4 ms·
That's on the client code. You can't stop callers from doing something stupid (or cosmic rays from flipping bits). At that point crashing fast is preferable.
by smelterdemon 9y ago
That's on the client code. You can't stop callers from doing something stupid (or cosmic rays from flipping bits). At that point crashing fast is preferable.
- pjmlp 9y agoI disagree, the premise of design-by-contract and clean code methodologies is that functions must ensure the integrity of the data handled by them.
- jstimpfle 9y agoThat's theoretic talk. Try doing it in practice and still get things done / be able to maintain the code / see the forest for the trees. But I have a feeling that we are lacking a bit of context here. Some people seem to focus on web-application style of programming (understandably) where you have lots of trust issues. Whenever data is carried across trust boundaries it needs to be checked (this applies to integrity in general, of which null safety is just a small part). (On the other hand, deserialization is not about validation of function arguments. Deserializers should assert integrity on the spot before calling into deeper nested functions).
- pjmlp 9y agoI did it in practice, during the MFC's glory days, several years ago. Making use of ASSERT_VALID(), VERIFY(), AfxCheckMemory(), AfxIsValidAddress(), AfxIsMemoryBlock() and many other helper functions. A style enforced at the company's code reviews, which helped a lot our code quality.