4 ms·
Secure C coding standards by SEI
- sigjuice 10y agoIs there a code analysis tool that will flag code that violates these rules?
- wyldfire 10y agoElsewhere on the SEI site there are some checkers [1] [2]. They also advocate using clang's "-Wthread-safety" among others. It doesn't sound to me like there exists a tool that will measure this coding standard as conformance criteria. [1] https://github.com/SEI-CERT/scvs https://github.com/SEI-CERT/scvs [2] https://sourceforge.net/projects/rosecheckers/ https://sourceforge.net/projects/rosecheckers/
- deleted 10y ago[deleted]
- bliker 10y agoClang tidy supports some of the rules http://clang.llvm.org/extra/clang-tidy/ http://clang.llvm.org/extra/clang-tidy/
- EliRivers 10y agoIf you're on someone else's budget, there are some commercial tools that flag against various coding standards. A quick check on something I half remembered shows these people say they cover CERT; http://www.programmingresearch.com/coding-standards/compliance-modules/ http://www.programmingresearch.com/coding-standards/complian... I know there are more.
- rezzo 10y agoDirect PDF download: http://www.sei.cmu.edu/downloads/sei-cert-c-coding-standard-2016-v01.pdf http://www.sei.cmu.edu/downloads/sei-cert-c-coding-standard-...
- orthopteroid 10y agoMiserable fail to cert for requiring a https-less registration for a document on security.
- dward 10y agoCMU doesn't require, but it does allow: https://www.sei.cmu.edu/downloads/sei-cert-c-coding-standard-2016-v01.pdf https://www.sei.cmu.edu/downloads/sei-cert-c-coding-standard...
- hsivonen 10y agoThe “compliant solution” example for setlocale() is thread-unsafe, AFAICT. (I’m not aware of a safe solution other than “don’t use the text processing part of the C standard library, because its design is too wrong”.)
- wuch 10y agoThere is a thread-specific uselocale() in POSIX.1-2008.
- kazinator 10y agoIs anyone else finding some of these rules to be bizzarely tone deaf? Recurring pattern: "Don't do such and such that is obviously wrong." Well, no kidding! I would never do such a thing ... on purpose! It's the not-on-purpose occurrences that I need help with. Without a concrete plan on how to prevent or detect that situation, this advice isn't helpful. I know I shouldn't rely on uninitialized memory, and, believe me, I do not want to. Give me a coding strategy which minimizes the occurrence of uses of uninitialized memory. Recommend a compiler and its particular compiler options, or some lint or other static checking tool or run-time detection. "Don't read uninitialized memory" isn't something I can turn into a concrete action to somehow improve software quality. It's like a driver's manual which says "stay on the road and don't run over people".
- generic_user 10y agoLike the ISO C standard I do not think that Cert is meant to be a training document in and of itself like a book. The user of the standard is going to have to draw on other sources, experience and technology to put together a an implementation strategy. The purpose of the standard is to allows a piece of software to get CERT certified. You have to actually submit your code to CERT and they analyze it and give you a certificate and add the software to the list of conforming systems. This can intern help to gain other certifications. For instance if you are working on software for the Department Of Defense they have there own sets of certification standards. Some of which may be satisfied by conformance to CERT. I would start to investigate static analyzers and compilers and see what you can find. Specifically look for claim that diagnose standards violations and which ones. Also take a look at section 1.7. There is a difference between the 99 coding 'rules' and the 185 'recommendations'. Recommendations provide guidance but do not necessarily indicate a defect. So a recommendation is not necessarily exact.
- kazinator 10y agoIn that case, why is it repeating material out of ISO C instead of just referring to ISO C as a base document for all those points. You can summarize it all in one item: "A program fails to conform to the CERT standard for secure coding if it violates any of the following 'undefined behavior' situations explicitly described in ISO C, or implicitly by omission: [give a summary list with brief descriptions and section references]"