3 ms·
Proper defensive C programming solves these problems. If argc is 0, don't look at argv. Sanity check argv != NULL before looking at it. Or, maybe write secur
by errcorrectcode 5y ago
Proper defensive C programming solves these problems.
If argc is 0, don't look at argv.
Sanity check argv != NULL before looking at it.
Or, maybe write security-critical programs in safer languages like Rust.
- TillE 5y agoYeah I find it completely bizarre to not check everything for error conditions, unless you're writing some sloppy one-off code and don't care. People out there write some pretty funky C.
- errcorrectcode 5y agoIt's a safety / performance tradeoff that isn't well-constrained by the language or most tools. That's partially why it's a fragile and dangerous language. If you're writing a serious kernel in C, you ought to have programmatic debugging assertion constraints for every parameter.