3 ms·
In practical terms its not very dramatic. C11 allows you to check and set exact alignment with alignof alignas. There are also bounds checking (_s) functions th
by generic_user 10y ago
In practical terms its not very dramatic. C11 allows you to check and set exact alignment with alignof alignas. There are also bounds checking (_s) functions that set errno messages on overflow. Also _Generic can give automatic type deduction in certain cases.
All of these things simply help you 'check your work'. Bounds checking has been standard good practice for years now so its not a surprise they put that in the standard library. There is still no magic and its the programmer who has to put forward the effort to check for errors.
- pjmlp 10y ago> Bounds checking has been standard good practice for years now so its not a surprise they put that in the standard library. Not really, It has been removed from the standard library and made an optional Annex. A C11 compliant compiler is not required to provide them. For me those "secure" functions are just as insecure as their cousins, because they still require C developers to track pointers and bounds separately. The only thing they improve in regards to security is not forcing us to manually place a null character at the very end, in case the destinations are filled up. But the danger of passing the wrong length, origin or destination is still there.
- generic_user 10y agoI think threads, atomics and bounds checking were all TR proposals up until C11. Then they added the conditional (optional) features. Threads and atomics are mandatory and bounds checking and 'analyzability' are conditional. If you have to deal with strings in C more then likely you have written a string interface with bounds checking. Its not clear if it needs to be standard so its good that its optional. Icc, gcc and clang support it so I would not hesitate to use it. My point was that 'safety' in C is still more or less a process of training the programmer rather then a language feature. And that was and still is a design goal. But at least now you can point to the bounds checking functions and other new features as an example of how to get there. I'm not going to argue whether C is safe. Or whether XYZ is safer then C. Thats way of topic.