Splint (programming tool)


Splint, short for Secure Programming Lint, is a programming tool for statically checking C programs for security vulnerabilities and coding mistakes. Formerly called LCLint, it is a modern version of the Unix lint tool.
Splint has the ability to interpret special annotations to the source code, which gives it stronger checking than is possible just by looking at the source alone. Splint is used by gpsd as part of an effort to design for zero defects.
Splint is free software released under the terms of the GNU General Public License.
Development activity on Splint stopped in 2010. According to the CVS at SourceForge, as of September 2012 the most recent change in the repository was in November 2010. As of June 2018, the git repository at GitHub concurs, showing no changes since November 2010.

Example


  1. include
int main

Splint's output:

Variable c used before definition
Suspected infinite loop. No value used in loop test is modified by test or loop body.
Assignment of int to char: c = getchar
Test expression for if is assignment expression: c = 'x'
Test expression for if not boolean, type char: c = 'x'
Fall through case

Fixed source:

  1. include
int main