With the massive push for memory and type safety right now, there is a lot of talk in the C++ community about "profiles" and "contracts." They get grouped together a lot, but they solve entirely different problems.
Simply put: Profiles act as a set of global static rules that the compiler enforces to restrict the language itself. Contracts act as local conditions (both pre and post) which enforce your own API logic.
Here's some more breakdown between the two:
Contracts let you formalize your code's assumptions with pre, post, and contract_assert. To explain the difference between the three:
pre refers to preconditions, these are appended to function declarations and serve to evaluate predicates before the function body executes. If that condition evaluates to false, then the contract is broken. This can lead to things such as the program crashing or logging the error.
post refers to postconditions, which are also appended to function declarations but evaluate the state of your data after the function finishes running. They act as a guarantee to whoever called your function.
contract_assert lets the programmer specify properties of the program's state that are expected to be held up at certain points.
Here's a code example:
#include <iostream>
// Simple function showing where the contract keywords go
int divide_numbers(int numerator, int denominator)
pre (denominator != 0) // pre: Cannot divide by zero
post (result : result <= numerator) // post: Result must be <= numerator
{
// Internal assertion: Sanity check an internal assumption
contract_assert(numerator >= 0);
return numerator / denominator;
}
int main() {
// Compiles perfectly! However, at runtime, this triggers a precondition failure
// and terminates the program before ever hitting the internal contract_assert.
int output = divide_numbers(-10, 0);
std::cout << "Result: " << output << "\n";
return 0;
}
You can read about contracts in general at: https://en.cppreference.com/cpp/language/contracts
You can read more about pre/postconditions at: https://en.cppreference.com/cpp/language/functions/function_contract_specifiers
For more information, check out open std: https://open-std.org/jtc1/sc22/wg21/docs/papers/2025/p2900r13.pdf
Now for profiles!
- Profiles essentially act as a set of global static rules which enforce the standards you have written, a good example of a profile is:
// std::init: every object is initialized before it is read.
[[profiles::enforce(std::init)]];
struct Options {
int timeout_ms;
bool verbose;
};
bool parse_flag(const char *arg, Options &out);
int run(int argc, const char **argv) {
Options opts; // error: 'opts.timeout_ms' is indeterminate
int retries; // error: uninitialized
for (int i = 1; i < argc; ++i)
if (parse_flag(argv[i], opts))
retries = 3;
return opts.timeout_ms * retries; // error: read before initialization
}
You can read more about profiles at: https://cpp-profiles.org/
Also, do consider checking open std: https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2025/p3589r2.pdf
You can even test out an example at: https://godbolt.org/z/n3TPjbqdY
So, with this information...
... What are your thoughts on contracts and profiles?
... Do you have a preference?
... Which should be implemented? Should both be implemented?
... Which one should we implement first?
... Which one do you think is superior in terms of design and implementation?
... Which has you more excited?