Download C Secure Coding Guidelines Review Draft WG14
Transcript
REVIEW DRAFT SUBJECT TO CHANGE
Error! Reference source not found.
#include <stdio.h>
mytypedef_t x;
/* ... */
printf("%llu", (unsigned long long) x);
Noncompliant Code Example
In this noncompliant code example, scanf is used to read an unsigned long long value into x, which has
type mytypedef_t.
#include <stdio.h>
mytypedef_t x;
/* ... */
if (scanf("%llu", &x) != 1) {
/* handle error */
}
Bibliography
[ISO/IEC 9899-1999] Section 7.18.1.5, "Greatest-width integer types," and Section 7.19.6, "Formatted
input/output functions"
[MITRE 07] CWE ID 681, "Incorrect Conversion between Numeric Types"
[Seacord 09] "INT15-C. Use intmax_t or uintmax_t for formatted IO on programmer-defined integer types"
8.6
Do not use floating point variables as loop counters
[FLP030]
Using a floating point variable as a loop counter shall be diagnosed because floating point numbers have
precision limitations. Code that relies on floating point loop counters can result in unexpected behavior.
Noncompliant Code Example
In this noncompliant code example, a floating-point variable is used as a loop counter.
for (float x = 0.1f; x <= 1.0f; x += 0.1f) {
/* ... */
}
Bibliography
[ISO/IEC 14882:2003] Sections 2.13.3, "Floating literals," and 3.9.1, "Fundamental types"
[ISO/IEC PDTR 24772] "PLF Floating Point Arithmetic"
[Lockheed Martin 05] AV Rule 197, "Floating point variables shall not be used as loop counters"
[MISRA 04] Rules 13.3 and 13.4
[Seacord 09] "FLP30-C. Do not use floating point variables as loop counters"
8.7
Do not reuse variable names in subscopes
[DCL001]
A variable that is in the subscope of and shares its name with another variable shall be diagnosed because
reusing variable names can result in unexpected behavior.
Error! Reference source not found.
Copyright 2009 Carnegie Mellon University 61