Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Zed A. Shaw

Rating No ratings yet

"Please don’t feel cheated, but this book is not about teaching you C programming. You’ll learn to write programs in C, but the most important lesson you’ll get from this book is rigorous defensive programming. Today, too many programmers simply assume that what they write works, but one day it will fail catastrophically. This is especially true if you’re the kind of person who has learned mostly modern languages that solve many problems for you. By reading this book and following my exercises, you’ll learn how to create software that defends itself from malicious activity and defects. I’m using C for a very specific reason: C is broken. It is full of design choices that made sense in the 1970s but make zero sense now. Everything from its unrestricted, wild use of pointers to its severely broken NUL terminated strings are to blame for nearly all of the security defects that hit C. It’s my belief that C is so broken that, while it’s in wide use, it’s the most difficult language to write securely. I would fathom that Assembly is actually easier to write securely than C. To be honest, and you’ll find out that I’m very honest, I don’t think that anybody should be writing new C code. If that’s the case, then why am I teaching you C? Because I want you to become a better, stronger programmer, and there are two reasons why C is an excellent language to learn if you want to get better. First, C’s lack of nearly every modern safety feature means you have to be more vigilant and more aware of what’s going on. If you can write secure, solid C code, you can write secure, solid code in any programming language. The techniques you learn will translate to every language you use from now on. Second, learning C gives you direct access to a mountain of legacy code, and teaches you the base syntax of a large number of descendant languages. Once you learn C, you can more easily learn C++, Java, Objective-C, and JavaScript, and even other languages become easier to learn."

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on C course that uses the language's notorious unsafety as a teaching tool for rigorous, defensive programming—best for developers from managed languages who want to understand memory, pointers, and failure modes at the metal. 【Book Arc】 - **Opening (~0%–10%)**: Frames the book's contrarian thesis—C is "broken," so learning it forces vigilance—and explains why it still makes you a stronger programmer and unlocks legacy code and descendant languages. - **Early (~10%–30%)**: Toolchain and fundamentals via short exercises: make, formatted printing, debuggers (GDB/LLDB), memorizing operators and syntax, variables, conditionals, loops, arrays, strings, functions, and the first encounter with pointers and structs. - **Early–Middle (~30%–45%)**: Memory and robustness mechanics: heap vs. stack allocation, function pointers, the author's debug macros (dbg.h), advanced debugging strategy, data types and flow control, scope/globals, Duff's Device, I/O and files, and variadic functions. - **Middle (~45%–60%)**: Building real reusable code: libraries and linking, automated testing, common undefined behavior, then data structures—doubly linked lists, list algorithms, dynamic arrays, sorting/searching, and safer strings via bstrlib. - **Late (~60%–75%)**: Higher-level structures and algorithms: hashmaps and hashmap algorithms, string algorithms, binary search trees, each paired with unit tests and "how to improve it" prompts. - **Ending (~75%+%)**: A capstone project (devpkg) that pulls the earlier pieces—libraries, I/O, data structures, testing—into one working tool; excerpts do not cover the final exercises in detail. 【Key Takeaways】 - **The real subject is defensive programming, not C syntax** (Opening): the goal is software that defends itself from defects and malicious activity, with C chosen because its lack of safety nets forces awareness. - **C's brokenness is the curriculum** (Opening): unrestricted pointers and NUL-terminated strings are presented as the root of most C security defects, so you learn to see and avoid them rather than trust the language. - **Skills transfer outward** (Opening): writing secure C is framed as training that carries into every other language, plus easier entry into C++, Java, Objective-C, and JavaScript. - **Every exercise has a "How to Break It" and "Extra Credit" loop** (Early–Middle): you are pushed to deliberately cause failures, not just make code compile and run. - **Debugging is taught as a first-class skill** (Early–Middle): debuggers, debug printing, the dbg.h macros, and a stated debugging strategy appear before advanced data structures. - **Memory layout is treated as practical knowledge** (Early–Middle): stack vs. heap allocation, scope, globals, and undefined behavior are tied directly to bugs and security. - **Data structures are built, tested, and critiqued** (Middle–Late): linked lists, dynamic arrays, hashmaps, and BSTs come with unit tests and explicit improvement suggestions. - **Testing and libraries are part of the craft** (Middle): automated testing, linking, and shared libraries are integrated rather than deferred to a separate book. 【Reading Tips】 - Do the exercises in order and actually type them; the book is designed around short, tested, runnable programs, so passive reading defeats its purpose. - Deep-read the pointer, memory, and undefined-behavior sections (roughly the early-to-middle third); these are the conceptual bottlenecks and the source of most later difficulty. - Treat "How to Break It" as mandatory, not optional—it is where the defensive-programming lesson actually lands. - Skim the operator/syntax memorization exercises if you already know C basics, but return to them as reference when later exercises assume fluency. - Use the data-structure exercises as templates: implement, test, then attempt the "How to Improve It" suggestions before moving on. 【Coverage Limits】 This guide is synthesized from stratified excerpts covering the front matter, table of contents, and exercise listings; it does not include the full body text of individual exercises, so specific code, explanations, and the final project's details are only partially represented.
Page 16
u the base syntax of a large number of descendant languages. Once you learn C, you can more easily learn C++, Java, Objective-C, and JavaScript, and even oth...
View in text
Page 6
. . . . 10 Using Make . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 What You Should See . . . . . . . . . . . . . . . . . . . . . . ....
View in text
Page 9
tors . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109 Bit Operators . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109 Boolean Operat...
View in text
Page 11
. . 185 What You Should See . . . . . . . . . . . . . . . . . . . . . . . . . . . 187 How to Improve It . . . . . . . . . . . . . . . . . . . . . . . . . . ....
View in text
Page 13
t Code . . . . . . . . . . . . . . . . . . . . . . . . . . . 316 What You Should See . . . . . . . . . . . . . . . . . . . . . . . . . . . 320 How to Break I...
View in text
Page 16
secure your code so you understand why these issues matter. You’ll learn how to cause stack overflows, illegal memory access, and other common flaws that pla...
View in text
Page 19
eginners and works very well as a first book on programming. Once you’ve completed Learn Python the Hard Way, then you can come back and start this book. For...
View in text
Page 20
code, so when faced with a language like C, they break down. The simplest thing to do is just understand that everyone has this problem, and you can fix it b...
View in text
Tags
AI categories
Programming LanguageProgramming
c/c++
Publisher: Addison-Wesley
Publish Year: 2016
Language: English
Pages: 386
File Format: PDF
File Size: 5.2 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…