3 ms·
They said: "There were over 1400 direct invocations of 22 different safe strcpy()-like functions and over 400 direct invocations of 9 different unsafe strcpy()
by ArchD 8y ago
They said:
"There were over 1400 direct invocations of 22 different safe
strcpy()-like functions and over 400 direct invocations of 9 different
unsafe strcpy()-like functions. Approximately 22% of the direct
invocations of strcpy()-like functions are to unsafe variants."
There's nothing provably wrong with using strcpy() instead of strncpy(). If you are are careful to ensure certain initial conditions, there is nothing wrong and on a device with limited resources, it may be important to reduce unnecessary runtime safety checks and instead pay for error avoidance at compile-time.
- yjftsjthsd-h 8y ago> If you are are careful to ensure certain initial conditions And you trust people to do this? Even competent programmers need safeguards.
- ArchD 8y agoBlack-and-white thinking and argument is your enemy. Your use case may call for a lot of safety at the expense of performance, so you do run-time checks like this and sacrifice performance, or it may require extreme performance and you do static analysis instead of these wasteful run-time checks. There's no such thing as 'trust people'. If you write the code yourself you decide whether your own code is safe enough. If you are a manager, you look for unit tests, static analysis or do a detailed code review.