7

strlen returns the number of characters that precede the terminating null character. An implementation of strlen might look like this:

size_t strlen(const char * str)
{
    const char *s;
    for (s = str; *s; ++s) {}
    return(s - str);
}

This particular implementation dereferences s, where s may contain indeterminate values. It's equivalent to this:

int a;
int* p = &a;
*p;

So for example if one were to do this (which causes strlen to give an incorrect output):

char buffer[10];
buffer[9] = '\0';
strlen(buffer); 

Is it undefined behavior?

1
  • 1
    @user2864740 are you sure that the string must contain some value? Isn't C allowed to happily crash on a read-before-write? Commented Sep 12, 2014 at 1:27

4 Answers 4

4

Calling the standard function strlen causes undefined behaviour. DR 451 clarifies this:

library functions will exhibit undefined behavior when used on indeterminate values

For a more in-depth discussion see this thread.

Sign up to request clarification or add additional context in comments.

8 Comments

My comment below refers to the poster's implementation of a strlen function. Agree that the standard library has other constraints or liberties.
@KC-NH updated my post to clarify that I'm talking about the standard strlen function, not OP's pseudo-implementation.
A DR and the committees reply to it is not normative, and for the particular case here, you are citing things out of context. The phrase that you are citing is the answer to a question which is if passing undetermined values to a library "can" have undefined behavior. The DR you are citing actually shows that the question is relatively complex and does lead to easy answers as this one.
@JensGustedt well, we could say "The standard is unclear but DR 451 provides the committee's opinion on the matter". I don't think the quote is out of context; but anyone with doubts can and should read DR 451 in full
@MattMcNabb, that's not my point. I think that pointing to the DR is largely irrelevant here, since it discusses the stability of unspecified values. The presented code, here, only reads each byte once, so stability is not an issue. See my answer for an in depth analysis of the code as it is presented, here.
|
2

The behavior of the variant that you are showing is well defined under these circumstances.

  • The bytes of the uninitialized array have all indeterminate values, with exception of the 10th element that you set to 0.
  • Accessing an indeterminate value would only be UB if the address of the underlying object would be never taken or if the value is a trap for the corresponding type.
  • Since this is an array and access to array elements is through pointer arithmetic, the first case is not relevant, here.
  • Any char value can be accessed without UB, the clauses about trap representations in the standard explicitly exclude all character types from that.
  • Thus the values that you are dealing with are simply "unspecified".
  • Reading unspecified values may according to some members of the C standards committee give different results each time, what some call a "whobly" state or so. This property is not relevant, here, since your function reads any such value at most once.
  • So your access to the array elements gives you any arbitrary but valid char value.
  • You are sure that your for loop stops at latest at position 9, so you will not overrun your array.

So no "bad" things beyond the visible may happen if you use your specific version of the function. But having a function call that produces unspecified results is certainly nothing you want to see in real code. Something like this here leads to very subtle bugs, and you should avoid it by all means.

Comments

1

No, it's not undefined behavior. Your strlen function will stop before the end of the buffer. If your strlen function referenced buffer[10], then, yes that is undefined.

It certainly will be unexpected behavior, since most of buffer contains random data. "Undefined" is special word for people writing language standards. It means that anything could happen, including memory faults or exiting the program. By unexpected, I mean that it sure not what the programmer wanted to happen. On some runs, the result of strlen could be 3 or it could be 10.

Comments

0

Yes, it's undefined behaviour. From the draft C11 standard, §J.2 "Undefined behavior":

The behavior is undefined in the following circumstances:

...

The value of an object with automatic storage duration is used while it is indeterminate.

2 Comments

This code doesn't actually use the indeterminate values (buffer is not indeterminate, but buffer[0] is). However, strlen uses the values. Also, this annex is non-normative (it's supposed to be a sort of index to find various cases of UB). The normative text is more detailed and has some exceptions for when indeterminate use is not UB.
The object is not only "indeterminate" but the values are just "unspecified", so nothing bad can happen.

Your Answer

By clicking “Post Your Answer”, you agree to our terms of service and acknowledge you have read our privacy policy.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.