the report.
boyd4715
Here is what the report is generating:com/mycompany/business/admin/ejb/_AdminRemoteHome_Stub.java2Line 33 MALICIOUS_CODE May expose internal representation by returning reference to mutable object
boyd4715