3 ms·
asserts are for diagnostic-enabled code, don't use them for security checks.
by nbsd4lyfe 9y ago
asserts are for diagnostic-enabled code, don't use them for security checks.
- steveklabnik 9y agoThis is one area where Rust also differs from C; assert!s are left on in release mode; you use debug_assert! if you want something only in development.
- nbsd4lyfe 9y agoI agree, it's a hella questionable language choice, and not limited to C. I found out about it through https://github.com/rohe/pysaml2/issues/451 https://github.com/rohe/pysaml2/issues/451
- reza_n 9y agoI would argue the opposite, assert() statements are the best way to write defensive and secure C. There might have been a time when people commonly compiled out assert() statements from binaries, but that is only OK if the software was designed for that. Otherwise, that would be like me saying I am going to compile out all strlen() statements from a given binary and then expect it to behave the same.
- irundebian 9y agoSecure code should be correct and robust. To assure correctness assert()'s should be used, to assure robustness you should check return values and buffer sizes.