1,059 karma · joined February 7, 2010
Which is the precise definition of Not In My Back Yard...
if (std::vector<int> v = f(); !v.empty()) { // Use v }
without requiring an extra compound statement to limit the scope and lifetime of v.
It was submitted for PDTS (proposed draft technical standard), which means it goes out for balloting to ISO national bodies. That balloting either succeeds (at which point you have a Techincal Specification) or it comes back to the committee with comments that the committee then has to respond to (and then another round of balloting happens). Once it's accepted as a Technical Specification, it's still not part of the C++ International Standard. That's a decision the committee comes to at their own pace, much like what happened at this meeting where the Concepts TS was accepted (as amended) into the IS.
Think of a TS somewhat like a beta. There's no assurance that the contents of the TS will go into the IS at all or in the exact form it was originally specified in, but that's certainly the hope when the TS is published.
It's easy to forget that alignment is important on some architectures (other than for performance reasons), so be careful when using placement new: https://www.securecoding.cert.org/confluence/display/cpluspl...
This may seem obvious, but even the C++ committee got this one wrong when they created auto_ptr (which has since been removed from the standard): https://www.securecoding.cert.org/confluence/display/cpluspl...
This one is totally obvious but has a stunning number of ways you can fail to adhere to it, some of which look reasonable at first blush: https://www.securecoding.cert.org/confluence/display/cpluspl...
https://blogs.msdn.microsoft.com/vcblog/2007/05/17/diagnosin...
[[]][[]][]()[[]][[]]{}();
One thing to note, they split them into recommendations and rules. Recommendations are more stylistic and open to debate, whereas violations of rules generally result in definite security concerns.
min(a++, b++);
a or b would really be incremented twice.More information on the distinction can be found at: https://www.securecoding.cert.org/confluence/display/seccode...
Basically, the CERT rules all must be analyzable (though some require dynamic analysis instead of static analysis).
#include <string.h>
struct S {
int i;
char c;
int j;
};
void f(void) {
struct S s1 = { 0, 0, 0 }, s2 = { 0, 0, 0 };
memcpy(&s1, &s2, 9);
}
int main(void) {
f();
return 0;
}
MSVC, Clang, and PC-Lint are all silent on the code (which is reasonable behavior since it's impossible to glean programmer intent from that snippet -- maybe the programmer really only wants the first nine bytes!). (Btw, yes, I am using the analyzer features for MSVC and Clang, not just relying on high warning levels.)So while that warning can certainly be useless information, it does definitely catch bugs. Unfortunately, the people who write code like the above are also more likely to be people who ignore warnings. ;-)