
...
Code Block | ||||
---|---|---|---|---|
| ||||
my $source; open(SOURCEmy $SOURCE, "<", $source); @lines = (<SOURCE><$SOURCE>); close(SOURCE$SOURCE); |
It makes sure the variable containing the file name is properly defined, but it does nothing else to catch errors. Consequently, any error, such as the file not existing, being unreadable, or containing too much data to read into memory, will cause the program to abort.
...
Code Block | ||||
---|---|---|---|---|
| ||||
my $source; open(SOURCEmy $SOURCE, "<", $source) or croak "error opening $source: $!"; @lines = (<SOURCE><$SOURCE>); close(SOURCE$SOURCE) or croak "error closing $source: $!"; |
...
Code Block | ||||
---|---|---|---|---|
| ||||
use autodie; my $source; open(SOURCEmy $SOURCE, "<", $source); @lines = (<SOURCE><$SOURCE>); close(SOURCE$SOURCE); |
EXP32:EX2: Functions that send data to standard output or standard error need not have their return values checked. This includes print
and printf
, but only if their file handle argument is not supplied or is explicitly set to *STDOUT
or *STDERR
. If they send their output to any other file handle, their return value must be checked.
...
Failure to handle error codes or other values returned by functions can lead to incorrect program flow and violations of data integrity.
Recommendation | Severity | Likelihood | Remediation Cost | Priority | Level |
---|---|---|---|---|---|
EXP32-PL | Medium | Probable | Low | P12 | L1 |
Automated Detection
Tool | Version | Checker | Description | ||||||
---|---|---|---|---|---|---|---|---|---|
Perl::Critic | 5.0 | InputOutput::RequireCheckedClose | Implemented | ||||||
| PERL_D89 | Fully implemented |
Related Guidelines
SEI CERT C Coding Standard | EXP12-C. Do not ignore values returned by functions |
---|---|
SEI CERT C++ |
Coding Standard | VOID EXP12-CPP. Do not ignore values returned by functions or methods |
CERT Oracle Secure Coding Standard for Java | EXP00-J. Do not ignore values returned by methods |
Bibliography
[Conway 2005] | "Error Checking," p. 208 |
---|---|
[CPAN] | autodie |
[Open Group 2008] | open() |