4 ms·
This might well be valid according to the standard, but I find it very depressing how many people consider it reasonable behavior.
by jbb67 9y ago
This might well be valid according to the standard, but I find it very depressing how many people consider it reasonable behavior.
- sddfd 9y agoIf we want zero-overhead abstraction (i.e. don't generate null checks in front of every division, etc.) and a (reasonably) safe language, more static analysis is in order. The case in point is Rust: Its type system is basically an elaborate static analysis. Rusts advantage over tools like UBsan is that the programmer expects to interact with the type system. Many static analysis tools get rejected by programmers, because the expectation is that they "just work", when really one needs to interact with such a tool. This means bidirectional communication: The programmer tells the tool what invariant he wants to get, and the tool tells the programmer which invariants it is missing.
- umanwizard 9y agoWhy? This sort of optimization is necessary in order to make programs run fast.
- megous 9y agoWhat kind of optimization? I'd rather this kind of code would crash on me, like the code that gcc compiles out of this, rather than compiler silently doing crazy inferences out of obviously buggy code.
- umanwizard 9y agoFor this particular edge case, yes it seems absurd. However, many optimization passes are based on simplifying code by figuring out what range of values something can take. Most optimization passes don't know what the original code looks like, they only see it after it's been passed through a bunch of other optimization passes and preprocessing, so they can't reason about whether a particular optimization would seem "completely natural" or "abuse of UB" to the original programmer.
- guipsp 9y agoThis is a very specific case, if there is any other function that sets the pointer, the behavior is what you'd expect. https://godbolt.org/g/C3SYXt https://godbolt.org/g/C3SYXt
- Ded7xSEoPKYNsDd 9y agoIt might be what you expect for that particular compiler, but there's no guarantee. A different compiler might decide that because `Do` has only two possible values, that it should replace the dynamic function call with an if condition deciding between two static function calls like I did here manually, to trigger the bug again: https://godbolt.org/g/kWcvvb https://godbolt.org/g/kWcvvb