Multi-Tool Scanning
MemGuard orchestrates 15 detection tools in parallel with unified output and AI analysis.
Usage
# Scan with specific tools
memguard scan /tmp/binary --tools valgrind,helgrind,infer
# Scan with all available tools
memguard scan /tmp/binary
# Fast scan without AI
memguard scan /tmp/binary --no-ai
# Scan from source
memguard scan ./src/main.c --compile "gcc -g -O0 -o /tmp/out main.c"
# With binary arguments
memguard scan /tmp/server --args "--port 8080"
# Verbose (shows MemHint injection)
memguard scan /tmp/binary -v
# Export to JSON
memguard scan /tmp/binary --output report.json
# View past scans
memguard history
memguard report <scan-id>
How It Works
DWARF Source Discovery - reads binary debug info to find source files
MemHint Loading - injects custom allocator patterns into Infer
Parallel Execution - all tools run concurrently via asyncio
Unified Parsing - Valgrind XML, Infer JSON, cppcheck XML → MemoryError objects
Deduplication - merges same-location errors across tools
AI 4-Pass Analysis - triage, root cause, fix generation, step decomposition
Fix Validation - pattern validator + CWE validator + Z3 verifier
Detection Tools
Tool |
Type |
What It Detects |
|---|---|---|
Valgrind memcheck |
Dynamic |
Leaks, use-after-free, uninit reads, invalid free |
Helgrind |
Dynamic |
Data races, lock order violations, pthread misuse |
Facebook Infer |
Static |
Null deref, leaks, uninit reads (+ custom MM via MemHint) |
cppcheck |
Static |
Buffer overflows, null deref, style issues |
clang-tidy |
Static |
C++ modernization, bug-prone patterns |
ASan/LSan/MSan/UBSan/TSan |
Dynamic |
Address errors, leaks, uninit memory, UB, data races |
heaptrack |
Dynamic |
Every malloc/free with full call stacks |
rr |
Dynamic |
Deterministic recording for reverse debugging |
tracemalloc / memray |
Python |
Python memory allocation tracking |
Miri |
Rust |
Rust undefined behavior in unsafe code |
Bug Types
Bug Type |
Severity |
CWE |
Description |
|---|---|---|---|
|
CRITICAL |
CWE-416 |
Accessing memory after deallocation |
|
CRITICAL |
CWE-415 |
Calling free() twice on same pointer |
|
CRITICAL |
CWE-122 |
Writing past allocated buffer boundaries |
|
CRITICAL |
CWE-476 |
Dereferencing a NULL pointer |
|
CRITICAL |
CWE-362 |
Unsynchronized concurrent memory access |
|
INFO |
CWE-401 |
Allocated memory never freed |