Wiki Markup |
---|
Programmers frequently make errors regarding the precedence rules of operators due to the unintuitive low-precedence levels of {{&}}, {{\|}}, {{\^}}, {{<<}}, and {{>>}}. Mistakes regarding precedence rules can be avoided by the suitable use of parentheses. Defensive use of parentheses, if not taken to excess, also improves code readability. The precedence of operations by the order of the subclauses are defined in the Java Tutorials \[[Tutorials 08|AA. Java References#Tutorials 08]\]. |
...
Code Block | ||
---|---|---|
| ||
public static final int MASK = 1337;
public static final int OFFSET = -1337;
public static int computeCode(int x) {
return x & MASK + OFFSET;
}
|
According to the operator precedence rules, the expression is parsed as:
Code Block |
---|
x & (MASK + OFFSET)
|
This expression gets evaluated as shown below, resulting in the value 0.
Code Block |
---|
x & (1337 - 1337)
|
Compliant Solution
...
Code Block | ||
---|---|---|
| ||
public static final int MASK = 1337;
public static final int OFFSET = -1337;
public static int computeCode(int x) {
return (x & MASK) + OFFSET;
}
|
Exceptions
...
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
Other Languages
This rule appears in the C Coding Standard as EXP00-C. Use parentheses for precedence of operation.
...
Wiki Markup |
---|
\[[Tutorials 08|AA. Java References#Tutorials 08]\] [Expressions, Statements, and Blocks|http://java.sun.com/docs/books/tutorial/java/nutsandbolts/expressions.html], [Operators|http://java.sun.com/docs/books/tutorial/java/nutsandbolts/operators.html]
\[[ESA 05|AA. Java References#ESA 05]\] Rule 65: Use parentheses to explicitly indicate the order of execution of numerical operators |
...
EXP08-J. Be aware of integer promotions in binary operators 04. Expressions (EXP) EXP10EXP30-J. Understand the evaluation of Do not depend on operator precedence while using expressions containing non shortside-circuit operatorseffects