You are here: silicon.com > Software > Security Strategy

Security Strategy

Open source bug hunters make short work of clean-up

Samba boys make glitches extinct

Tags: amanda, coverity, samba

By Joris Evers

Published: 5 April 2006 08:55 GMT

Developers have quickly fixed many bugs in popular open source packages that were flagged as part of a US government-sponsored bug hunt.

More than 900 flaws were repaired in the two weeks after Coverity, which makes tools to analyse source code, announced the results of its first scan of 32 open source projects. As a result, some of the software is now entirely bug free, Coverity said in a statement.

Ben Chelf, the chief technology officer at Coverity, said in the statement: "My impression is that the open source community is producing software defect patches at an extremely fast rate."

The open source bug hunt is part of a three-year 'Open Source Hardening Project', dedicated to helping make such software as secure as possible. In January, the US Department of Homeland Security awarded $1.24m to Stanford University, Coverity and Symantec to find vulnerabilities in open-source projects.

In its initial analysis on 6 March, Coverity scanned more than 17.5 million lines of code from 32 open-source projects. On average, 0.434 bugs per 1,000 lines of code were found, the company said at the time.

More than 200 developers registered for access to the online defect database in the week after the first results were published. Since then, programmers for the Samba, Amanda and XMMS projects eliminated all the defects that the initial analysis detected, Coverity said Monday.

Samba, a popular open source project used to connect Linux and Microsoft Windows networks, showed the fastest developer response, Coverity said. The number of flaws was reduced from 216 to 18 in one week and to zero in two weeks.

Amanda, a backup tool, was the worst performer in Coverity's first analysis. It had the highest number of bugs per 1,000 lines of code, with a bug density of 1.237. The Amanda developers fixed 108 defects in a couple of weeks, according to Coverity.

XMMS, an audio player, had the lowest bug density, with 0.051 defects per 1,000 lines of code. A total of six holes have now been fixed, Coverity said.

As part of the government-funded effort, Stanford and Coverity have built a system that does daily scans of the code contributed to popular open-source projects. The resulting database of bugs is accessible to developers, so they can get the details they need to fix the flaws, Coverity said.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Developer - West Sussex - upto 45k + Excellent benefits

Fixing bugs Experienced Developer - West Sussex - upto 40k + Excellent benefits Are you a passionate and experienced Software developer? Do you have ...

Proposal Manager

This high-visibility position calls for a high-energy communications professional with excellent writing, project management, strategic thinking and ...

Java Developer

You will be responsible for bug and patch fixing of core products as well as development of new products. (Java, J2SE, Developer, Open Source, Perl, ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: