1 Scope
This Technical Specification specifies
— rules for secure coding in the C programming language and
— code examples.
This Technical Specification does not specify
— the mechanism by which these rules are enforced or
— any particular coding style to be enforced. (It has been impossible to develop a consensus
on appropriate style guidelines. Programmers should define style guidelines and apply
these guidelines consistently. The easiest way to consistently apply a coding style
is with the use of a code formatting tool. Many interactive development environments
provide such capabilities.)
Each rule in this Technical Specification is accompanied by code examples. Code examples
are informative only and serve to clarify the requirements outlined in the normative
portion of the rule. Examples impose no normative requirements.
Each rule in this Technical Specification that is based on undefined behavior defined
in the C Standard identifies the undefined behavior by a numeric code. The numeric
codes for undefined behaviors can be found in Annex B, Undefined Behavior.
Two distinct kinds of examples are provided:
...