Use type definitions (typedef
) to improve code readability.
The following declaration of the signal()
function is difficult to read and comprehend.
void (*signal(int, void (*)(int)))(int); |
This compliant solution makes use of type definitions to specify the same type as in the noncompliant code example.
typedef void (*SighandlerType)(int signum); extern SighandlerType signal( int signum, SighandlerType handler ); |
Code readability is important for discovering and eliminating vulnerabilities.
Recommendation |
Severity |
Likelihood |
Remediation Cost |
Priority |
Level |
---|---|---|---|---|---|
DCL05-C |
low |
unlikely |
medium |
P2 |
L3 |
Tool |
Version |
Checker |
Description |
|
---|---|---|---|---|
|
|
|||
|
|
|
|
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
C++ Secure Coding Standard: DCL05-CPP. Use typedefs to improve code readability
\[[ISO/IEC 9899:1999|AA. Bibliography#ISO/IEC 9899-1999]\] Section 6.7.7, "Type definitions" \[[ISO/IEC PDTR 24772|AA. Bibliography#ISO/IEC PDTR 24772]\] "BRS Leveraging human experience" |
02. Declarations and Initialization (DCL)