C and returning values quickly or safely, but not both
subethasoftware.com
subethasoftware.com
E.g. "Passing by value is slower, since a new variable has to be created. Passing by reference just passes an address and the code uses that address – no new variable is created." is not right for the example involving an int*, as passing a pointer is clearly as much data to copy as an int (and in the non-pointer case it will all end up in (faster) registers).
Similarly if you paste the "Returning a copy of a structure" example into godbolt you'll see GetDateTime4 writes directly into the caller's pointer. https://godbolt.org/z/Wj4Gn1YaP
pointers-to-structs ARE pointers-to-objects. That's the default way to operate on objects in a huge amount of code.
Don't use strncpy(), if it hits the limit it doesn't end the copy with NUL, causing random crashes.
Quite a few people have concluded that generally, despite the standard library using them, NUL-terminated C string were not the Right Way and it's better to have a struct with the pointer and a size_t length (and perhaps a size_t representing the possibly larger allocated length). This eliminates NUL handling, and strlen() as well and since everything can cheaply know the length, can be the basis of more secure code.
Like myapi(uint8_t *dest, const uint8_t *src, size_t dest_len, size_t src_len), it's very clear what will be doing what with what.
You can cast const away and do something unexpected in there, but that's on you doing the Wrong Thing.
If you're serious about your code, you will turn on -Werror -Wall -Wextra and anything else you don't like the look of, use static analysis and so on that makes this class of complaint moot.
No it doesn't. No-one has ever come up with a concrete set of rules for how to build C and not have embarrassingly basic security bugs. It's always some vague "oh, if you use enough warnings and static analysis it's not a problem", and if you have security bugs evidently you weren't using enough, and if it's impossible to write anything or use any libraries then evidently you were using too many. A C language that actually works is vaporware.
So my general feeling is that they're trying to work assuming people will want to screw their API intentionally; which looks quite unreasonable to me. A bit context about the 'why' would be interesting