C protocol development
C gives direct control over bytes, memory and native interfaces. Check buffer limits, ownership and error paths, then compile and test for the intended target.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
ISO standard text is paywalled; implementation guidance uses public secure coding sources and a deliberate C17 compatibility baseline
On this page
Overview#
C is used selectively when embedded constraints, vendor SDKs, or serial/binary protocols make it representative. ISO/IEC 9899:2024 (C23) is the current published C edition; this guide deliberately uses C17 as a broad compatibility baseline for long lived embedded and vendor toolchains. Record the selected edition, compiler, ABI, target, library, and vendor SDK requirements for every implementation.
Parsing baseline#
- Use fixed width integer types for wire values.
- Validate buffer length before every read and output capacity before every write.
- Check addition and multiplication for overflow before offsets or allocation.
- Decode endian values byte wise or through reviewed helpers; don't cast unaligned wire buffers to structs.
- Bound counters, recursion, TLVs, strings, nesting and allocation.
- Use explicit state enums and reject messages invalid for the current role/session.
- Treat CRC/checksum as corruption detection, not source authentication.
Resource and lifetime rules#
Define one owner for every allocation, file descriptor, socket, timer, mutex and SDK handle. Initialize cleanup state, use one auditable cleanup path where suitable, clear sensitive buffers with a mechanism the compiler won't optimise away, and don't use unbounded string or memory operations.
Concurrency and callbacks#
Document callback thread, buffer ownership and lifetime. Avoid calling complex integration logic or blocking I/O from an ISR/vendor callback. Transfer bounded immutable work to a controlled queue and define overflow behaviour.
Environment assurance#
Apply strict compiler warnings, static analysis, address/undefined behaviour sanitizers on supported hosts, and synthetic boundary fixtures. Record the exact compiler/tool versions, target/ABI, options, fixture digest, observations, and limitations with the integration evidence.
Sources#
- SEI C, SEI CERT C Coding Standard, public secure coding guidance, accessed 25 August 2026.
- ISO C23, ISO/IEC 9899:2024 catalogue entry, current published C edition; paywalled standard metadata, accessed 25 August 2026.
- ISO C17, ISO/IEC 9899:2018 catalogue entry, paywalled standard metadata, accessed 25 August 2026.