使用Fortify 20.2命令行工具分析.NET 5应用时加载构建会话失败的问题排查
Let's break down the issues you might be facing and where to find the log files to dig deeper:
Possible Issues in Your Workflow
These are the most common reasons you'd get the "Unable to load build session" error:
Different command line sessions for build and scan: The
sourceanalyzerbuild session (MyProject) is tied to the current shell's environment variables. If you ran themsbuildcommand in one command prompt, then opened a new one for the scan, Fortify can't locate the session data. You must run all three commands in the same terminal window.Missing Fortify instrumentation during build: Sometimes the MSBuild command doesn't properly generate the Fortify intermediate files (like
.fdbfiles) needed for scanning. Try adding explicit configuration/platform parameters to ensure a clean, consistent build:sourceanalyzer -b MyProject msbuild /t:rebuild /p:Configuration=Release /p:Platform=x64 "c:\MyProject\MyProject.sln"Also, make sure you're using the .NET 5-compatible MSBuild (from the .NET 5 SDK) instead of an older version that might not integrate correctly with Fortify 20.2.
Unquoted spaces in paths: If your project path contains spaces (e.g.,
c:\My Projects\MyProject.sln), you need to wrap the path in double quotes. Unquoted spaces can cause MSBuild to misinterpret the path, leading to incomplete build data that Fortify can't use.Permission restrictions: The user running the commands might lack write access to the project directory or Fortify's cache location. This can prevent Fortify from saving the build session data. Try running the command prompt as Administrator and verify folder permissions.
Leftover build artifacts: Even with
/t:rebuild, sometimes residual files from previous builds interfere. You could add a manual clean step before the build, or check if thebin/objdirectories are properly cleared before running MSBuild.
Where to Find the Fortify Log File
The log file location depends on your setup, but here are the most common places to check:
User-specific Fortify directory: By default, Fortify stores logs in your user profile under:
C:\Users\[YourUsername]\.fortify\sca\logsLook for files named like
sca_*.logorsourceanalyzer_*.log—the most recent one will contain details about the build session failure.Current working directory: If you didn't specify a log location, Fortify might also write logs to the directory where you ran the
sourceanalyzercommands. Check for files with.logextensions here.Environment variable override: If you've set the
SCA_LOG_DIRenvironment variable, the logs will be in the path specified by that variable.Verbose output for quick location: Add the
-verboseflag to your scan command to get real-time output that includes the exact log file path:sourceanalyzer -b MyProject -scan -f c:\MyReports\MyReport.fpr -verbose
内容的提问来源于stack exchange,提问作者gsharp

