Wiki Markup |
---|
The C99 {{fopen()}} function is used to open an existing file or create a new one \[[ISO/IEC 9899:1999|AA. C References#ISO/IEC 9899-1999]\]. However, {{fopen()}} does not indicate if an existing file has been opened for writing or a new file has been created. This may lead to a program overwriting or accessing an unintended file. |
Noncompliant Code Example
...
(fopen()
)
In this noncompliant code example, the file referenced by file_name
is opened for writing. This example is noncompliant if the programmer's intent was to create a new file, but the referenced file already exists.
Code Block | ||
---|---|---|
| ||
char *file_name; FILE *fp; /* initialize file_name */ fp = fopen(file_name, "w"); if (!fp) { /* Handle error */ } |
Noncompliant Code Example
...
(fopen_s()
...
, ISO/IEC TR 24731-1)
Wiki Markup |
---|
The ISO/IEC TR 24731-1 {{fopen_s()}} function is designed to improve the security of the {{fopen()}} function \[[ISO/IEC TR 24731-1:2007|AA. C References#SO/IEC TR 24731-1-2007]\]. However, like {{fopen()}}, {{fopen_s()}} provides no mechanism to determine if an existing file has been opened for writing or a new file has been created. |
Code Block | ||
---|---|---|
| ||
char *file_name; FILE *fp; /* initialize file_name */ errno_t res = fopen_s(&fp, file_name, "w"); if (res != 0) { /* Handle error */ } |
Compliant Solution
...
(open()
...
, POSIX)
Wiki Markup |
---|
The {{open()}} function, as defined in the Open Group Base Specifications Issue 6 \[[Open Group 04|AA. C References#Open Group 04]\], is available on many platforms and provides finer control than {{fopen()}}. In particular, {{fopen()}} accepts the {{O_CREAT}} and {{O_EXCL}} flags. When used together, these flags instruct the {{open()}} function to fail if the file specified by {{file_name}} already exists. |
...
For examples on how to check for the existence of a file without opening it, see FIO10-C. Take care when using the rename() function.
Compliant Solution
...
(fopen()
...
, GNU)
Wiki Markup |
---|
Section 12.3 of the GNU C Library says: \[[Loosemore 07|AA. C References#Loosemore 07]\] |
...
Use of this (nonportable) extension allows for the easy remediation of legacy code.
Compliant Solution
...
(fdopen()
...
, POSIX)
Wiki Markup |
---|
For code that operates on {{FILE}} pointers and not file descriptors, the POSIX {{fdopen()}} function can be used to associate an open stream with the file descriptor returned by {{open()}}, as shown in this compliant solution \[[Open Group 04|AA. C References#Open Group 04]\]. |
...