diff options
| author | dacctal <donotcontactmevia@email.invalid> | 2026-06-29 03:19:33 +0000 |
|---|---|---|
| committer | dacctal <donotcontactmevia@email.invalid> | 2026-06-29 03:19:33 +0000 |
| commit | d85350854dca4c6495cb78c89ff4934c7a908509 (patch) | |
| tree | 2b8cbd9db60f81b0ab538be447d318017e064ff1 /include/banned.h | |
| parent | 5f153abb7345aa4ddc574621d6842e07f80a559c (diff) | |
FCC: banned.h
Diffstat (limited to 'include/banned.h')
| -rw-r--r-- | include/banned.h | 47 |
1 files changed, 47 insertions, 0 deletions
diff --git a/include/banned.h b/include/banned.h new file mode 100644 index 0000000..2b934c8 --- /dev/null +++ b/include/banned.h @@ -0,0 +1,47 @@ +#ifndef BANNED_H +#define BANNED_H + +/* + * This header lists functions that have been banned from our code base, + * because they're too easy to misuse (and even if used correctly, + * complicate audits). Including this header turns them into compile-time + * errors. + */ + +#define BANNED(func) sorry_##func##_is_a_banned_function + +#undef strcpy +#define strcpy(x,y) BANNED(strcpy) +#undef strcat +#define strcat(x,y) BANNED(strcat) +#undef strncpy +#define strncpy(x,y,n) BANNED(strncpy) +#undef strncat +#define strncat(x,y,n) BANNED(strncat) +#undef strtok +#define strtok(x,y) BANNED(strtok) +#undef strtok_r +#define strtok_r(x,y,z) BANNED(strtok_r) + +#undef sprintf +#undef vsprintf +#define sprintf(...) BANNED(sprintf) +#define vsprintf(...) BANNED(vsprintf) + +#undef gmtime +#define gmtime(t) BANNED(gmtime) +#undef localtime +#define localtime(t) BANNED(localtime) +#undef ctime +#define ctime(t) BANNED(ctime) +#undef ctime_r +#define ctime_r(t, buf) BANNED(ctime_r) +#undef asctime +#define asctime(t) BANNED(asctime) +#undef asctime_r +#define asctime_r(t, buf) BANNED(asctime_r) + +#undef mktemp +#define mktemp(x) BANNED(mktemp) + +#endif /* BANNED_H */ |
