why is this bad

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Gernot Frisch

    #1

    why is this bad

    char* s=" ";

    int main()
    {
    strcpy(s, "Hello World");
    }

    This program crashes nicely. I think s is a pointer to a string that
    is stored in the executable memory, so the strcpy will overwrite part
    of the program, right?

    I would not do this, but I found this error and I want to be able to
    explain it to the one who wrote it.
    Thank you,

    --
    -Gernot
    int main(int argc, char** argv) {printf
    ("%silto%c%cf%c gl%ssic%ccom%c" , "ma", 58, 'g', 64, "ba", 46, 10);}

    _______________ _______________ __________
    Looking for a good game? Do it yourself!
    GLBasic - you can do
    GLBasic is a programming language that supports multiple platforms like e.g. iPhone



  • alexmdac@hotmail.com

    #2
    Re: why is this bad

    I guess the string literal is stored in read-only memory. Try
    char sz[256] = " ";
    //etc.

    Comment

    • William Payne

      #3
      Re: why is this bad


      "Gernot Frisch" <Me@Privacy.net > wrote in message
      news:31lef0F39q seqU1@individua l.net...[color=blue]
      > char* s=" ";
      >
      > int main()
      > {
      > strcpy(s, "Hello World");
      > }
      >
      > This program crashes nicely. I think s is a pointer to a string that is
      > stored in the executable memory, so the strcpy will overwrite part of the
      > program, right?
      >
      > I would not do this, but I found this error and I want to be able to
      > explain it to the one who wrote it.
      > Thank you,
      >
      > --
      > -Gernot
      > int main(int argc, char** argv) {printf ("%silto%c%cf%c gl%ssic%ccom%c" ,
      > "ma", 58, 'g', 64, "ba", 46, 10);}
      >
      > _______________ _______________ __________
      > Looking for a good game? Do it yourself!
      > GLBasic - you can do
      > www.GLBasic.com
      >
      >[/color]

      String literalts are really of type const char* (even though you declared
      yours as just char*), that's probably the reason for the crash.
      So when declaring string literals always use type const char* so the
      compiler can catch such errors...if you want to modify the string, declare
      it as:
      char foo[] = { "hello" };

      / WP


      Comment

      • Risto Lankinen

        #4
        Re: why is this bad


        "William Payne" <ericliljaNoSpa m@yahoo.com> wrote in message
        news:cp40d2$bq3 $1@news.island. liu.se...[color=blue]
        >
        > "Gernot Frisch" <Me@Privacy.net > wrote in message
        > news:31lef0F39q seqU1@individua l.net...[color=green]
        > > char* s=" ";
        > >
        > > int main()
        > > {
        > > strcpy(s, "Hello World");
        > > }
        > >
        > > This program crashes nicely.[/color]
        >
        > String literalts are really of type const char* (even though you declared
        > yours as just char*), that's probably the reason for the crash.[/color]

        The interesting bit, of course, is why does C++ type mechanism
        allow you to initialize an object of type <char *> with something
        that really is a <const char *> ?!?

        IMO that's a flaw in C++ type mechanism.

        - Risto -


        Comment

        • Peter Koch Larsen

          #5
          Re: why is this bad


          "Risto Lankinen" <rlankine@hotma il.com> skrev i en meddelelse
          news:fQftd.3173 0$g4.595574@new s2.nokia.com...[color=blue]
          >
          > "William Payne" <ericliljaNoSpa m@yahoo.com> wrote in message
          > news:cp40d2$bq3 $1@news.island. liu.se...[color=green]
          >>
          >> "Gernot Frisch" <Me@Privacy.net > wrote in message
          >> news:31lef0F39q seqU1@individua l.net...[color=darkred]
          >> > char* s=" ";
          >> >
          >> > int main()
          >> > {
          >> > strcpy(s, "Hello World");
          >> > }
          >> >
          >> > This program crashes nicely.[/color]
          >>
          >> String literalts are really of type const char* (even though you declared
          >> yours as just char*), that's probably the reason for the crash.[/color]
          >
          > The interesting bit, of course, is why does C++ type mechanism
          > allow you to initialize an object of type <char *> with something
          > that really is a <const char *> ?!?
          >
          > IMO that's a flaw in C++ type mechanism.
          >
          > - Risto -
          >
          >[/color]
          It sure is! Well - it sure isn't! It is a left-over from C, kept for
          portability reasons.

          /Peter


          Comment

          • Rolf Magnus

            #6
            Re: why is this bad

            Risto Lankinen wrote:
            [color=blue][color=green]
            >> String literalts are really of type const char* (even though you declared
            >> yours as just char*), that's probably the reason for the crash.[/color]
            >
            > The interesting bit, of course, is why does C++ type mechanism
            > allow you to initialize an object of type <char *> with something
            > that really is a <const char *> ?!?[/color]

            Usually, it doesn't. You cannot remove constness without a cast, but...
            since there is so much C code (and maybe old C++ code) that lets non-const
            char* point to string literals, those are an exception to that rule.
            [color=blue]
            > IMO that's a flaw in C++ type mechanism.[/color]

            It's not a bug, it's a feature.

            Comment

            • Karl Heinz Buchegger

              #7
              Re: why is this bad

              Risto Lankinen wrote:[color=blue]
              >
              > "William Payne" <ericliljaNoSpa m@yahoo.com> wrote in message
              > news:cp40d2$bq3 $1@news.island. liu.se...[color=green]
              > >
              > > "Gernot Frisch" <Me@Privacy.net > wrote in message
              > > news:31lef0F39q seqU1@individua l.net...[color=darkred]
              > > > char* s=" ";
              > > >
              > > > int main()
              > > > {
              > > > strcpy(s, "Hello World");
              > > > }
              > > >
              > > > This program crashes nicely.[/color]
              > >
              > > String literalts are really of type const char* (even though you declared
              > > yours as just char*), that's probably the reason for the crash.[/color]
              >
              > The interesting bit, of course, is why does C++ type mechanism
              > allow you to initialize an object of type <char *> with something
              > that really is a <const char *> ?!?
              >
              > IMO that's a flaw in C++ type mechanism.[/color]

              It is, but it is there for a (once) good reason:
              For compatibility with its ancestor: C


              --
              Karl Heinz Buchegger
              kbuchegg@gascad .at

              Comment

              • Gernot Frisch

                #8
                Re: why is this bad

                >> IMO that's a flaw in C++ type mechanism.[color=blue]
                >
                > It is, but it is there for a (once) good reason:
                > For compatibility with its ancestor: C[/color]

                IMO: if it's bound to crash, it should give a warning at compile time.


                Comment

                • msalters

                  #9
                  Re: why is this bad


                  Gernot Frisch wrote:[color=blue][color=green][color=darkred]
                  > >> IMO that's a flaw in C++ type mechanism.[/color]
                  > >
                  > > It is, but it is there for a (once) good reason:
                  > > For compatibility with its ancestor: C[/color]
                  >
                  > IMO: if it's bound to crash, it should give a warning at compile[/color]
                  time.

                  It does - at least at all compilers I use. You probably have your
                  warning level set way too low - but if you're maintaining older
                  code, that may be required to ignore all the bugs in the code.
                  Regards,
                  Michiel Salters

                  Comment

                  • Andrey Tarasevich

                    #10
                    Re: why is this bad

                    William Payne wrote:[color=blue][color=green]
                    >> char* s=" ";
                    >>
                    >> int main()
                    >> {
                    >> strcpy(s, "Hello World");
                    >> }
                    >>
                    >> This program crashes nicely. I think s is a pointer to a string that is
                    >> stored in the executable memory, so the strcpy will overwrite part of the
                    >> program, right?
                    >>[/color]
                    > String literalts are really of type const char* (even though you declared
                    > yours as just char*), that's probably the reason for the crash.[/color]

                    Firstly, string literals in C++ are really of type 'const char[N+1]'
                    (where N is the length of the string), not 'const char*'

                    Secondly, casting away constness and modifying anything through a
                    pointer of type 'const char*' alone is not enough to cause a crash.
                    Whether the crash (or more formally, undefined behavior) will occur
                    depends solely on the modifiability of the object pointed by the pointer.

                    In this particular case the object pointed by the pointer is not
                    modifiable. That's why the code causes undefined behavior (manifested as
                    a crash is this case).

                    --
                    Best regards,
                    Andrey Tarasevich

                    Comment

                    • Andrey Tarasevich

                      #11
                      Re: why is this bad

                      Gernot Frisch wrote:[color=blue][color=green][color=darkred]
                      >>> IMO that's a flaw in C++ type mechanism.[/color]
                      >>
                      >> It is, but it is there for a (once) good reason:
                      >> For compatibility with its ancestor: C[/color]
                      >
                      > IMO: if it's bound to crash, it should give a warning at compile time.
                      > ...[/color]

                      It is not necessarily bound to crash. For example, forceful removal of
                      constness is a well-established implementationa l idiom in C language and
                      no one is saying that it is "bound to crash". There's no reason why it
                      should suddenly be "bound to crash" in C++. One just needs to learn to
                      use such things with proper care. The real problem here is that some
                      people use such features without even noticing, without understanding
                      what they've just done.

                      Don't get me wrong though, I'm all against this deprecated feature of
                      C++ language. I'm just against perceiving such things as something
                      necessarily "bound to crash".

                      --
                      Best regards,
                      Andrey Tarasevich

                      Comment

                      • Jack Klein

                        #12
                        Re: why is this bad

                        On Tue, 07 Dec 2004 10:44:27 GMT, "Risto Lankinen"
                        <rlankine@hotma il.com> wrote in comp.lang.c++:
                        [color=blue]
                        >
                        > "William Payne" <ericliljaNoSpa m@yahoo.com> wrote in message
                        > news:cp40d2$bq3 $1@news.island. liu.se...[color=green]
                        > >
                        > > "Gernot Frisch" <Me@Privacy.net > wrote in message
                        > > news:31lef0F39q seqU1@individua l.net...[color=darkred]
                        > > > char* s=" ";
                        > > >
                        > > > int main()
                        > > > {
                        > > > strcpy(s, "Hello World");
                        > > > }
                        > > >
                        > > > This program crashes nicely.[/color]
                        > >
                        > > String literalts are really of type const char* (even though you declared
                        > > yours as just char*), that's probably the reason for the crash.[/color]
                        >
                        > The interesting bit, of course, is why does C++ type mechanism
                        > allow you to initialize an object of type <char *> with something
                        > that really is a <const char *> ?!?
                        >
                        > IMO that's a flaw in C++ type mechanism.
                        >
                        > - Risto -[/color]

                        As others have pointed out, it is for comparability with existing C
                        code. And as for why C allowed and still allows it, there were string
                        literals in C for about 15 years before there was a 'const' keyword.

                        --
                        Jack Klein
                        Home: http://JK-Technology.Com
                        FAQs for
                        comp.lang.c http://www.eskimo.com/~scs/C-faq/top.html
                        comp.lang.c++ http://www.parashift.com/c++-faq-lite/
                        alt.comp.lang.l earn.c-c++

                        Comment

                        • Jack Klein

                          #13
                          Re: why is this bad

                          On Tue, 07 Dec 2004 11:00:41 -0800, Andrey Tarasevich
                          <andreytarasevi ch@hotmail.com> wrote in comp.lang.c++:
                          [color=blue]
                          > Gernot Frisch wrote:[color=green][color=darkred]
                          > >>> IMO that's a flaw in C++ type mechanism.
                          > >>
                          > >> It is, but it is there for a (once) good reason:
                          > >> For compatibility with its ancestor: C[/color]
                          > >
                          > > IMO: if it's bound to crash, it should give a warning at compile time.
                          > > ...[/color]
                          >
                          > It is not necessarily bound to crash. For example, forceful removal of
                          > constness is a well-established implementationa l idiom in C language and
                          > no one is saying that it is "bound to crash". There's no reason why it
                          > should suddenly be "bound to crash" in C++. One just needs to learn to
                          > use such things with proper care. The real problem here is that some
                          > people use such features without even noticing, without understanding
                          > what they've just done.
                          >
                          > Don't get me wrong though, I'm all against this deprecated feature of
                          > C++ language. I'm just against perceiving such things as something
                          > necessarily "bound to crash".[/color]

                          There is no forceful removal of "constness" involved when this code is
                          compiled as C.

                          Unlike C++, in C the type of a string literal is NOT "array of const
                          char", it is "array of char". So there is no need to remove the const
                          qualifier, because it neither exists nor is implied.

                          Attempting to modify a string literal in C is undefined behavior not
                          because the chars are const, but because the C standard specifically
                          states that it is undefined.

                          --
                          Jack Klein
                          Home: http://JK-Technology.Com
                          FAQs for
                          comp.lang.c http://www.eskimo.com/~scs/C-faq/top.html
                          comp.lang.c++ http://www.parashift.com/c++-faq-lite/
                          alt.comp.lang.l earn.c-c++

                          Comment

                          • Andrey Tarasevich

                            #14
                            Re: why is this bad

                            Jack Klein wrote:[color=blue][color=green][color=darkred]
                            >> >>> IMO that's a flaw in C++ type mechanism.
                            >> >>
                            >> >> It is, but it is there for a (once) good reason:
                            >> >> For compatibility with its ancestor: C
                            >> >
                            >> > IMO: if it's bound to crash, it should give a warning at compile time.
                            >> > ...[/color]
                            >>
                            >> It is not necessarily bound to crash. For example, forceful removal of
                            >> constness is a well-established implementationa l idiom in C language and
                            >> no one is saying that it is "bound to crash". There's no reason why it
                            >> should suddenly be "bound to crash" in C++. One just needs to learn to
                            >> use such things with proper care. The real problem here is that some
                            >> people use such features without even noticing, without understanding
                            >> what they've just done.
                            >>
                            >> Don't get me wrong though, I'm all against this deprecated feature of
                            >> C++ language. I'm just against perceiving such things as something
                            >> necessarily "bound to crash".[/color]
                            >
                            > There is no forceful removal of "constness" involved when this code is
                            > compiled as C.[/color]

                            I'm not saying that there is one in this particular code. All I'm trying
                            to say is that existence of a modification-allowing access path to
                            non-modifiable data does not necessarily lead to a problem. It is not a
                            good thing most of the time, but it has its uses.

                            --
                            Best regards,
                            Andrey Tarasevich

                            Comment

                            Working...