5 ms·
If by "bounds-checks indexes" you mean "panics when given an out of bounds index, even if it's a compile time constant" then sure. I'm not sure why people talk
by ue_ 9y ago
If by "bounds-checks indexes" you mean "panics when given an out of bounds index, even if it's a compile time constant" then sure. I'm not sure why people talk about Rust being safe when this sort of thing happens and it can't catch it at compile time. At least C compilers have sanitizers that pick up things like that.
- bjz_ 9y ago> I'm not sure why people talk about Rust being safe when this sort of thing happens and it can't catch it at compile time. "Safe" as in "memory safe". Panicking is better than allowing one to read into that memory. I would prefer panic-safe, but we might have to wait for a new dependently typed systems lang for that.
- masklinn 9y ago> If by "bounds-checks indexes" you mean "panics when given an out of bounds index, even if it's a compile time constant" then sure. Er yes, it's safe as in memory-safe, as in an OOB will not own the entire application let alone machine. Error on OOB is a very common (if not quite universal) strategy — and incidentally also the one Go uses, the other primary one being returning null (which would be difficult in a language where most types are not nullable). If you want panic-safe, use .get.
- ue_ 9y agoHow is an error differentiated from a panic? Can a panic as is caused by the OOB situation I described be recovered from, or is it necessarily fatal?
- masklinn 9y ago> How is an error differentiated from a panic? I'm using them for the same purpose, but panic is rust-specific whereas error is not. > Can a panic as is caused by the OOB situation I described be recovered from, or is it necessarily fatal? Technically it can be recovered from[0] but practically it usually should not be. Panics should not be used as an exceptions system. An OOB panic is basically a failed assertion. If OOB is a normal part of your operations, use a panic-safe access method (e.g. slice::get[1] which returns an Option<&T>) [0] https://doc.rust-lang.org/std/panic/fn.catch_unwind.html https://doc.rust-lang.org/std/panic/fn.catch_unwind.html [1] https://doc.rust-lang.org/std/primitive.slice.html#method.get https://doc.rust-lang.org/std/primitive.slice.html#method.ge...
- ue_ 9y agoInteresting, thank you.
- Ar-Curunir 9y agoYou mean, compared to C, which silently allows you to read data beyond the end of the array? Sanitizers also exist for rust. Furthermore, often time the bounds check can be elided when using standard constructs like iterators.