01.07.2016 Views

SEI CERT C Coding Standard

tqcylJ

tqcylJ

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.12 EXP44-C. Do not rely on side effects in operands to sizeof, _Alignof, or _Generic 122<br />

4.13 EXP45-C. Do not perform assignments in selection statements 126<br />

4.14 EXP46-C. Do not use a bitwise operator with a Boolean-like operand 131<br />

5 Integers (INT) 132<br />

5.1 INT30-C. Ensure that unsigned integer operations do not wrap 132<br />

5.2 INT31-C. Ensure that integer conversions do not result in lost or misinterpreted data 138<br />

5.3 INT32-C. Ensure that operations on signed integers do not result in overflow 147<br />

5.4 INT33-C. Ensure that division and remainder operations do not result in divide-by-zero<br />

errors 157<br />

5.5 INT34-C. Do not shift an expression by a negative number of bits or by greater than or<br />

equal to the number of bits that exist in the operand 160<br />

5.6 INT35-C. Use correct integer precisions 166<br />

5.7 INT36-C. Converting a pointer to integer or integer to pointer 169<br />

6 Floating Point (FLP) 173<br />

6.1 FLP30-C. Do not use floating-point variables as loop counters 173<br />

6.2 FLP32-C. Prevent or detect domain and range errors in math functions 176<br />

6.3 FLP34-C. Ensure that floating-point conversions are within range of the new type 185<br />

6.4 FLP36-C. Preserve precision when converting integral values to floating-point type 189<br />

6.5 FLP37-C. Do not use object representations to compare floating-point values 191<br />

7 Array (ARR) 193<br />

7.1 ARR30-C. Do not form or use out-of-bounds pointers or array subscripts 193<br />

7.2 ARR32-C. Ensure size arguments for variable length arrays are in a valid range 203<br />

7.3 ARR36-C. Do not subtract or compare two pointers that do not refer to the same array 207<br />

7.4 ARR37-C. Do not add or subtract an integer to a pointer to a non-array object 209<br />

7.5 ARR38-C. Guarantee that library functions do not form invalid pointers 212<br />

7.6 ARR39-C. Do not add or subtract a scaled integer to a pointer 222<br />

8 Characters and Strings (STR) 226<br />

8.1 STR30-C. Do not attempt to modify string literals 226<br />

8.2 STR31-C. Guarantee that storage for strings has sufficient space for character<br />

data and the null terminator 230<br />

8.3 STR32-C. Do not pass a non-null-terminated character sequence to a library function<br />

that expects a string 242<br />

8.4 STR34-C. Cast characters to unsigned char before converting to larger integer sizes 247<br />

8.5 STR37-C. Arguments to character-handling functions must be representable as an<br />

unsigned char 251<br />

8.6 STR38-C. Do not confuse narrow and wide character strings and functions 253<br />

9 Memory Management (MEM) 256<br />

9.1 MEM30-C. Do not access freed memory 256<br />

9.2 MEM31-C. Free dynamically allocated memory when no longer needed 262<br />

9.3 MEM33-C. Allocate and copy structures containing a flexible array member<br />

dynamically 264<br />

9.4 MEM34-C. Only free memory allocated dynamically 269<br />

9.5 MEM35-C. Allocate sufficient memory for an object 273<br />

9.6 MEM36-C. Do not modify the alignment of objects by calling realloc() 277<br />

<strong>SEI</strong> <strong>CERT</strong> C <strong>Coding</strong> <strong>Standard</strong>: Rules for Developing Safe, Reliable, and Secure Systems<br />

Software Engineering Institute | Carnegie Mellon University<br />

[DISTRIBUTION STATEMENT A] Approved for public release and unlimited distribution.<br />

ii

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!