使用Bullseye进行C代码覆盖率测试:探针分布疑问求助
Great question! Let's break down what's going on here with Bullseye Coverage—easy to mix up its different coverage collection modes if you're not familiar with the defaults.
First off, that single probe you're spotting at each function's start means Bullseye is configured to collect function-level coverage, not the branch/condition coverage you were expecting. This probe doesn't track internal control transfers at all—it only has one job: record whether the function was executed at all. Function-level coverage is the simplest form of coverage; it just answers "which functions got called during testing?" and doesn't dig into how code flows inside those functions.
So why aren't you seeing probes at for, if, or while statements? That's almost certainly because you didn't enable branch/condition coverage when instrumenting your code. Bullseye defaults to function-level coverage unless you explicitly tell it to collect more detailed data. Here's how to fix that:
- When compiling with Bullseye's wrapper compiler (
bcinstead ofgcc/clang), add the-bcov:branchflag to enable branch coverage. For example:bc -bcov:branch your_c_code.c -o your_program - If you're using a build system like Make, update your compiler command to include that flag, or set the
BULLSEYE_FLAGSenvironment variable to-bcov:branchbefore building.
Once you re-instrument with branch coverage enabled, you'll start seeing probes inserted at every control transfer point (like if conditions, loop headers, and switch cases). These probes track whether each branch was taken or skipped, giving you the detailed coverage data you initially expected.
Just to recap: Bullseye's probe placement directly ties to the coverage level you request. Function-level = single entry probe; branch/condition level = probes at all control flow junctions.
内容的提问来源于stack exchange,提问作者smwikipedia

