Function pointers store the address of a function, not the function itself
Syntax: int (ptr)(int, int) — parentheses around ptr are mandatory
Use typedef to make function pointer types readable
Callbacks allow passing a function as an argument — used in qsort, event handlers
Dispatch tables replace long switch/if-else chains with an array of function pointers
Biggest pitfall: calling a NULL function pointer causes a segfault — always check before calling
✦ Definition~90s read
What is Function Pointers in C?
A function pointer is a variable that stores the memory address of a function, allowing you to call that function indirectly through the pointer. In C, functions themselves are not first-class objects—you can't pass them around or store them directly—but function pointers give you that capability.
★
Imagine you hire a contractor and instead of telling them exactly how to do every step, you hand them a card with a phone number to call when they finish a task — whoever answers decides what happens next.
They exist because embedded systems and low-level code often need dynamic dispatch: deciding at runtime which function to execute, without the overhead of a virtual machine or runtime type system. The cost is a single indirection through the pointer, which on ARM Cortex-M or AVR microcontrollers is typically 2–4 cycles and zero additional RAM beyond the pointer itself.
Function pointers solve real problems in constrained environments. They replace long if-else or switch chains with dispatch tables—arrays of function pointers indexed by an enum or integer—which are faster, more maintainable, and easier to extend. They enable callback mechanisms like qsort's comparator argument, where a generic sorting function calls back into your code without knowing your data types.
They also let C approximate object-oriented patterns: putting function pointers inside structs creates virtual method tables (vtables) that mimic polymorphism, used extensively in real-time operating systems like FreeRTOS (task control blocks) and in hardware abstraction layers (HALs) from STM32 and NXP.
But function pointers come with sharp edges. The most dangerous is the NULL crash: calling a function pointer that hasn't been initialized or has been set to NULL. On bare-metal embedded systems, there's no OS to catch the segfault—the processor jumps to address 0x00000000, which is typically the reset vector or unmapped memory, causing a hard fault or watchdog reset.
This is a common bug in state machine implementations and callback registrations where a pointer is declared but never assigned. The fix is defensive: always initialize function pointers to a safe default (like a no-op function), validate them before calling, and use static analysis tools (e.g., PC-lint, Coverity) to catch uninitialized paths.
When you need dynamic dispatch but can't afford the risk, consider alternatives like jump tables (computed goto in GCC) or explicit state enums with switch statements—though those lose the flexibility of runtime-replaceable handlers.
Plain-English First
Imagine you hire a contractor and instead of telling them exactly how to do every step, you hand them a card with a phone number to call when they finish a task — whoever answers decides what happens next. A function pointer is that phone number. It's not the function itself; it's the address where the function lives in memory, so you can hand it to someone else and say 'call this when you're ready.' This lets your code be flexible — the same contractor can call your plumber, your electrician, or your interior designer depending on what card you give them.
Every non-trivial C program eventually hits a wall: you need a piece of code to behave differently depending on context, but you don't want to litter your logic with a dozen if-else branches. Sort algorithms need comparison logic. Event loops need to dispatch to different handlers. Plugin systems need to call code that didn't exist when the core was compiled. In every one of these cases, function pointers are the tool C gives you — and understanding them is what separates C programmers who write clever hacks from those who write clean, extensible systems.
The problem function pointers solve is simple: in C, functions are not first-class values you can pass around the way you'd pass an integer. But their addresses are. A function pointer stores that address, which means you can store a function in a variable, pass it as an argument, return it from another function, or keep a whole table of them. This is how the C standard library's qsort works, how operating system kernels register interrupt handlers, and how game engines implement entity behavior without a class hierarchy.
By the end of this article you'll be able to declare and call function pointers without second-guessing the syntax, build a working callback system, construct a dispatch table that replaces a cascade of if-else statements, and spot the two errors that burn every developer the first time they use function pointers in production code.
What a Function Pointer Actually Is
A function pointer stores the address of a function in memory, allowing you to call that function indirectly through the pointer. In C, a function name decays to a pointer to the function's entry point, just as an array name decays to a pointer to its first element. The declaration syntax mirrors the function signature: return_type (*ptr_name)(parameter_types). This indirection is the core mechanic — you can pass functions as arguments, store them in arrays, or assign them at runtime. Function pointers have a fixed size (typically 4 or 8 bytes, matching the platform's pointer width) and can be compared for equality. Dereferencing a NULL function pointer causes an immediate crash — often a hard fault on embedded systems — because the processor jumps to address zero. This is not a recoverable error; it's a silent, catastrophic failure. Use function pointers when you need runtime polymorphism without C++ overhead: callback registration, state machines, command dispatch tables, or plugin architectures. In embedded firmware, they are essential for decoupling hardware drivers from application logic — for example, a timer driver that calls a user-defined callback on overflow. The cost is one extra indirection per call (negligible on most MCUs) and the risk of NULL dereference if not validated.
⚠ NULL Function Pointer = Hard Fault
Calling a NULL function pointer does not return an error — it jumps to address 0x00000000, triggering an immediate hard fault on ARM Cortex-M and most embedded targets.
📊 Production Insight
A production UART driver stored a callback pointer in a struct; a race condition in initialization left it NULL. The first interrupt fired, jumped to zero, and locked the system with no log output.
Symptom: system hangs silently on first UART RX interrupt — no crash dump, no watchdog reset because the fault handler was not configured.
Rule: Always initialize function pointers to a safe default (e.g., a no-op function) and validate non-NULL before calling in interrupt context.
🎯 Key Takeaway
A function pointer is just an address — calling a NULL pointer is a jump to zero, not a function call.
Validate function pointers before calling them, especially in interrupt handlers or callback dispatch loops.
Use function pointers for runtime polymorphism in C, but prefer static dispatch when the target function is known at compile time.
thecodeforge.io
Function Pointers C
Declaring and Calling a Function Pointer — Getting the Syntax Right Once and For All
The syntax for function pointers trips people up because the asterisk belongs to the name, not the return type. Read the declaration from the inside out: the name of the variable is in the middle, wrapped in parentheses with an asterisk, and the surrounding parts describe what function signature it can point to.
For a function that takes two ints and returns an int, the pointer type is: int (operation)(int, int). That parentheses around operation is mandatory — without it, int operation(int, int) is a completely different thing: a function named operation that returns int .
Once you have the pointer, calling it is straightforward. Modern C allows you to call it directly as operation(a, b) — the compiler knows it's a pointer and handles the dereference. The older explicit-dereference syntax (*operation)(a, b) also works and makes the pointer nature more obvious. Both styles are valid; pick one and be consistent within a codebase.
function_pointer_basics.cC
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
#include <stdio.h>
/*
* io.thecodeforge naming convention applied to math operations
* All share the signature: (int, int) -> int
*/
inttcf_add(int a, int b) { return a + b; }
inttcf_subtract(int a, int b) { return a - b; }
inttcf_multiply(int a, int b) { return a * b; }
// Typedef makes the syntax human-readable
typedef int (*MathOperation)(int, int);
intmain(void) {
// Pointerassignment (no & required, though valid)
MathOperation operation = tcf_add;
printf("tcf_add(10, 4) = %d\n", operation(10, 4));
operation = tcf_subtract;
printf("tcf_subtract(10, 4) = %d\n", operation(10, 4));
operation = tcf_multiply;
printf("tcf_multiply(10, 4) = %d\n", operation(10, 4));
return0;
}
Output
tcf_add(10, 4) = 14
tcf_subtract(10, 4) = 6
tcf_multiply(10, 4) = 40
💡Pro Tip: Always typedef your function pointer types
Writing typedef int (*MathOperation)(int, int) once means every subsequent use is just MathOperation. When this type appears in a struct, a parameter list, and a return type — and it will — you'll be very glad you did. It also makes the code self-documenting: MathOperation communicates intent far better than the raw pointer syntax.
📊 Production Insight
In production, the most common failure is assigning a function pointer without matching the signature.
The compiler does not check the signature unless you use typedef and -Werror.
Always use typedef and compile with -Werror=incompatible-pointer-types to catch mismatches at compile time.
🎯 Key Takeaway
Read function pointer declarations inside-out: the name with the asterisk is in the middle.
Typedef your function pointer types immediately — one line that prevents entire classes of bugs.
Call syntax is flexible: ptr(args) or (*ptr)(args) — be consistent.
Callbacks — Passing Functions as Arguments the Way qsort Does
A callback is nothing more than a function pointer you pass to another function so that function can call yours at the right moment. It's the foundational pattern behind event-driven systems, custom sorting, plugin architectures, and async I/O notification.
The C standard library's qsort is the example every C programmer meets first. You hand qsort your array and a comparator — a function pointer that tells qsort how to decide which of two elements is 'less than' the other. qsort doesn't care what you're sorting or how you define order; it just calls your comparator whenever it needs to compare two elements.
Building your own callback-based API follows the same pattern. You design a function that accepts a function pointer parameter. Callers provide different functions to customize behavior. Your core logic stays untouched.
callback_pattern.cC
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
#include <stdio.h>
#include <stdlib.h>
namespace io_thecodeforge {
typedef struct {
char name[32];
int score;
} TcfPlayer;
// Comparatorfor qsort: descending order
inttcf_compare_descending(constvoid *a, constvoid *b) {
constTcfPlayer *pa = (constTcfPlayer *)a;
constTcfPlayer *pb = (constTcfPlayer *)b;
return pb->score - pa->score;
}
// Predicate callback type
typedef int (*TcfPredicate)(constTcfPlayer *p);
voidtcf_filter_players(TcfPlayer *list, int n, TcfPredicate should_print) {
for (int i = 0; i < n; i++) {
if (should_print(&list[i])) {
printf(" %s: %d\n", list[i].name, list[i].score);
}
}
}
inttcf_is_pro(constTcfPlayer *p) { return p->score >= 90; }
}
intmain(void) {
using namespace io_thecodeforge;
TcfPlayer team[] = {{"Alice", 95}, {"Bob", 45}, {"Charlie", 92}};
int n = 3;
qsort(team, n, sizeof(TcfPlayer), tcf_compare_descending);
printf("Pro Players Only:\n");
tcf_filter_players(team, n, tcf_is_pro);
return0;
}
Output
Pro Players Only:
Alice: 95
Charlie: 92
🔥Interview Gold: Why does qsort take void* parameters?
qsort was written to sort any type — ints, structs, strings. Because C has no generics, it uses void to accept a pointer to anything. Your comparator receives void and must cast to the concrete type it expects. This is safe because you know what you put in the array — the type information lives with the caller, not with qsort.
📊 Production Insight
Callbacks in production often cause issues when the callback pointer is invalidated (e.g., after module unload).
Always manage callback lifetimes: register and deregister pairs, and use weak references if possible.
A common production bug: passing a callback from a dynamically loaded library that gets unloaded, then calling the callback — immediate segfault.
🎯 Key Takeaway
qsort demonstrates the power of callbacks: algorithms become reusable.
Callback receivers must handle NULL pointers gracefully.
Callback providers must ensure the pointer remains valid — use registration/deregistration pairs.
thecodeforge.io
Function Pointers C
Dispatch Tables — Replacing if-else Chains With an Array of Function Pointers
Once you can store a function pointer in a variable, you can store them in an array. An array of function pointers is called a dispatch table (or jump table), and it's one of the most useful patterns in systems programming.
Consider a simple calculator that handles four operations. The naive approach is a chain of if-else or a switch statement. That works for four operations, but what about forty? You'd have forty branches, and adding a new operation means touching the dispatcher every single time.
A dispatch table maps an index (or enum value) directly to a function. Adding a new operation is adding one entry to the table. The dispatcher doesn't change at all.
💡Pro Tip: Dispatch tables scale where switch statements don't
A switch statement with 50 cases is unreadable. A dispatch table with 50 entries is just a list — you can sort it, load it from a config file, or build it at runtime. In performance-critical code, a table lookup is often faster than a long branch chain.
📊 Production Insight
Dispatch tables are fast, but they are static. Changing behavior at runtime requires reloading the table.
In production, ensure thread safety when the table is updated concurrently — use a mutex or RCU.
A common mistake: forgetting to terminate the table with a sentinel, causing out-of-bounds access.
🎯 Key Takeaway
Dispatch tables are the C way of doing polymorphism — map an enum to a function.
They scale linearly with the number of cases, unlike switch statements.
Always validate the index before accessing the table to avoid out-of-bounds crashes.
Function Pointers in Structs — How C Fakes Object-Oriented Design
If you put function pointers inside a struct, the struct gains behavior — it's not just data anymore. This is exactly how C++ implements virtual functions under the hood (the vtable).
This pattern works by defining a struct that holds function pointer fields. Different 'instances' can point their pointers at different implementations. Code that operates on the struct calls the function through the pointer without knowing which implementation it's talking to.
This matters because C is used where C++ isn't an option — microcontrollers and kernels. Knowing how to build a clean interface with function pointers lets you write reusable C code rather than copying logic for every new variant.
🔥Interview Gold: This is exactly how C++ vtables work
When you declare a virtual function in C++, the compiler generates a vtable (dispatch table) and a vptr (hidden pointer) in every object. Calling a virtual function is just dereferencing that pointer. Knowing this explains the 'cost' of virtual functions: one extra pointer dereference.
📊 Production Insight
Structs with function pointers are powerful but fragile — a missing initializer leaves the pointer unset.
Always provide an init function that fills in all function pointers, or use designated initializers.
In production, consider using a const vtable pointer shared across instances to save memory.
🎯 Key Takeaway
Function pointers in structs give you polymorphism without inheritance.
Always initialize all function pointers in a struct — incomplete initialization is a time bomb.
This pattern is used in Linux device drivers, embedded RTOS, and many firmware frameworks.
State Machines with Function Pointers — Clean Event Handling Without Switch Statements
State machines are everywhere — protocol handlers, UI navigation, game states. The textbook approach uses a switch statement with a state variable. That works, but as states grow, the switch becomes a maintenance nightmare. Function pointers offer a cleaner alternative: each state is a function, and the state machine's current state pointer is a function pointer. Transitioning to a new state is as simple as reassigning the pointer.
This pattern is common in embedded systems where memory is tight and you need deterministic timing. Each state function receives events and returns the next state function pointer. The main loop simply calls the current state function in a tight loop, consuming no additional stack depth.
Implementing this avoids the risk of missing a state in a switch, keeps state logic isolated, and makes adding new states trivial — just write a new function and register it.
💡Pro Tip: State machine with function pointers eliminates the switch
Each state is a separate function with full visibility into its own logic. Transitions are explicit and traceable. This pattern is standard in automotive and aerospace code where state machines are large and must be verified.
📊 Production Insight
Function pointer state machines are fast but can be tricky to debug because the call stack doesn't show a state variable.
Use a debug hook that prints the current state function name on each transition.
Watch out for infinite loops if a state function forgets to update the next pointer — the machine hangs.
🎯 Key Takeaway
State machines implemented with function pointers are cleaner than giant switch statements.
Each state is a function, transitions are pointer assignments.
Always initialize the next state before returning — unassigned next leads to a stuck state machine.
Where Functions Live — The Address You Never Knew You Needed
Every function you write sits in memory at a specific address. Just like a variable, a function name without parentheses evaluates to its entry point. This isn't trivia — it's the whole reason function pointers exist. When you write multiply instead of multiply(), you're grabbing an address, not calling anything.
Competitor tutorials love to show you the syntax, but they skip the why. The address lets you store, pass, and invoke logic at runtime. That's what turns static C code into something dynamic. You don't need classes for polymorphism; you just need a pointer-sized value that points to executable instructions.
If you're debugging a crash and the callstack points to garbage, it's often because someone corrupted a function pointer. Know the address. Trust nothing.
AddressDemystified.cppCPP
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
// io.thecodeforge — c-cpp tutorial
#include <stdio.h>
voidgreet() {
printf("Hello from greet!\n");
}
intmain() {
// Function name without parentheses = addressprintf("greet lives at: %p\n", greet);
// Same address via explicit & operatorprintf("greet address: %p\n", &greet);
void (*fn)() = greet;
fn(); // call via pointer
(*fn)();// explicit dereference — both workreturn0;
}
Output
greet lives at: 0x100003f4b0
greet address: 0x100003f4b0
Hello from greet!
Hello from greet!
⚠ Production Trap:
Never cast a function pointer to void* and back. The C standard doesn't guarantee it works. On some architectures like CHERI or systems with pointer authentication, this will blow up at runtime.
🎯 Key Takeaway
A function name without parentheses is just an address — treat it like any other pointer, because that's exactly what it is.
Function Pointers in C++ — The Same Beast, Sharper Teeth
C++ inherits C's function pointers wholesale, but the language adds a layer of complexity that'll bite you if you're careless. Member function pointers? Different syntax, different cost. Lambdas? They can decay to function pointers, but only if they capture nothing — otherwise you're looking at std::function and heap allocations.
The core semantics haven't changed: a function pointer is still just an address. But C++ templates, overloads, and namespaces mean you can't always grab an address with just the bare name. You might need & explicitly to disambiguate an overloaded function. If you see "reference to overloaded function could not be resolved", that's your cue.
Bottom line: every trick you learned in C works here. The hazards come from C++ features that pretend to be simpler than they are. Test your assumptions with std::is_same or a static_assert — let the compiler tell you the truth.
Use auto to store member pointers: auto action = &Server::start;. The compiler deduces the correct type every time, and you avoid the esoteric (svr.*ptr)() syntax confusion.
🎯 Key Takeaway
C++ member function pointers require the & operator and a special call syntax — they are not interchangeable with free function pointers.
Function Pointers for Plugin Systems — Loading Unknown Code at Runtime
Static linking is for people who rebuild their entire product to add one feature. Real systems load functionality at runtime via dynamic libraries. Function pointers are the glue that makes this possible.
When you call dlopen() on a shared object, the OS hands you a handle. You then use dlsym() to pluck a function by name out of that binary blob. The symbol resolves to a memory address — exactly the same kind of address you'd get from &myFunction. Cast that to the correct function pointer type, and you're calling code that didn't exist when your program was compiled.
This is how game engines load mods, how editors support plug-ins, and how production servers swap logging backends without restart. The contract is simple: the plugin exposes a function with a known signature, usually int init(plugin_api* api). Your host calls it through a pointer. No headers, no recompilation. Just a void pointer cast and a handshake.
Memory management is your problem. The plugin's code stays in RAM until you call dlclose(). Keep the handle around if you plan to unload later — dangling function pointers are a crash just waiting for a holiday weekend.
Never cast a function pointer through void* on POSIX. The C standard says it's undefined behavior. Use a union or memcpy the bytes. Real-world code does it anyway because every compiler allows it, but don't act surprised when a static analyzer flags it.
🎯 Key Takeaway
Function pointers let you invoke code that didn't exist at compile time. dlopen + dlsym is your backdoor for plugin loading.
Polymorphism Without the vtable — Manual Dispatch in Embedded Systems
C++ vtables are a luxury. They cost memory per class, per instance. When your firmware has 2KB of RAM, you can't afford that. So you build polymorphism by hand with function pointers embedded in structs — one pointer per method, one table per object.
You define a struct with data and one function pointer per operation. A 'constructor' function fills those slots, then returns the struct. Each 'method' takes a pointer to that struct as its first argument — hello, this. The caller doesn't know whether it's talking to a UART driver or a SPI driver. It just calls dev->write(dev, buffer, len) through the pointer.
No casting, no inheritance, no virtual dispatch overhead. The function pointer is a direct jump. Compare that to a switch on device type, which the compiler may or may not optimize into a jump table. Manual dispatch always wins on worst-case latency. This is why every RTOS scheduler uses function pointers for task entry points.
The tradeoff: you type out the dispatch table yourself. No compiler-generated wrappers. But you also see exactly how much flash each virtual call costs. In constrained environments, that transparency is worth more than syntactic sugar.
Use a single function pointer per 'virtual method', not one per call site. Group them in a vtable struct and have each object point to one vtable. Saves 4 bytes per pointer times the number of methods — huge on 8-bit micros.
🎯 Key Takeaway
Structs with function pointers give you manual polymorphism with zero vtable overhead. Embedded systems use this instead of C++ because they control every byte of flash.
● Production incidentPOST-MORTEMseverity: high
NULL Function Pointer in Embedded Firmware
Symptom
Device crashes immediately when a specific task runs. No error message, just a reset. The crash log shows a hard fault at address 0x00000000.
Assumption
The function pointer was initialized at startup, but a code path skipped initialization under certain conditions.
Root cause
A conditional branch in the initialization code did not set the function pointer because a configuration flag was missing. The pointer remained NULL (zero). When the task dispatch attempted to call the function, the CPU jumped to address 0, causing a hard fault.
Fix
Initialize all function pointers to a safe default handler (a no-op function) at declaration. Add a NULL check before every call: if (handler) handler(); else default_handler();.
Key lesson
Always initialize function pointers to a safe default, not just NULL.
Add a NULL guard before every function pointer call — it costs one branch and prevents hard-to-diagnose crashes.
Treat uninitialized function pointers as undefined behavior — they will crash eventually.
Production debug guideSymptom → Action guide for diagnosing function pointer failures in C code4 entries
Symptom · 01
Segfault when calling through a function pointer
→
Fix
Check if the pointer is NULL. In GDB: print ptr — if 0x0, look for missing initialization. Use a conditional breakpoint to catch the assignment.
Symptom · 02
Correct behavior sometimes, wrong behavior other times (non-deterministic)
→
Fix
Likely a dangling pointer to a function that went out of scope (e.g., function defined in another translation unit that was unloaded). Check that the function's address is still valid. In embedded: confirm the function resides in a non-overwritten code section.
Symptom · 03
Stack corruption after calling through a function pointer
→
Fix
The function pointer signature does not match the actual function. Check the number and types of arguments and return value. Use typedef and compile with -Werror to catch mismatches.
Symptom · 04
Program crashes only on release build, not debug
→
Fix
Optimizer may have inlined or removed the function pointer. Use volatile on the pointer or disable optimization for that file. Alternatively, check that the pointer is not optimized away.
★ Quick Debug Cheat Sheet for Function PointersWhen a function pointer call crashes, use these commands to diagnose the problem fast.
Segfault on function pointer call−
Immediate action
Run GDB and inspect the pointer value.
Commands
print my_func_ptr
info functions my_func_ptr (to see if the target function exists in symbol table)
Fix now
Add a NULL check before the call: if (my_func_ptr) my_func_ptr();
Unexpected behavior, pointer seems valid+
Immediate action
Check the function signature at the call site vs the definition.
Commands
ptype my_func_ptr (in GDB to see the declared type)
whatis target_function (to see the actual function type)
Fix now
Ensure the signature matches exactly. Use typedef to enforce consistency.
Dangling pointer after module unload+
Immediate action
Verify the function is still loaded in memory.
Commands
info sharedlibrary (to see loaded shared objects)
disassemble target_function (to see if code is there)
Fix now
Deregister function pointers when unloading a module. Use a weak symbol or dynamic registration with a removal callback.
Aspect
Function Pointer
Direct Function Call
Flexibility
Runtime decision — any matching function
Compile-time decision — fixed function
Performance
One extra pointer dereference (negligible)
Inlineable — zero overhead possible
Syntax complexity
Requires careful declaration and typedef
Straightforward, no extra setup
Use case
Callbacks, plugins, dispatch tables, polymorphism
Known, fixed behavior — most code
Debuggability
Harder — must inspect pointer value in debugger
Easy — function name visible in call stack
Null risk
Calling NULL pointer = crash (undefined behavior)
No null risk — call site is always resolved
Testability
Easy to swap implementations in tests
Requires wrapping or recompiling to mock
⚙ Quick Reference
9 commands from this guide
File
Command / Code
Purpose
function_pointer_basics.c
/*
Declaring and Calling a Function Pointer
callback_pattern.c
namespace io_thecodeforge {
Callbacks
dispatch_table.c
typedef void (*TcfHandler)(const char *arg);
Dispatch Tables
tcf_polymorphism.c
typedef struct TcfLogger TcfLogger;
Function Pointers in Structs
state_machine_fp.c
typedef struct TcfEvent TcfEvent;
State Machines with Function Pointers
AddressDemystified.cpp
void greet() {
Where Functions Live
CppMemberPtr.cpp
struct Server {
Function Pointers in C++
Plugin.cpp
typedef int (*plugin_init_t)(int version);
Function Pointers for Plugin Systems
Device.cpp
struct Device {
Polymorphism Without the vtable
Key takeaways
1
The asterisk in a function pointer declaration belongs to the name, not the return type
int (op)(int, int) is a pointer to a function; int op(int, int) is a function that returns a pointer.
2
typedef your function pointer types immediately
it's one line of investment that makes every struct, parameter list, and return type that uses the type readable and maintainable.
3
A dispatch table (array of function pointers keyed by a command name or enum value) is the clean alternative to long switch or if-else chains
adding a new case means adding one table entry, not touching dispatcher logic.
4
Function pointers inside structs give you runtime polymorphism in C
the same mechanism the Linux kernel uses for device drivers and that C++ compilers use to implement virtual functions via vtables.
5
Always check for NULL before calling a function pointer
a single uninitialized pointer can crash your entire system.
Common mistakes to avoid
3 patterns
×
Missing parentheses around the pointer name in declaration
Symptom
Writing int handler(int) instead of int (handler)(int). The compiler treats it as a function returning an int pointer, not a pointer to a function. The code compiles but calling handler(5) or dereferencing incorrectly causes undefined behavior.
Fix
Always wrap (*name) to ensure the asterisk modifies the variable name, not the return type. Use a typedef to avoid repeating the complex syntax.
×
Calling a NULL function pointer
Symptom
Uninitialized or reset pointers contain garbage or zero. Calling them causes a Segfault or HardFault immediately. In production, this is the number one source of crashes in code using function pointers.
Fix
Always initialize pointers to NULL and verify before execution: if (ptr) ptr(args);. Consider providing a default no-op function for empty states.
×
Signature mismatch when casting function pointers
Symptom
Forcing a void ()(int) function into a void ()(float) pointer via a cast. The code may compile with a warning, but calling it corrupts the stack because the arguments are interpreted differently.
Fix
Ensure the function signature exactly matches the typedef or the expected type. Never cast function pointers across incompatible signatures. Use compiler flags to enforce strict type checking.
INTERVIEW PREP · PRACTICE MODE
Interview Questions on This Topic
Q01JUNIOR
What is the difference between `void *f(int)` and `void (*f)(int)`?
Q02SENIOR
How would you implement a 'Plug-and-Play' driver architecture in C?
Q03SENIOR
Why is qsort's comparator function signature `int (*)(const void*, const...
Q04SENIOR
Explain the memory overhead and performance impact of using function poi...
Q01 of 04JUNIOR
What is the difference between `void *f(int)` and `void (*f)(int)`?
ANSWER
The first is a function declaration: f is a function taking an int and returning a void pointer. The second is a pointer to a function: f is a variable that can hold the address of a function taking an int and returning void. In the second case, you need to assign an actual function before calling f(5).
Q02 of 04SENIOR
How would you implement a 'Plug-and-Play' driver architecture in C?
ANSWER
Define an interface struct containing function pointers for init, read, write, and close. Each driver provides an instance of this struct with its own implementations. A central registry holds an array of such structs. When the system needs to use a device, it looks up the driver by ID and calls the operations through the function pointers. This is exactly how the Linux kernel's file_operations works.
Q03 of 04SENIOR
Why is qsort's comparator function signature `int (*)(const void*, const void*)`?
ANSWER
Because C lacks generics, qsort uses void* to accept any data type. The comparator receives pointers to two elements and must cast them to the correct type internally. This allows qsort to sort any type of array without knowing the element type at compile time. The caller is responsible for providing a comparator that correctly casts and compares.
Q04 of 04SENIOR
Explain the memory overhead and performance impact of using function pointers for a state machine.
ANSWER
Memory overhead is minimal: each function pointer is 4–8 bytes (depending on architecture). The state variable is a single pointer. Performance impact includes one extra pointer dereference per transition (to fetch the function address) and the inability to inline the state function (since the call is indirect). However, in most applications this overhead is negligible compared to the benefits of maintainability. In extremely tight loops (e.g., audio processing), you might inline critical states manually.
01
What is the difference between `void *f(int)` and `void (*f)(int)`?
JUNIOR
02
How would you implement a 'Plug-and-Play' driver architecture in C?
SENIOR
03
Why is qsort's comparator function signature `int (*)(const void*, const void*)`?
SENIOR
04
Explain the memory overhead and performance impact of using function pointers for a state machine.
SENIOR
FAQ · 5 QUESTIONS
Frequently Asked Questions
01
How do I debug a function pointer that crashes?
Use a debugger like GDB to inspect the value of the pointer before the call. If the address is 0x0, it's a NULL pointer. If it's a random high address, it's likely uninitialized. Always initialize your pointers and check them before calling to prevent these 'googable' production crashes.
Was this helpful?
02
Can I have an array of function pointers with different signatures?
No. All elements in a C array must be of the same type. To simulate different signatures, you would typically use a 'generic' signature (like void* arguments) or wrap the function pointers in a union/struct with a type tag.
Was this helpful?
03
Do I need the & operator to assign a function to a pointer?
Technically no. In C, a function name 'decays' to a pointer in an expression, much like an array name. p = my_func; and p = &my_func; are functionally identical, though the latter is more explicit.
Was this helpful?
04
What is the LeetCode equivalent for practicing function pointers?
Problems involving custom sorting (using qsort or std::sort in C++) or implementing designs like a 'Min Stack' or 'LRU Cache' in C often require managing pointers to behavior. Implementing a 'Command Pattern' from scratch in C is also a standard interview challenge.
Was this helpful?
05
How do I make function pointers thread-safe?
If multiple threads can read and write the same function pointer, use atomic operations or a mutex around reads and writes. C11 provides atomic types for this: atomic TcfHandler handler; ensures atomic loads/stores. For complex structures (dispatch tables), use RCU or copy-on-write to allow lock-free reads.