V3508. AUTOSAR. Unbounded functions performing string operations should not be used.

This diagnostic rule is based on the software development guidelines developed by AUTOSAR (AUTomotive Open System ARchitecture).

The analyzer issues the warning when it detects the following functions:

  • strcpy;
  • strcmp;
  • strcat;
  • strchr;
  • strspn;
  • strcspn;
  • strpbrk;
  • strrchr;
  • strstr;
  • strtok;
  • strlen.

Incorrect use of these functions may result in undefined behavior since they do not perform bound checking when reading from or writing to the buffer.

Here is an example of code triggering this warning:

int strcpy_internal(char *dest, const char *source)
  int exitCode = FAILURE;
  if (source && dest)
    strcpy(dest, source);
    exitCode = SUCCESS;

  return exitCode;

This diagnostic is classified as:

  • AUTOSAR-M18.0.5

Bugs Found

Checked Projects
Collected Errors
14 526
This website uses cookies and other technology to provide you a more personalized experience. By continuing the view of our web-pages you accept the terms of using these files. If you don't want your personal data to be processed, please, leave this site. Learn More →