5 ms·
Why call .unwrap() in a function which returns Result<_,_>? For something so critical, why aren't you using lints to identify and ideally deny panic inducing c
by tristan-morris 11mo ago
Why call .unwrap() in a function which returns Result<_,_>?
For something so critical, why aren't you using lints to identify and ideally deny panic inducing code. This is one of the biggest strengths of using Rust in the first place for this problem domain.
- sayrer 11mo agoYes, can't have .unwrap() in production code (it's ok in tests)
- orphea 11mo agoLike goto, unwrap is just a tool that has its use cases. No need to make a boogeyman out of it.
- gishh 11mo agoTo be fair, if you’re not “this tall” you really shouldn’t consider using goto in a c program. Most people aren’t that tall.
- tucnak 11mo agoNonsense. Linux kernel for one example, uses goto everywhere for error handling.
- fwjafwasd 11mo agopanicans should be using .expect() in production
- metaltyphoon 11mo agoYes it's meant to be used in test code. If you're sure it can't fail do then use .expect() that way it shows you made a choice and it wasn't just a dev oversight.
- keyle 11mo agounwrap itself isn't the problem...
- tptacek 11mo agoProbably because this case was something more akin to an assert than an error check.
- stefan_ 11mo agoYou are saying this would not have happened in a C release build where asserts define to nothing? Wonder why these old grey beards chose to go with that.
- tptacek 11mo agoI am one of those old grey beards (or at least, I got started shipping C code in the 1990s), and I'd leave asserts in prod serverside code given the choice; better that than a totally unpredictable error path.
- ashishb 11mo ago> You are saying this would not have happened in a C release build where asserts define to nothing? Afaik, Go and Java are the only languages that make you pause and explicitly deal with these exceptions.
- tristan-morris 11mo agoAnd rust, but they chose to panic on the error condition. Wild.
- ashishb 11mo ago> And rust, but they chose to panic on the error condition. Wild. unwrap() implicitly panic-ed, right?
- aw1621107 11mo agoI don't think "implicitly panicked" is an accurate description since unwrap()'s entire reason for existing is to panic if you unwrap an error condition. If you use unwrap(), you're explicitly opting into the panicking behavior. I suppose another way to think about it is that Result<T, E> is somewhat analogous to Java's checked exceptions - you can't get the T out unless you say what to do in the case of the E/checked exception. unwrap() in this context is equivalent to wrapping the checked exception in a RuntimeException and throwing that.
- koakuma-chan 11mo agoWhy is there a 200 limit on appending names?
- nickmonad 11mo agoLimits in systems like these are generally good. They mention the reasoning around it explicitly. It just seems like the handling of that limit is what failed and was missed in review.
- zmj 11mo agoEverything has a limit. You can define it, or be surprised when you find out what it is.