Congrats on the completion of this effort! C/C++ can be memory safe but take some effort. IMHO the timeline figure could benefit in mobile from using larger fonts. Most plotting libraries have horrible font size defaults. I wonder why no library picked the other extreme end: I have never seen too large an axis label yet.
No strcpy either
11–20 of 151 posts
Re: No strcpy either
#12From the article: > It has been proven numerous times already that strcpy in source code is like a honey pot for generating hallucinated vulnerability claims This closing thought in the article really stood out to me. Why even bother to run AI checking on C code if the AI flags strcpy() as a problem without caveat?
Re: No strcpy either
#13> A new breed of AI-powered high quality code analyzers, primarily ZeroPath and Aisle Research, started pouring in bug reports to us with potential defects. We have fixed several hundred bugs as a direct result of those reports – so far.
[1] https://daniel.haxx.se/blog/2025/12/23/a-curl-2025-review/
Re: No strcpy either
#14Re: No strcpy either
#15From the article: > It has been proven numerous times already that strcpy in source code is like a honey pot for generating hallucinated vulnerability claims This closing thought in the article really stood out to me. Why even bother to run AI checking on C code if the AI flags strcpy() as a problem without caveat?
Because people are stupid and use AI for things it is not good at.
people overestimate AI
Re: No strcpy either
#16I don't really think this adds anything over forcing callers to use memcpy directly, instead of strcpy.
Re: No strcpy either
#17I'm surprised curlx_strcopy doesn't return success. Sure you could check if dest[0] != '/0' if you care to, but that's not only clumsy to write but also error prone, and so checking for success is not encouraged.
DEBUGASSERT(slen
it means it succeeded. Although some compilers will remove the assertions in release builds.I would have preferred an explicit error code though.
Re: No strcpy either
#18After years I now think it's essential to have a library which records at least how much memory is allocated to a string along with the pointer.
Something like this: https://github.com/msteinert/bstring
Re: No strcpy either
#19Congrats on the completion of this effort! C/C++ can be memory safe but take some effort. IMHO the timeline figure could benefit in mobile from using larger fonts. Most plotting libraries have horrible font size defaults. I wonder why no library picked the other extreme end: I have never seen too large an axis label yet.