33 ms·
> As if the world needed more unsafe C code connected to the internet. Assuming (as usual) that the code generation is solid because of curl’s reputation: why
by avgcorrection 3y ago
> As if the world needed more unsafe C code connected to the internet.
Assuming (as usual) that the code generation is solid because of curl’s reputation: why not trust it? It would be pretty bad if the generator could emit memory-unsafe code. (I don’t know.)
- eichin 3y agoFor a trivial example, the code just calls curl_easy_init, a bunch of curl_easy_setopt, curl_easy_perform to do the work, and curl_easy_cleanup. (It leaves comments like "CURLOPT_WRITEDATA set to a objectpointer" in a comment block on params for which "You may select to either not use them or implement them yourself" - that's presumably where you are going to write your own unsafe code :-)
- avgcorrection 3y agoAh I see, thanks.
- Too 3y agoOh don’t get me wrong. I trust curl and I have no reason not to trust this tool. It’s the consumer of this tool and all the code around it that will get written I don’t trust.