mirror of
https://github.com/cjcliffe/CubicSDR.git
synced 2026-10-08 08:10:26 -04:00
1.8 KiB
1.8 KiB
Plan: Remove MSVC C4996 Suppression
See also: RECOMMENDATIONS.md | PLAN.md
Current State
Line 712 of CMakeLists.txt:
ADD_DEFINITIONS(/wd"4996")
This globally suppresses all "This function or variable may be unsafe" warnings from MSVC CRT. This hides potential buffer overflow risks from functions like sprintf, strcpy, strcat, etc.
Implementation Plan
- Remove the
/wd4996suppression fromCMakeLists.txt. - Build the project and catalog all C4996 warnings (file, line, function).
- For each occurrence, replace with the safe variant:
sprintf→snprintfstrcpy→strncpyorstd::stringoperationsstrcat→strncatorstd::stringoperationssscanf→ use bounds-checked alternatives
- If any third-party/vendored code triggers C4996, suppress it locally with
#pragma warning(disable: 4996)around just that code, not globally. - Re-enable the warning globally and verify a clean build.
Verification Criteria
/wd4996is removed fromCMakeLists.txt.- MSVC build produces zero C4996 warnings in project source code.
- Third-party/vendored code uses local
#pragma warning(disable: 4996)if needed. - No buffer overflow or unsafe function regressions introduced.
Rollback Strategy
If the C4996 fixes introduce behavioral changes (e.g., snprintf vs sprintf edge cases):
git revertthe commit.- Re-add
/wd4996toCMakeLists.txtto restore the suppressed build. - Consider fixing warnings incrementally (one file at a time) rather than all at once.
Files to Modify
| File | Action |
|---|---|
CMakeLists.txt |
Remove /wd4996 |
| Various source files | Replace unsafe CRT functions (exact count TBD after unsuppressing) |