Code Review Sample checklist -Does the system compile without errors? -Do all of the functions work (has anything been stubbed out)? -Are all of the files (programs, screens, reports) and procedures used, or does the project contain things that aren’t used anymore? -Does each routine have a proper header? -Is the header updated to reflect major changes in the routine? -Are parameters described in the header? -Are required parameters checked immediately upon entering the routine, both for their presence and their data type? -Are there comments in the code? A good rule of thumb for knowing when there are “enough” comments in the code is to remove the code and just read the comments. Is it still clear what the routine is doing? -Do the comments explain why? -Is the code formatted with indenting and white space? -Does each logic structure check for the “in all other cases” structure? -Are variables named consistently and according to your standards? -Are long or complex calculations commented? -Are there complex nestings—many levels deep, or structures that look very elaborate? -Are there comments that indicate code has been modified (this is good, by the way)? -Are there chunks of code that have been commented out (with no explanation of why the code was left in place)? -Is a return value always returned? -Are all possible return values of the same data type? -Are string comparisons handled properly—both with respect to exactness and case? -Are file locations hard-coded or is the application portable? -Are similar but not identical functions used as if they were interchangeable? -Does arithmetic performed on dates handle the turn of the millennium gracefully? -Are divisors tested for zero? -Are variables initialized? -Does the code contain “magic numbers,” or are they 1) explained, or 2) DEFINED as appropriate for the language? -Are there blocks of repetitious code? -Can custom code be replaced by common code or library functions? -Is code in the proper place in the hierarchy of the call stack? -Are variables scoped and released when appropriate? -Are the more common cases tested first in logic structures? -Do routines have one exit or does each exit call a single termination routine? -Is the code contained within loops absolutely necessary? -Are external device accesses trapped appropriately? -Are files checked for existence (before creating, writing, or updating)? -Is the environment returned to the same state at the end of the routine? -Is there an implicit target environment (development language, operating system, machine/hardware)? * eof