CertC-EXP00

Use parentheses for precedence of operation

Required inputs: IR

C programmers commonly make errors regarding the precedence rules of C operators because of the unintuitive low-precedence levels of &, |, ^, <<, and >>. Mistakes regarding precedence rules can be avoided by the suitable use of parentheses. Using parentheses defensively reduces errors and, if not taken to excess, makes the code more readable.

Subclause 6.5 of the C Standard defines the precedence of operation by the order of the subclauses.

Noncompliant Code Example

The intent of the expression in this noncompliant code example is to test the least significant bit of x:

x & 1 == 0

Because of operator precedence rules, the expression is parsed as

x & (1 == 0)

which evaluates to

(x & 0)

and then to 0.

Compliant Solution

In this compliant solution, parentheses are used to ensure the expression evaluates as expected:

(x & 1) == 0
Exceptions

EXP00-C-EX1: Mathematical expressions that follow algebraic order do not require parentheses. For instance, in the expression

x + y * z

the multiplication is performed before the addition by mathematical convention. Consequently, parentheses to enforce the algebraic order would be redundant:

x + (y * z)
Risk Assessment

Mistakes regarding precedence rules may cause an expression to be evaluated in an unintended way, which can lead to unexpected and abnormal program behavior.

Recommendation Severity Likelihood Remediation Cost Priority Level
EXP00-C Low Probable Medium P4 L3
Related Guidelines
SEI CERT C++ Coding Standard VOID EXP00-CPP. Use parentheses for precedence of operation
ISO/IEC TR 24772:2013 Operator Precedence/Order of Evaluation [JCW]
MISRA C:2012 Rule 12.1 (advisory)
Bibliography
[ Dowd 2006] Chapter 6, "C Language Issues" ("Precedence," pp. 287-288)
[ Kernighan 1988]
[ NASA-GB-1740.13] Section 6.4.3, "C Language"
Excerpt from SEI CERT C Coding Standard: Rules for Developing Safe, Reliable, and Secure Systems (2016 Edition) and SEI CERT C Coding Standard [https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/recommendations/expressions-exp/exp00-c], Copyright (C) 1995-2026 Carnegie Mellon University. See section 9.4. "3rd-Party Licenses" in the documentation for full details.

Possible Messages

Key

Text

Severity

Disabled

missing_parens_depends_on_precedence

Parentheses should be used to avoid dependence on precedence rules

None

False

parens_duplicating_algebraic_order

Mathematical expressions that follow algebraic order do not require parentheses

None

False

Options

allow_algebraic_order

allow_algebraic_order : bool = True

Whether parens can be omitted for multiplicative operators as operands in additive operators.
 

allow_relations_in_logical

allow_relations_in_logical : bool = False

Whether parens can be omitted for relational operators in logical operators.
 

consider_assignments

consider_assignments : bool = False

Whether assignments inside expressions should be considered as well.
 

exception

exception : typing.Callable[[Expression, Expression], bool] | None = None

Programmable test if parens in physical node (1. argument) around operand (2. argument) and right, left or both sides can be omitted.