4 ms·
The Rust compiler does this. No out-of-bounds accesses and therefore no buffer overflows. So yes it has been generalized.
by Datenstrom 8y ago
The Rust compiler does this. No out-of-bounds accesses and therefore no buffer overflows. So yes it has been generalized.
- fpgaminer 8y agoThe Rust compiler does some limited "static analysis"* to determine if an array access is guaranteed to always be within bounds. But it doesn't do this universally. In other words, it's easy to write a program in safe Rust code that will attempt out of bounds accesses. The saving grace is that in those cases the compiler just inserts a bounds check which panics at run-time. That's a bit different from a formally verified OOB safe program which wouldn't require any compiler-injected bounds checking. All accesses are provably safe either because they are naturally so, or because the code explicitly performed a bounds check. * IIRC what Rust's compiler actually does is just inject bounds checks on all array accesses and then depends on the underlying optimizations to remove them when possible. That's certainly a form of static analysis, but perhaps some wouldn't consider it as such.
- Datenstrom 8y agoVery true. Wouldn't it be possible to solve it to that standard using dependent types? I think I read that those are on a distant wishful thinking roadmap for Rust in some RFC. I really hope they get added some day, I find myself wanting them all the time.