5 ms·
strlen is not safe and the design of this function does not permit it to ever be safe. That is my point. Most "nice" C functions are also not used as teaching
by oddity 8y ago
strlen is not safe and the design of this function does not permit it to ever be safe. That is my point.
Most "nice" C functions are also not used as teaching examples. There's a difference in how one writes C code for production use and instructive use.
- saagarjha 8y agoI take it you come from a higher level language, where null termination would seem risky. In C, however, strlen is considered safe (as opposed to say strcpy, strcat, etc. which do have "safe" replacements). As for terse examples being given to beginners, here's the example The C Programming Language gives for strcpy: void strcpy(char *s, char *t) { while ((*s++ = *t++) != '\0') ; }
- ChrisSD 8y agoC11 introduced strnlen_s, a "safe" replacement to strlen.
- colejohnson66 8y agoWhat’s safer about it? Doesn’t `strlen' just scan until the null character, then go nullCharPtr - str ? Is there something unsafe with that?
- ChrisSD 8y agoWhat if there is no null?
- a1369209993 8y agoIf there isn't a NUL, then you're asking for a property relevantly distict from length of a datum relevantly distinct from a C-string. Use `strchr(s,0x00)` or `memchr(s,0x00,zs)`.
- deleted 8y ago[deleted]
- slrz 8y agoThen you probably shouldn't feed it to the str* functions at all. Use the mem* functions instead.
- ChrisSD 8y agoThat's the same as saying you should never use the str* functions. Nothing in C guarantees a string must have a null byte. As you're well aware, C-strings aren't a separate type that's distinct from char arrays. Sure you can say that good programmers will always ensure a C-string is a C-string but there's decades of programming history that shows that's not true in practice.
- saagarjha 8y agoThen use a language other than C that doesn't shoehorn string handling into char , as I've mentioned in other comments. If you're have a char with no terminating null byte and you hand it to a function with "str" and its name, you're going to have a bad time.
- saagarjha 8y agostrnlen_s takes a parameter for the maximum number of characters to scan. This way, it won’t overflow the buffer you provide it if there’s no trailing null byte.
- beefhash 8y agostrnlen_s is in Annex K, which is an optional part of the standard. Incidentally, no libc in widespread usage has implemented it.
- ChrisSD 8y agoTrue. The non standard strnlen is however more widespread. Microsoft implements strnlen_s in terms of strnlen like so. _String == 0 ? 0 : strnlen(_String, _MaxCount)
- toopsss 8y agoYou haven’t read K&R C I’m going to guess. Terseness is a traditional component of C and UNIX (cf creat). I don’t care to debate the merits but that is a fact. Most C books in the 80s were written in this style. Furthermore in the days or micros code was generally terse for many and varied reasons. There were people typing code on membrane keyboards.