3 ms·
Has anyone found a static analysis tool which understands C11 annex K (aka “safe C”) functions? I’ve found some tools like CLANG static analysis will raise erro
by NLips 3y ago
Has anyone found a static analysis tool which understands C11 annex K (aka “safe C”) functions? I’ve found some tools like CLANG static analysis will raise errors for potentially incorrect calls to stdlib C functions, but doesn’t understand the replacements, which means some errors previously caught by analysis can only be caught at runtime.
- bierjunge 3y agoAnnex K is optional and the only compiler I'm aware of implementing it is MSVC (and only Microsoft wanted that in the standard), so the support for it will be nonexistent in "normal" tooling. If you need it, check if MS has something.
- lelanthran 3y ago> Annex K is optional and the only compiler I'm aware of implementing it is MSVC (and only Microsoft wanted that in the standard), And to rub salt into the wound, the Annex K functions supplied with MSVC are non-conforming to the standards Annex K functions, which were also pushed hard by Microsoft, which make them kinda doubly pointless: you use them and make code that is neither portable to another compiler nor conforming to the standard :-/
- account42 3y agoAlmost sounds like yet another EEE tactic.
- mumblemumble 3y agoI'd just as happily attribute this one to Microsoft's systemic inability to stick to a single plan for five minutes in a row.
- pjmlp 3y agoTo be fair, most the stuff ISO adopts is rarely taken as suggested, that isn't the first, nor will be the last.
- rurban 3y agoI've implemented _FORTIFY_SOURCE=3 like checks with safeclib, the Annex K library. Compile-time and run-time