24 ms·
"Regarding 1., do you completely disregard MISRA-C and the other safety certifications?" Hmm, i don't think i understand that. Of course we do not disregard MI
by S_I 10y ago
"Regarding 1., do you completely disregard MISRA-C and the other safety certifications?"
Hmm, i don't think i understand that. Of course we do not disregard MISRA-C. I don't know where this impression came from. As i said, no dynamic allocation, no pointer arithmetic etc. Could you elaborate?
"What about bounds checking and making sure the pointers are always valid?"
Well, if your code is controlling big, possibly dangerous machines, you will/should be doing formal verification anyway (i use FRAMA-C). This will go a long way regarding said issues.
Furthermore you will not/should not create your complex state machines by hand. There are tools for that (and yes, formally verified as well).
P.S.: CompCert is a necessity as well.
- pjmlp 10y agoBecause of this "In my world memory safety is simply not an issue, because we don't allocate dynamically". In C, memory safety is always an issue, due to how array and strings are handled via pointers without any sort of validation. Thanks for clarifying your tooling, nice to see you care. It would be good if more developers would care to use Frama-C.
- S_I 10y agoAh, i see. Of course it is an issue, but it is not an issue ;-).