For example, when I'd review C code I'd look at the str???() function use. They are nearly always infested with bugs, usually either neglecting to add a terminator zero or neglecting to add sufficient storage for the terminating zero.
How can that language still be so popular?
The length of the string "Foo", when properly terminated, is 3. The minimum number of bytes needed [1] to represent that string properly is 4 (3+'\0'). The actual number of bytes used by that string is whatever you asked for and received when using "malloc".
[1] Assuming ASCII and 1-byte characters.
Back when I was musing about what D would be like, I happened across some BASIC code. I was drawn to the use of strings, which were so simple in BASIC. I decided that D would be a failure if strings weren't as easy to use as in BASIC.
And D strings turned out to be better than I'd dared hope!
I proposed an enhancement to C to get much of that benefit, but it received zero traction in the C community. Oh well.
It's also an easy language to write a compiler for. At one point I counted over 30 C compilers available for DOS.
Edit: I guess I should've at least asked myself if the question was rhetorical.
All I want is a menubar, a toolbar, a statusbar, and some dialog windows. I don't want fading transitions when I click a tab.
It's crazy that I'm forced to write header files just to have a menubar.
Zig 1.0 can't come soon enough.
Or... https://quickshell.org/ ?
No doubt there are valid reasons to use it, that is just the state of things they are unfortunately.
That's what I meant, not that self hosted compliers don't exist.
It takes a lot a passion and dedication to security and reverse engineering to get there.
I'd guess the curriculum is half reverse engineering and half reading any write-ups to see the attacks and areas of attack for inspiration