From: pharrington Date: 2009-12-09T11:15:12+09:00 Subject: Re: Wordpress Port On Dec 8, 7:30 pm, Seebs wrote: > On 2009-12-09, David Masover wrote: > > > I like this both for the ludicrous example, when he finally decides to figure > > out how much to allocate: > > char* bigString; > > int i = 0; > > i = strlen("John, ") > >      + strlen("Paul, ") > >      + strlen("George, ") > >      + strlen("Joel "); > > bigString = (char*) malloc (i + 1); > > size_t len; > len = snprintf(NULL, 0, "%s, %s, %s, %s", "John", "Paul", "George", "Joel"); > bigString = malloc(len + 1); > > :) > > > Now suppose you add a string to that, or remove it. If you add it to one place > > and not the other, or remove it from one place and not the other, you're > > either wasting RAM or hitting a buffer overrun every time. > > Which is why snprintf was added. > > > Are you sure you never make a mistake here? > > Not totally sure, but I don't think I've found one in my code in at least > five years.  I'm pretty careful. > > Oh, wait!  I did have one.  It wasn't really in an entirely comparable > context, but there was a case where there was a plain error in the > attempt to count how many copies of a substring I needed space for. > > > Am I being unrealistic? Is this the kind of thing you'd never do? > > Not really, it's just that it's the kind of thing I do by idiom, and the > idioms are safe and effective. > > > The problem is, this requires me to always, always remember to do it. This is > > how a lot of PHP stuff is written, though I'm told it's changing, and those in > > the know use libraries that allow you to do it the Right Way. How would the > > Right Way look? > > Heh.  Actually, I reinvented this myself, pretty recently; I had to do some > database stuff in PHP (don't ask, it's horrible).  So EVERY single usage > looks like: >         $foo = do_query("SELECT a, b FROM table WHERE other_id = '%d';", $id); > > (note:  Yes, I'm passing a number in as a string.  I inherited a database > where every foreign key was stored as a VARCHAR string holding the digits > of the number of the foreign table's plain old integer id column.  A > chunk of this database made it to the front page of the Daily WTF once.) > > > Can you see why that's safer? I can develop a much easier to maintain habit of > > using only single-quoted strings as my queries. Since the actual values are > > always passed separately, they are always escaped -- I don't have to remember > > anything special to make that work. > > Yup! > > > The point is that higher levels of abstraction do allow us to abstract away > > opportunities to screw things up. This is true in the language itself, and in > > the libraries. > > Yes. > > > I could live with that, but I'm guessing it might've been the last straw... > > It was the point at which I told one of my friends that PHP had finally > achieved the dubious distinction of being the first language I actually > thought was uglier than perl.  He told me maybe I should look at Ruby, > and that was probably one of the best bits of advice I've gotten since, > sometime in the tail end of the 80s, someone told me about the distinction > between "works in C" and "works in this particular compiler". > > -s > -- > Copyright 2009, all wrongs reversed.  Peter Seebach / usenet-nos...@seebs.nethttp://www.seebs.net/log/<-- lawsuits, religion, and funny pictureshttp://en.wikipedia.org/wiki/Fair_Game_(Scientology) <-- get educated! As long as we're not talking about Ruby, for years (ironically mostly since I stopped coding PHP) I've wondered why people always forget that PHP *does* have SQL prepared statements built into the standard library (with mysqli). Granted, it's not exactly as slick as anything in Ruby, but its really not hard to just call prepare() and bind_param (), or even to take a minute to hack out a function that does this more concisely. But then I remember, the official guides don't stress the use of this, and hardly any tutorials even mention it (I've never read any PHP books, so I can't comment on that state of affairs). But yeah, the use of a language just goes in the direction of whats easiest to do with it :\