Commit cac9bc

2025-10-28 12:02:02 flichtenheld: ASSERT
Development/CodeStyle.md ..
@@ 91,6 91,14 @@
This makes the intent immediately clear to the reader / reviewer.
Note that we do not use the `[[fallthrough]]` attribute yet, since this is only officially introduced by C23.
+ ### Use `ASSERT()` to verify assumptions, but never use `assert()`
+
+ If there are assumptions in your code about the state of parameters/variables and you assume these conditions to be always fulfilled then you can use `ASSERT()` to verify them. We define our own version of `ASSERT()` which is not affected by `-DNDEBUG`. It will exit the program with an error code but log an informational message first. For this reason it is preferred over the default `assert()` provided by the standard library. Never use `assert()` in our code.
+
+ `ASSERT()` can be used if you want to make sure that certain conditions are fulfilled which are necessary to avoid e.g. overflows or unsafe casts. This should only be used if a violation of the condition signifies a programming error or an otherwise unexpected program state (think hardware error). Do not use it to handle expectable errors. E.g. if the condition is violated due to external input then it is probably required to handle it gracefully instead of allowing the external entity to DOS us.
+
+ It is acceptable to use `ASSERT()` to react to OOM conditions in most cases, since we do expect our code to recover in those situations.
+
## Portability concerns
### Printing time_t and suseconds_t values
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9