With the massive push for memory and type safety right now, there is a lot of talk in the C++ community about "profiles" and "contracts." They get grouped together a lot, but they solve entirely different problems.
Simply put: Profiles act as a set of global static rules that the compiler enforces to restrict the language itself. Contracts act as local conditions (both pre and post) which enforce your own API logic.
Here's some more breakdown between the two:
Contracts let you formalize your code's assumptions with
pre, post, and contract_assert. To explain the difference between the three:`pre` refers to preconditions, these are appended to function declarations and serve to evaluate predicates before the function body executes. If that condition evaluates to false, then the contract is broken. This can lead to things such as the program crashing or logging the error.
post refers to postconditions, which are also appended to function declarations but evaluate the state of your data after the function finishes running. They act as a guarantee to whoever called your function.`contract_assert` lets the programmer specify properties of the program's state that are expected to be held up at certain points.
Here's a code example:
#include <iostream>
// Simple function showing where the contract keywords go
int divide_numbers(int numerator, int denominator)
pre (denominator != 0) // pre: Cannot divide by zero
post (result : result <= numerator) // post: Result must be <= numerator
{
// Internal assertion: Sanity check an internal assumption
contract_assert(numerator >= 0);
return numerator / denominator;
}
int main() {
// Compiles perfectly! However, at runtime, this triggers a precondition failure
// and terminates the program before ever hitting the internal contract_assert.
int output = divide_numbers(-10, 0);
std::cout << "Result: " << output << "\n";
return 0;
}
You can read about contracts in general at: [https://en.cppreference.com/cpp/language/contracts](https://en.cppreference.com/cpp/language/contracts)
You can read more about pre/postconditions at: [https://en.cppreference.com/cpp/language/functions/function\_contract\_specifiers](https://en.cppreference.com/cpp/language/functions/function_contract_specifiers)
For more information, check out open std: [https://open-std.org/jtc1/sc22/wg21/docs/papers/2025/p2900r13.pdf](https://open-std.org/jtc1/sc22/wg21/docs/papers/2025/p2900r13.pdf)
Now for profiles!
Profiles essentially act as a set of global static rules which enforce the standards you have written, a good example of a profile is:
​
// std::init: every object is initialized before it is read.
[profiles::enforce(std::init)];
struct Options {
int timeoutms;
bool verbose;
};
bool parseflag(const char arg, Options &out);
int run(int argc, const char argv) {
Options opts; // error: 'opts.timeout_ms' is indeterminate
int retries; // error: uninitialized
for (int i = 1; i < argc; ++i)
if (parse_flag(argv[i], opts))
retries = 3;
return opts.timeout_ms retries; // error: read before initialization
}
You can read more about profiles at: https://cpp-profiles.org/
Also, do consider checking open std: https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2025/p3589r2.pdf
You can even test out an example at: https://godbolt.org/z/n3TPjbqdY
So, with this information...
... What are your thoughts on contracts and profiles?
... Do you have a preference?
... Which should be implemented? Should both be implemented?
... Which one should we