3 ms·
> the function will be run. You can't be sure, that's just what one compiler does today. Static analysis tools tend to refer to the standard. $ tis-analyz
by junke 9y ago
> the function will be run.
You can't be sure, that's just what one compiler does today. Static analysis tools tend to refer to the standard.
$ tis-analyzer foo.c -val
/tmp/foo.c:16:[kernel] warning: Function pointer and pointed function have incompatible types.
Pointer type: int ()
Non-function: {0}
assert \valid_function(Do);
....
/tmp/foo.c:16:[value] Assertion 'Value,function_pointer' got final status invalid.
In other words, the pointer is not initialized.
- gambiting 9y agoWhat worries me is that almost every other compiler supported by godbolt would wipe your drive. It's not an anomaly of Clang - it's something fundamentally wrong in the design of compilers that allows them to do this at right optimization levels. Which means that if I have a method that wipes my entire production database but never ever call it, it might still get called because of mistake like this one where someone forgot to initialize a function pointer.
- yorwba 9y agoIf you have a method that wipes your entire production database, and have a function pointer that is only ever set to point to that function, and you call it ... then what made you think it wouldn't wipe the production database? It's the only thing it could possibly do. There are optimizations that can bite you when you thought you were doing everything right, but misunderstood undefined behavior. This is not such a case. If you write that kind of code, wiping your database is letting you off easy.
- phkahler 9y ago>> Which means that if I have a method that wipes my entire production database but never ever call it, it might still get called because of mistake like this one where someone forgot to initialize a function pointer. Do you actually have a method like that? Somehow I doubt it. Also, the example is completely contrived. If you have an uninitialized function pointer it's going to be pretty uncommon that there's only one possible function for the compiler to conclude is the right one. Also, you should not be testing on a production system. On a note related to your example, many automotive ECUs have the ability to re-flash over the vehicle network. In many cases the OEM requires that they do not contain any code to erase or program their own flash memory. This is for the reason you cite - if somehow (for whatever reason) that code were to execute it may brick that device. This then requires that the bootloader download a couple functions to RAM prior to updating its own code - those functions are the ones that erase and write flash. This is also convenient for some micro controllers that can't modify flash while code is being executed from it.
- guipsp 9y agoThis is a very specific case, if there is any other function that sets the pointer, the behavior is what you'd expect. https://godbolt.org/g/C3SYXt https://godbolt.org/g/C3SYXt