Warning C4996: This function or variable may be unsafe — compared to GCC on POSIX

前端 未结 3 1451
无人共我
无人共我 2020-12-30 01:08

I notice that MS compilers give \"deprecated\" warnings for cstdlib functions like getenv. MS has invented its own standard such as _dupenv_s

3条回答
  •  抹茶落季
    2020-12-30 01:42

    1. In a sane world, the answer would be "of course not, that would be stupid!" In this world, though, it seems there is no end of gut-wrenchingly poorly thought out undocumented behavior upon which people will stoop to depending upon. Raymond Chen has a great collection of such anecdotes (anecdon'ts?) in his blog. Such as the hideous practice of using a bug in the loader to share thread-local variables between an exe and a DLL. When you have as many customers as Microsoft does, the only safe choice is to never even risk breaking backwards compatibility.

    2. The difference in warnings is because cl.exe is going out of its way to highlight a potential security problem, and g++ isn't. getenv and puts and friends are all still broken under POSIX, but (at least for getenv) there isn't a more secure alternative in the standard library. And, unlike Microsoft, the GNU folks probably see a standard library call with potential security problems as a lesser evil than a more secure but platform-specific library call.

提交回复
热议问题