Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosAndroid Police: Samsung is smashing records! #shorts #tech #phones(21.09.2026 um 13:55 Uhr)
YouTube Security Videosheise & c't: Bundesnetzagentur wollte diesen Futterautomaten verbieten(21.09.2026 um 13:53 Uhr)
YouTube Security VideosNeil Patel: Your Google Traffic Isn't An Asset It's A Loan #shorts(21.09.2026 um 14:05 Uhr)
Windows Tipps & SecurityF-14 A Tomcat Top Gun endlich als Revell Klemmbausteinmodell erhältlich(21.09.2026 um 14:27 Uhr)
Sichere ProgrammierungShow the Hand-Back Sample Before Approving an Agent Score(21.09.2026 um 14:15 Uhr)
Sichere ProgrammierungHybrid retrieval in one Postgres query: RRF over tsvector + pgvector(21.09.2026 um 14:15 Uhr)
YouTube Security VideosAndroid Police: Samsung is smashing records! #shorts #tech #phones(21.09.2026 um 13:55 Uhr)
YouTube Security Videosheise & c't: Bundesnetzagentur wollte diesen Futterautomaten verbieten(21.09.2026 um 13:53 Uhr)
YouTube Security VideosNeil Patel: Your Google Traffic Isn't An Asset It's A Loan #shorts(21.09.2026 um 14:05 Uhr)
Windows Tipps & SecurityF-14 A Tomcat Top Gun endlich als Revell Klemmbausteinmodell erhältlich(21.09.2026 um 14:27 Uhr)
Sichere ProgrammierungShow the Hand-Back Sample Before Approving an Agent Score(21.09.2026 um 14:15 Uhr)
Sichere ProgrammierungHybrid retrieval in one Postgres query: RRF over tsvector + pgvector(21.09.2026 um 14:15 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Avoid the Temptation of bool

Introduction The Boolean type (spelled bool in C, C++, Go, and Rust, among others; and boolean in Java) is fundamental to programming since so many things are either true or false. Of course you can use bool for function parameters, and…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




Introduction



The Boolean type (spelled bool in C, C++, Go, and Rust, among others; and boolean in Java) is fundamental to programming since so many things are either true or false. Of course you can use bool for function parameters, and it’s tempting to do so — but you probably shouldn’t. Consider a function call like:




void *buf = alloc_buf( 4096, true );  // What does "true" mean?






Seeing a literal true or false as part of a function call tells you nothing about what it means. Does it mean the buffer is maximally aligned? Zeroed? Prints an error message if the allocation fails? You have no idea. You have to find and read the either function’s declaration or documentation to know what it means:




void* alloc_buf( size_t size, bool zero_buf );






It’s for this reason I personally try to avoid using bool for parameters in public APIs. Code is read far more than it’s written, so clarity matters. But what can you do instead of using bool? That’s what this article is about.




This article’s examples are specifically in C but apply equally well to C-like languages or any language that has a Boolean type.







Alternatives to bool



There are a few alternatives depending on circumstances and taste.






Use Two Functions



Instead of a single function, have two:




void* alloc_raw( size_t size );
void* alloc_zero( size_t size );






Note that this would be in the public API. Internally, you can still implement a single function that takes a bool if you want and have the public functions just call the internal function.






Use an Enumeration



Instead of using bool, define an enumeration:




enum alloc_opts {
ALLOC_RAW,
ALLOC_ZEROED
};
typedef enum alloc_opts alloc_opts;

void* alloc_buf( size_t size, alloc_opts opt );






Of all the languages mentioned, only Go doesn’t directly support enumerations — but you can fake it.



You might think creating an enumeration to replace a bool is overkill, but now look how the function is called:




void *buf = alloc_buf( 4096, ALLOC_ZERO );






It’s barely longer, but much clearer. Investing more in functions’ APIs has a many-fold return on said investment in terms of clarity.



Another benefit of using an enumeration is that it allows for additional options to be added easily by converting the enumeration to use bit flags:




enum alloc_opts {
ALLOC_RAW = 0,
ALLOC_ALIGNED = 1 << 0,
ALLOC_ZEROED = 1 << 1,
};






Then you can do things like:




void *buf = alloc_buf( 4096, ALLOC_ALIGNED | ALLOC_ZERO );






Note that code already using the function doesn’t have to change (unless you want to use the new options); it just has to be recompiled.






Use Comments (as a Last Resort)



If your code either calls a 3rd-party function that takes a bool parameter or you simply can’t change your function’s API for whatever reason, at least use inline comments that repeat the name of the parameters:




void *buf = alloc_buf( 4096, /*zero_buf=*/true );






Programmers reading your code (including yourself in several months’s time) will thank you.






Conclusion



Since bool is so easy, it’s very tempting to use it for function parameters, especially when retrofitting an existing function just to tweak it. Avoid the temptation: either add a second function or use an enumeration.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Avoid the Temptation of bool

Thematisch verwandte Begriffe: Avoid, Temptation, bool · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94097 | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. Th…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick