3 ms·
I think the answer is yes. There's a complementary project [1] that aims to enforce a slightly more restricted memory safe subset of C++ than the lifetime profi
by safercplusplus 7y ago
I think the answer is yes. There's a complementary project [1] that aims to enforce a slightly more restricted memory safe subset of C++ than the lifetime profile checker does (or eventually will). The restrictions do not manifest as limitations on the code, but rather as extra run-time checks in some scenarios.
The C++ language maps one-to-one to the safe subset, so auto-conversion of (reasonable) existing C++ code to the safe subset should be a straightforward (if tedious) undertaking. The issue will be the performance of the converted code, which will depend on how pointers/references are used in the original code.
Pointers that are expected to never point to (in addition to never dereference to) a destroyed object can be converted to "safe" pointers with little run-time overhead [2]. Otherwise the pointer would need to converted to one with more overhead [3]. Pointers that can be verified (by the static analyzer) to conform to "scope lifetime" rules (akin to Rust) can remain zero-overhead pointers.
New code written in the safe subset would generally have performance in the ballpark of traditional C++ [4].
[1] https://github.com/duneroadrunner/scpptool https://github.com/duneroadrunner/scpptool
[2] https://github.com/duneroadrunner/SaferCPlusPlus#norad-pointers https://github.com/duneroadrunner/SaferCPlusPlus#norad-point...
[3] https://github.com/duneroadrunner/SaferCPlusPlus#registered-pointers https://github.com/duneroadrunner/SaferCPlusPlus#registered-...
[4] https://github.com/duneroadrunner/SaferCPlusPlus-BenchmarksGame https://github.com/duneroadrunner/SaferCPlusPlus-BenchmarksG... (note that the benchmark code is quite old and will be updated soon)
- muizelaar 7y agoIs there a document that describes roughly how to do the conversion? How are things like pointer arithmetic handled?
- safercplusplus 7y agoUnfortunately, documentation [1] is still kind of lacking. Like Rust (and arguably modern C++ conventions?), the safe subset doesn't support pointer arithmetic directly. You would have to convert the pointer to an iterator (and its target to an appropriate container). Auto-conversion of code that uses pointer arithmetic is challenging, but has been demonstrated to be solvable in the general case [2]. [1] https://github.com/duneroadrunner/SaferCPlusPlus#getting-started-on-safening-existing-code https://github.com/duneroadrunner/SaferCPlusPlus#getting-sta... [2] https://github.com/duneroadrunner/SaferCPlusPlus-AutoTranslation https://github.com/duneroadrunner/SaferCPlusPlus-AutoTransla...
- xiphias2 7y agoThanks, it's really cool. I hope it gets enough backing from corporations that have big/huge C++ code bases.