Skip to main content
assistive.skiplink.to.breadcrumbs
assistive.skiplink.to.header.menu
assistive.skiplink.to.action.menu
assistive.skiplink.to.quick.search
Log in
Confluence
Spaces
Hit enter to search
Help
Online Help
Keyboard Shortcuts
Feed Builder
What’s new
Available Gadgets
About Confluence
Log in
SEI CERT C Coding Standard
Pages
Boards
Space shortcuts
Dashboard
Secure Coding Home
Android
C
C++
Java
Perl
Page tree
Browse pages
Configure
Space tools
View Page
A
t
tachments (0)
Page History
Page Information
View in Hierarchy
View Source
Export to PDF
Export to Word
Pages
…
SEI CERT C Coding Standard
4 Back Matter
EE. Analyzers
CodeSonar_V
Page Information
Title:
CodeSonar_V
Author:
Amy Gale
Jul 30, 2014
Last Changed by:
Amy Gale
Jul 21, 2025
Tiny Link:
(useful for email)
https://wiki.sei.cmu.edu/confluence/x/U9UxBQ
Export As:
Word
·
PDF
Incoming Links
SEI CERT C Coding Standard (193)
Page:
STR02-C. Sanitize data passed to complex subsystems
Page:
EXP10-C. Do not depend on the order of evaluation of subexpressions or the order in which side effects take place
Page:
POS48-C. Do not unlock or destroy another POSIX thread's mutex
Page:
MEM04-C. Beware of zero-length allocations
Page:
DCL18-C. Do not begin integer constants with 0 when specifying a decimal value
Page:
INT36-C. Converting a pointer to integer or integer to pointer
Page:
DCL16-C. Use "L," not "l," to indicate a long value
Page:
ARR39-C. Do not add or subtract a scaled integer to a pointer
Page:
SIG30-C. Call only asynchronous-safe functions within signal handlers
Page:
INT30-C. Ensure that unsigned integer operations do not wrap
Page:
POS54-C. Detect and handle POSIX library errors
Page:
MSC38-C. Do not treat a predefined identifier as an object if it might only be implemented as a macro
Page:
MSC18-C. Be careful while handling sensitive data, such as passwords, in program code
Page:
WIN00-C. Be specific when dynamically loading libraries
Page:
CodeSonar
Page:
ERR34-C. Detect errors when converting a string to a number
Page:
DCL04-C. Do not declare more than one variable per declaration
Page:
EXP34-C. Do not dereference null pointers
Page:
MSC30-C. Do not use the rand() function for generating pseudorandom numbers
Page:
MEM03-C. Clear sensitive information stored in reusable resources
Page:
POS51-C. Avoid deadlock with POSIX threads by locking in predefined order
Page:
ARR36-C. Do not subtract or compare two pointers that do not refer to the same array
Page:
CON33-C. Avoid race conditions when using library functions
Page:
MEM07-C. Ensure that the arguments to calloc(), when multiplied, do not wrap
Page:
EXP15-C. Do not place a semicolon on the same line as an if, for, or while statement
Page:
ERR30-C. Take care when reading errno
Page:
FLP30-C. Do not use floating-point variables as loop counters
Page:
MEM35-C. Allocate sufficient memory for an object
Page:
INT31-C. Ensure that integer conversions do not result in lost or misinterpreted data
Page:
POS49-C. When data must be accessed by multiple threads, provide a mutex and guarantee no adjacent data is also accessed
Page:
CON36-C. Wrap functions that can spuriously wake up in a loop
Page:
INT02-C. Understand integer conversion rules
Page:
CON05-C. Do not perform operations that can block while holding a lock
Page:
CON41-C. Wrap functions that can fail spuriously in a loop
Page:
ENV01-C. Do not make assumptions about the size of an environment variable
Page:
FIO01-C. Be careful using functions that use file names for identification
Page:
DCL06-C. Use meaningful symbolic constants to represent literal values
Page:
EXP05-C. Do not cast away a const qualification
Page:
DCL11-C. Understand the type issues associated with variadic functions
Page:
CON01-C. Acquire and release synchronization primitives in the same module, at the same level of abstraction
Page:
DCL41-C. Do not declare variables inside a switch statement before the first case label
Page:
INT18-C. Evaluate integer expressions in a larger size before comparing or assigning to that size
Page:
EXP47-C. Do not call va_arg with an argument of the incorrect type
Page:
MEM33-C. Allocate and copy structures containing a flexible array member dynamically
Page:
MEM36-C. Do not modify the alignment of objects by calling realloc()
Page:
POS34-C. Do not call putenv() with a pointer to an automatic variable as the argument
Page:
SIG01-C. Understand implementation-specific details regarding signal handler persistence
Page:
ENV32-C. All exit handlers must return normally
Page:
ENV33-C. Do not call system()
Page:
EXP08-C. Ensure pointer arithmetic is used correctly
Page:
MSC37-C. Ensure that control never reaches the end of a non-void function
Page:
POS44-C. Do not use signals to terminate threads
Page:
EXP33-C. Do not read uninitialized memory
Page:
CON02-C. Do not use volatile as a synchronization primitive
Page:
DCL07-C. Include the appropriate type information in function declarators
Page:
MSC13-C. Detect and remove unused values
Page:
INT33-C. Ensure that division and remainder operations do not result in divide-by-zero errors
Page:
INT34-C. Do not shift an expression by a negative number of bits or by greater than or equal to the number of bits that exist in the operand
Page:
FIO13-C. Never push back anything other than one read character
Page:
MSC23-C. Beware of vendor-specific library and language differences
Page:
DCL20-C. Explicitly specify void when a function accepts no arguments
Page:
DCL37-C. Do not declare or define a reserved identifier
Page:
EXP45-C. Do not perform assignments in selection statements
Page:
MSC11-C. Incorporate diagnostic tests using assertions
Page:
SIG02-C. Avoid using signals to implement normal functionality
Page:
CON39-C. Do not join or detach a thread that was previously joined or detached
Page:
INT09-C. Ensure enumeration constants map to unique values
Page:
API07-C. Enforce type safety
Page:
FIO06-C. Create files with appropriate access permissions
Page:
EXP42-C. Do not compare padding data
Page:
MSC22-C. Use the setjmp(), longjmp() facility securely
Page:
INT13-C. Use bitwise operators only on unsigned operands
Page:
STR31-C. Guarantee that storage for strings has sufficient space for character data and the null terminator
Page:
API02-C. Functions that read or write to or from an array should take an argument to specify the source or target size
Page:
FLP36-C. Preserve precision when converting integral values to floating-point type
Page:
CON43-C. Do not allow data races in multithreaded code
Page:
ARR37-C. Do not add or subtract an integer to a pointer to a non-array object
Page:
ENV30-C. Do not modify the object referenced by the return value of certain functions
Page:
EXP12-C. Do not ignore values returned by functions
Page:
MEM31-C. Free dynamically allocated memory when no longer needed
Page:
ARR32-C. Ensure size arguments for variable length arrays are in a valid range
Page:
DCL05-C. Use typedefs of non-pointer types only
Page:
FIO39-C. Do not alternately input and output from a stream without an intervening flush or positioning call
Page:
SIG35-C. Do not return from a computational exception signal handler
Page:
MSC07-C. Detect and remove dead code
Page:
CON30-C. Clean up thread-specific storage
Page:
MEM00-C. Allocate and free memory in the same module, at the same level of abstraction
Page:
MSC12-C. Detect and remove code that has no effect or is never executed
Page:
DCL00-C. Const-qualify immutable objects
Page:
STR06-C. Do not assume that strtok() leaves the parse string unchanged
Page:
PRE32-C. Do not use preprocessor directives in invocations of function-like macros
Page:
API00-C. Functions should validate their parameters
Page:
EXP14-C. Beware of integer promotion when performing bitwise operations on integer types smaller than int
Page:
FIO45-C. Avoid TOCTOU race conditions while accessing files
Page:
EXP00-C. Use parentheses for precedence of operation
Page:
PRE11-C. Do not conclude macro definitions with a semicolon
Page:
STR03-C. Do not inadvertently truncate a string
Page:
EXP43-C. Avoid undefined behavior when using restrict-qualified pointers
Page:
POS52-C. Do not perform operations that can block while holding a POSIX lock
Page:
ARR38-C. Guarantee that library functions do not form invalid pointers
Page:
FIO21-C. Do not create temporary files in shared directories
Page:
INT04-C. Enforce limits on integer values originating from tainted sources
Page:
DCL03-C. Use a static assertion to test the value of a constant expression
Page:
STR05-C. Use pointers to const when referring to string literals
Page:
FIO10-C. Take care when using the rename() function
Page:
FIO46-C. Do not access a closed file
Page:
FIO47-C. Use valid format strings
Page:
PRE31-C. Avoid side effects in arguments to unsafe macros
Page:
INT32-C. Ensure that operations on signed integers do not result in overflow
Page:
MSC21-C. Use robust loop termination conditions
Page:
FIO40-C. Reset strings on fgets() or fgetws() failure
Page:
MEM11-C. Do not assume infinite heap space
Page:
POS05-C. Limit access to files by creating a jail
Page:
DCL23-C. Guarantee that mutually visible identifiers are unique
Page:
FLP00-C. Understand the limitations of floating-point numbers
Page:
EXP36-C. Do not cast pointers into more strictly aligned pointer types
Page:
EXP46-C. Do not use a bitwise operator with a Boolean-like operand
Page:
FIO44-C. Only use values for fsetpos() that are returned from fgetpos()
Page:
FIO42-C. Close files when they are no longer needed
Page:
STR34-C. Cast characters to unsigned char before converting to larger integer sizes
Page:
WIN30-C. Properly pair allocation and deallocation functions
Page:
CON32-C. Prevent data races when accessing bit-fields from multiple threads
Page:
DCL30-C. Declare objects with appropriate storage durations
Page:
EXP37-C. Call functions with the correct number and type of arguments
Page:
FIO24-C. Do not open a file that is already open
Page:
DCL15-C. Declare file-scope objects or functions that do not need external linkage as static
Page:
MSC33-C. Do not pass invalid data to the asctime() function
Page:
STR04-C. Use plain char for characters in the basic character set
Page:
CON31-C. Do not destroy a mutex while it is locked
Page:
DCL36-C. Do not declare an identifier with conflicting linkage classifications
Page:
CON35-C. Avoid deadlock by locking in a predefined order
Page:
INT12-C. Do not make assumptions about the type of a plain int bit-field when used in an expression
Page:
MSC24-C. Do not use deprecated or obsolescent functions
Page:
EXP30-C. Do not depend on the order of evaluation for side effects
Page:
WIN02-C. Restrict privileges when spawning child processes
Page:
DCL02-C. Use visually distinct identifiers
Page:
STR32-C. Do not pass a non-null-terminated character sequence to a library function that expects a string
Page:
FIO02-C. Canonicalize path names originating from tainted sources
Page:
FIO37-C. Do not assume that fgets() or fgetws() returns a nonempty string when successful
Page:
ARR01-C. Do not apply the sizeof operator to a pointer when taking the size of an array
Page:
DCL19-C. Minimize the scope of variables and functions
Page:
FIO34-C. Distinguish between characters read from a file and EOF or WEOF
Page:
MSC39-C. Do not call va_arg() on a va_list that has an indeterminate value
Page:
MEM30-C. Do not access freed memory
Page:
POS38-C. Beware of race conditions when using fork and file descriptors
Page:
CON37-C. Do not call signal() in a multithreaded program
Page:
EXP35-C. Do not modify objects with temporary lifetime
Page:
FLP32-C. Prevent or detect domain and range errors in math functions
Page:
PRE00-C. Prefer inline or static functions to function-like macros
Page:
INT07-C. Use only explicitly signed or unsigned char type for numeric values
Page:
DCL40-C. Do not create incompatible declarations of the same function or object
Page:
INT01-C. Use size_t or rsize_t for all integer values representing the size of an object
Page:
ERR33-C. Detect and handle standard library errors
Page:
PRE30-C. Do not create a universal character name through concatenation
Page:
CON07-C. Ensure that compound operations on shared variables are atomic
Page:
FIO08-C. Take care when calling remove() on an open file
Page:
SIG34-C. Do not call signal() from within interruptible signal handlers
Page:
INT08-C. Verify that all integer values are in range
Page:
CON38-C. Preserve thread safety and liveness when using condition variables
Page:
EXP44-C. Do not rely on side effects in operands to sizeof, _Alignof, or _Generic
Page:
MSC06-C. Beware of compiler optimizations
Page:
DCL39-C. Avoid information leakage when passing a structure across a trust boundary
Page:
FLP06-C. Convert integers to floating point for floating-point operations
Page:
POS30-C. Use the readlink() function properly
Page:
PRE05-C. Understand macro replacement when concatenating tokens or performing stringification
Page:
MSC20-C. Do not use a switch statement to transfer control into a complex block
Page:
MSC25-C. Do not use insecure or weak cryptographic algorithms
Page:
FLP34-C. Ensure that floating-point conversions are within range of the new type
Page:
STR37-C. Arguments to character-handling functions must be representable as an unsigned char
Page:
INT05-C. Do not use input functions to convert character data if they cannot handle all possible inputs
Page:
MEM34-C. Only free memory allocated dynamically
Page:
MEM05-C. Avoid large stack allocations
Page:
SIG00-C. Mask signals handled by noninterruptible signal handlers
Page:
SIG31-C. Do not access shared objects in signal handlers
Page:
MSC32-C. Properly seed pseudorandom number generators
Page:
INT35-C. Use correct integer precisions
Page:
DCL01-C. Do not reuse variable names in subscopes
Page:
MSC17-C. Finish every set of statements associated with a case label with a break statement
Page:
STR00-C. Represent characters using an appropriate type
Page:
DCL13-C. Declare function parameters that are pointers to values not changed by the function as const
Page:
MEM01-C. Store a new value in pointers immediately after free()
Page:
FIO30-C. Exclude user input from format strings
Page:
MSC09-C. Character encoding: Use subset of ASCII for safety
Page:
ARR00-C. Understand how arrays work
Page:
MSC41-C. Never hard code sensitive information
Page:
MSC00-C. Compile cleanly at high warning levels
Page:
CON40-C. Do not refer to an atomic variable twice in an expression
Page:
FLP02-C. Avoid using floating-point numbers when precise computation is needed
Page:
CON34-C. Declare objects shared between threads with appropriate storage durations
Page:
WIN01-C. Do not forcibly terminate execution
Page:
STR38-C. Do not confuse narrow and wide character strings and functions
Page:
ARR30-C. Do not form or use out-of-bounds pointers or array subscripts
Page:
PRE02-C. Macro replacement lists should be parenthesized
Hierarchy
Parent Page
Page:
EE. Analyzers
Labels
There are no labels assigned to this page.
Recent Changes
Time
Editor
Jul 21, 2025 18:00
Amy Gale
View Changes
CodeSonar 9.0 -> 9.1
Mar 10, 2025 17:57
Amy Gale
View Changes
Jan 30, 2025 00:27
Amy Gale
View Changes
Bump CodeSonar version for C mappings
Apr 01, 2024 15:55
Jon O'Donnell
View Changes
Dec 07, 2023 09:25
Jon O'Donnell
View Page History
Overview
Content Tools
{"serverDuration": 886, "requestCorrelationId": "d0a2707a80edfe74"}