5 ms·
I think nowadays it's a bit of a misconception that C++ is unsafe regarding memory; RAII essentially takes care of it for you when you talking about IO or other
by clappski 10y ago
I think nowadays it's a bit of a misconception that C++ is unsafe regarding memory; RAII essentially takes care of it for you when you talking about IO or other resources, and under the circumstances that you really need a pointer you can either use a reference or a smart pointer, which essentially just delegates the management of RAII to the smart pointer object.
- TazeTSchnitzel 10y agoSo it's safe so long as you're using the safety features. So, unsafe.
- pjmlp 10y agoC++ is a car with safety belts. It is up to the person to buckle it, or not. C is a car made in the days when having a safety belt wasn't even a concept, so there is no option to buckle it.
- Spivak 10y agoMaybe a better metaphor would be C is a car with a knife pointing out of the steering wheel. The fact that it's dangerous makes the person drive safer and more cautiously.
- marssaxman 10y agoNah... C is just a motorcycle. Primitive, zippy, dangerous, loud, and fun. People who don't ride don't understand; people who do ride are OK with the risks they're taking.
- DerekL 10y agoIt's a often repeated idea that the dangers of making mistakes with C code will scare the programmers into writing correct code. This completely fails in my experience. I've worked on large C projects that suffered a ton of leaks, free-after-use, buffer overruns, etc.
- user5994461 10y agoCorrection: use-after-free
- xyzzy_plugh 10y agoRAII is great until you stumble upon an API that is terrible and doesn't care. If you can't use exceptions or have any limitations that make RAII difficult to use, then suddenly everything becomes a lot messier. Alternatively you can take it the other route and discard RAII but then you're basically just writing C. Some of the most heinous, insane bugs I have ever seen are because C++ is a complexity nightmare and very intelligent people struggle to get things right. Rust is orders of magnitude safer as it forces you to play with safe constructs only (avoiding surprises left by others, or past you) and wrapping anything explicitly unsafe.
- steveklabnik 10y agoEven smart pointers can trivially cause memory unsafety. The simplest example is that std::move-ing a uniq_ptr makes the original nullptr, which is just sitting around, waiting to be dereferenced. This compiles cleanly with all warnings enabled on every compiler I've tried it on, yet that dereference is UB.
- duneroadrunner 10y agoWhile conventional C++ is a vast improvement in memory safety, it does not, at the moment, fully address the problem. Complete memory safety may be achieved if/when the "Core Guidelines Lifetime Checker"[1] is completed, but in the mean time SaferCPlusPlus[2] can be used to achieve memory safety. SaferCPlusPlus can, of course, be used with C code as well (if you're willing to use a C++ compiler), but will typically be slower than with the corresponding C++ code. [1] https://blogs.msdn.microsoft.com/vcblog/2016/03/31/c-core-guidelines-checkers-preview-of-the-lifetime-safety-checker/ https://blogs.msdn.microsoft.com/vcblog/2016/03/31/c-core-gu... [2] shameless plug: https://github.com/duneroadrunner/SaferCPlusPlus https://github.com/duneroadrunner/SaferCPlusPlus