To me it reads fine and the idea is that is frees that data address if its occupied. I'm sure I'm not the only one who is curious why this is bad.
To me it reads fine and the idea is that is frees that data address if its occupied. I'm sure I'm not the only one who is curious why this is bad.
The program will work with no problems, but sensitive data that has been used then freed is available for retrieval when bugs like heartbleed are found.
As the article suggests the right way is to clean the data from memory ( by overwriting it with something else) before freeing it.
For instance if you set a stack-resident buffer that contained a key to all zeros using memset, then simply exit the scope, most optimisations will detect it as unnecessary (wtf? this never gets read back, who cares?) and ditch the line.
Search for memset_s (part of the C11 standard) for a clear function that can survive optimisers.
if (b->d != NULL)
{Insisting on braces is a style concern, though it does seem to protect people from themselves to some extent.
Code should be written for the benefit of humans, not compilers.
if ((bool(b->d != NULL) == true) { }
much better to be explicit, don't you think?