3 ms·
I have been using this for years. Capacity is not size. A zero size array will have non zero capacity. All c code is unsafe.
by nice_byte 4y ago
I have been using this for years. Capacity is not size. A zero size array will have non zero capacity. All c code is unsafe.
- klyrs 4y agoWhere do you check that capacity is nonzero? When capacity is zero, what happens on this line? a.capacity <<= 1u; "all c code is unsafe" is not an excuse to permit bloody obvious, undocumented memory overruns. I write a lot of c. Avoiding the unsafe bits, avoiding UB, is the skill required to write good c. "C code is unsafe" is a Rustacean marketing slogan. Don't believe it, but definitely don't practice it.
- nice_byte 4y agojust don't initialize it with 0 capacity :-)
- skullt 4y agoWhy not just fix it? It's a trivial fix and has the added benefit that a zero-initialized DYN_ARR_OF(x) struct would be in a valid state, which is always nice. A struct with several dynamic arrays can then much simpler to initialize, for example.
- acmj 4y agoFor a library, if the user input is wrong, throw an error or an assertion failure. It shouldn't be causing an uninformative segmentation fault which your library does. The fix is a trivial. Why so defensive?