isocpp / isocpp/CppCoreGuidelines

'Ensures' example regarding security bug is misleading

Open
#11 8 comments 0 reactions 1 assignee View on GitHub

Nobody has claimed this yet.

Enhancement -- Security
Dominant language
CSS
Stars
45.3k
Forks
5.6k
PR merge metrics
No merged PRs in 30d

Description

Example, bad: Consider a famous security bug

 void f() // problematic
 {
  char buffer[MAX];
  // ...
  memset(buffer,0,MAX);
 }

There was no postcondition stating that the buffer should be cleared and the optimizer eliminated the apparently redundant memset() call:

 void f() // better
 {
  char buffer[MAX];
  // ...
  memset(buffer,0,MAX);
  Ensures(buffer[0]==0);
 }

This implies that the second version averts the security bug. But this isn't true: the compiler is free to note that buffer[0]==0 should always be true at the point, replace the argument with a constant true, then make the same elimination of the memset call. And in fact, both GCC and Clang do so. The only correct way to avoid the security bug is to use a special-purpose function like memset_s (or maybe volatile).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.