When a package variable is declared local
, it is often assumed that the package variable's contents are duplicated and stored in the local variable. This is not so; the local variable is set to undef
, just like any other uninitialized variable. Consequently, local variables must be initialized. They may be initialized with the contents of the package variable. If they are meant to be uninitialized, they should be explicitly set to undef
.
Perl has a large number of builtin functions, they are described on the perlfunc
manpage [Wall 2011]. Perl also has a handful of reserved keywords such as while
; they are described on the perlsyn
manpage [Wall 2011].
Do not use an identifier for a subroutine that has been reserved for a builtin function or keyword.
Noncompliant Code Example
...
Code Block | ||||
---|---|---|---|---|
| ||||
$passwd_required = 1;
# ...
sub authenticate_user {
local $passwd_required;
if (defined $passwd_required) {
print "Please enter a password\n";
# ... get and validate password
} else {
print "No password necessary\n";
}
}
authenticate_user();
|
...
This compliant solution initializes the localized variable to the old value. So , so it correctly prompts the user for a password.
Code Block | ||||
---|---|---|---|---|
| ||||
$passwd_required = 1;
# ...
sub authenticate_user {
local $passwd_required = $passwd_required;
if (defined $passwd_required) {
print "Please enter a password\n";
# ... get and validate password
} else {
print "No password necessary\n";
}
}
authenticate_user();
|
...
Recommendation | Severity | Likelihood | Remediation Cost | Priority | Level |
---|---|---|---|---|---|
DCL04-PL | low Low | probable Probable | medium Medium | P2 P4 | L3 |
Automated Detection
| Tool |
| Diagnostic | |
---|---|---|---|---|
Perl::Critic | Variables::RequireInitializationForLocalVars |
Bibliography
...
...
2005] |
...
"Initialization," p. 78 | |
[CPAN] | Elliot Shank, Perl-Critic-1.116 Variables::RequireInitializationForLocalVars |
[Wall 2011] | perlfunc, perlsyn |
...
01. Declarations and Initialization DCL32-PL. Every module must return a true value