The perlfunc manpage says, with regard to the builtin built-in eval forms
:,
If there is a syntax error or runtime error, or a "die" statement is executed, "eval" returns an undefined value in scalar context or an empty list in list context, and $@ is set to the error message. If there was no error, $@ is guaranteed to be the empty string. Beware that using "eval" neither silences Perl from printing warnings to STDERR, nor does it stuff the text of warning messages into $@.
...
It is also Perl's exception trapping mechanism, where the die operator is used to raise exceptions.
...
Programmers may often suppress exceptions. This can be , which is easily accomplished by not examining the $@
variable (also known as $EVAL_ERROR
). Because eval
makes ignoring exceptions the default, it is critically important that programmers inspect $@
after using eval
.
Exceptions are intended to disrupt the expected control flow of the application. Many exceptions are supprssed suppressed out of not knowing how to handle the exception , or not even knowing that one may have been thrown. Consequently, exceptions must never be suppressed. If a call to eval
fails, the calling code must at least inspect $@
. If the developer does not know how to handle the exception, they he can always propagate it up the stack by issuing their his own fatal error.
Noncompliant Code Example
This noncompliant code example uses the eval
builtin built-in form to divide two numbers. Without using eval
the , the code would abort if $b
happened to be 0, but thanks to eval
, code processing can resume normally, with $answer
being uninitialized. This It produces a warning when the unitialized uninitialized value is embedded in the string passed to print()
. So eval
can be used to completely ignore an important error that may occur.
...
This compliant solution checks to see if eval
failed , and, if so, emits a warning message and initializes $answer
.
...
The CERT Oracle Secure Coding Standard for Java: ERR00-J. Do not suppress or ignore checked exceptions
Bibliography
...