signed/unsigned conversions
Chris Evans
chris@scary.beasts.org
Wed Nov 8 11:36:00 GMT 2000
Michael,
Thank you very much for the reply!
-Wconversion is close to what we need.
It warns about implicit signed<->unsigned conversions, iff that conversion
occurs across a function boundary.
It doesn't warn with the simple case
{
unsigned int i1 = 0;
int i2 = -1;
i1 = i2; /* No warning */
i2 = i1; /* No warning */
}
Cheers
Chris
On Wed, 8 Nov 2000, Michael Meissner wrote:
> On Wed, Nov 08, 2000 at 04:08:27PM +0000, Chris Evans wrote:
> >
> > Hi,
> >
> > Mailing gcc-bugs, sorry if it's an inappropriate address :)
> >
> > Does gcc have a warning flag to warn if there are implicit conversions
> > between signed and unsigned variables? e.g. assigning an int to an
> > unsigned int, (or visa versa), be it explicitly or across a function call.
> >
> > If gcc _does_ have this, what is the option? It is not documented in the
> > info => bug.
> >
> > If it _doesn't_ have this, PLEASE PLEASE add it. It is a vital warning
> > flag to have for security purposes.
> >
> > As an aside, many other compilers seem to have the ability to warn about
> > this condition.
> >
> > If you have no objections, I'll forward the response to the security-audit
> > list, who are interested in this capability.
>
> There are two switches that may match what you want:
>
> `-Wconversion'
> Warn if a prototype causes a type conversion that is different
> from what would happen to the same argument in the absence of a
> prototype. This includes conversions of fixed point to floating
> and vice versa, and conversions changing the width or signedness
> of a fixed point argument except when the same as the default
> promotion.
>
> Also, warn if a negative integer constant expression is implicitly
> converted to an unsigned type. For example, warn about the
> assignment `x = -1' if `x' is unsigned. But do not warn about
> explicit casts like `(unsigned) -1'.
>
> `-Wsign-compare'
> Warn when a comparison between signed and unsigned values could
> produce an incorrect result when the signed value is converted to
> unsigned. This warning is also enabled by `-W'; to get the other
> warnings of `-W' without this warning, use `-W -Wno-sign-compare'.
>
> These options are present in 2.95.2 as well as the current sources.
>
> --
> Michael Meissner, Red Hat, Inc.
> PMB 198, 174 Littleton Road #3, Westford, Massachusetts 01886, USA
> Work: meissner@redhat.com phone: +1 978-486-9304
> Non-work: meissner@spectacle-pond.org fax: +1 978-692-4482
>
More information about the Gcc-bugs
mailing list