Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

According to Section 7.4 of C99,

The header <ctype.h> declares several functions useful for classifying and mapping characters. In all cases the argument is an int, the value of which shall be representable as an unsigned char or shall equal the value of the macro EOF. If the argument has any other value, the behavior is undefined.

This is complicated by the fact that the char data type might, in any implementation, be signed or unsigned.

Non-Compliant Code Example

This non-compliant code example may pass illegal values to the ctype functions.

Code Block
size_t count_whitespace(const char *s) {
  const char *t = s;
  while(isspace(*t))  /* possibly *t < 0 */
    ++t;
  return t - s;
}

Compliant Solution 1

Pass character strings around explicitly using unsigned characters.

Code Block
size_t count_whitespace(const unsigned *s) {
  const unsigned char *t = s;
  while(isspace(*t))
    ++t;
  return t - s;
}

Wiki Markup
This approach is inconvenient when you need to interwork with other functions that haven't been designed with this approach in mind, such as the string handling functions found in the standard library \[[Kettlewell 02|AA. C References#Kettlewell 02]\].

Compliant Solution 2

This compliant solution uses an explicit cast.

Code Block
size_t count_whitespace(const char *s) {
  const char *t = s;
  while(isspace((unsigned char)*t))
    ++t;
  return t - s;
}

Priority: P3 Level: L3

Component

Value

Severity

1 (low)

Likelihood

1 (unlikely)

Remediation cost

3 (low)

References