28 ms·
GCC 10.1 Released
- DyslexicAtheist 6y agoI love the built-in static analyzer -fanalyzer option in gcc-10. [1] https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.html https://gcc.gnu.org/onlinedocs/gcc/Static-Analyzer-Options.h...
- ufo 6y agoWhat do you love the most about the new analyzer pass? I haven't had a chance to try it out for myself yet but I'm looking forward to it.
- htfy96 6y agoAn example to detect use-after-free: https://godbolt.org/z/zhiNLW https://godbolt.org/z/zhiNLW Basically this replicates what clang-tidy did
- cornstalks 6y agoToo bad it doesn't detect the mismatch between new and free.
- peapicker 6y agoAnd if you fix it to use delete instead of free, you get "can't delete void *" errors. Perhaps not the best example code.
- DyslexicAtheist 6y agoI like not having to run another commercial tool[1] that will likely not be in use whenever I move on to the next project because no one has heard of it. Biggest advantage I see is it's integrated into the compiler and so sees the same things the compiler does. Having gcc do this out of the box helps people port their experience/skills with static analysis to other companies. We already have clang-tidy and I like it too but it's nice to have a fall-back to compare when one produces a strange result. And a bit of competition is always good to have between such projects. And on most big projects it's not like you can just change the build system to use another compiler. Also I found some interesting cases which valgrind didn't see because it was in an unreachable branch. [1] https://news.ycombinator.com/item?id=22712338 https://news.ycombinator.com/item?id=22712338
- glouwbug 6y agoImagine if -fanalyze was like rusts borrow checker
- simias 6y agoYou Rust borrow checker requires special annotations and restrictions put on the code to do its job. I don't think you could something like that automatically on a C or C++ full codebase without having to manually annotate and refactor it somewhat. There are many common (and safe) C and C++ patterns that would be outright rejected by Rust's borrow checker, for instance initializing a structure or array partially if you're sure that nobody is going to use the initialized portion. Or having multiple mutable pointers/reference to the same object. You could do something like that at runtime though, but then you have Valgrind, basically.
- pkolaczk 6y ago> Rust borrow checker requires special annotations and restrictions put on the code to do its job. This is a good thing, because it makes lifetimes and ownership explicit and visible in the code. It serves the similar purpose as type annotations in function signatures. > Or having multiple mutable pointers/reference to the same object Sure you can have that with `unsafe`. And this is a good thing, because multiple mutable pointers to the same object is at best bad coding practice that leads to unsafe code, and you should avoid that in any language, including the ones with GC. Working with codebases where there are multiple distant things mutating shared stuff is a terrible experience. If a C/C++ version of "borrow checker" could mark such (anti)patterns at least as warnings, that would bring a lot of value.
- verdagon 6y agoCan you explain why multiple mutable pointers is bad practice? I understand the benefits and the risks of them, and understand how Rust prevents both, but I dont yet understand why it's bad practice, and am interested to learn why.
- 6y ago
- qalmakka 6y agoIsn't it very similar to something Clang has had for years?
- legends2k 6y agoTangential: I think many platforms that GCC supports and the kind of optimisation GCC provides might make it a superior choice for projects. For those developers its exciting. Also if an existing project is using it for a long-time and has not intentions of switching to Clang, for them too this would be interesting.
- CoolGuySteve 6y agoMy project uses g++ but I’ve been using a clang static-analysis step in my CI pipeline for a while now. Compiling with clang is much, much slower but it finds interesting errors sometimes. I only had to ifdef out one code section that it couldn’t understand (something about indexing an array with a constexpr function returning an enum class from a template parameter). It depends on the project, but this one and another project I made work are both 100k lines of C++ and took half a day to setup. It was worth it imo.
- tele_ski 6y agoInteresting that your build times are slower with clang. I've found on most of my projects clang is roughly 30% faster to compile in debug, but release I haven't seen a huge difference between the two.
- petters 6y agoPerhaps they are slower because Clang is doing static analysis in this case.
- CoolGuySteve 6y agoStatic analysis is a lot slower but regular clang++ is also significantly slower than g++, like a 4-5 minute build time vs 2:30 on g++. It might have something to do with a heavy usage of templates in a few files, I don't know. Clang's autovectorization is better in a few functions I disassembled but otherwise the generated code doesn't benchmark any faster, it's better in some places, worse in others.
- rwmj 6y agoReally? I tried to use it but I got a lot of false positives - in fact, every one of the errors in my medium-sized codebase was I believe a false positive. I spent a few hours last night looking at all of them and while I found a missing free, it was not one picked up by this analysis, but it happened to be in the same code that the analyzer flagged. Also the error messages are enormous in some cases. It does show potential, and I hope it improves in future. Be nice to have a libre version of coverity one day. Edit: Output from compiling nbdkit upstream with -fanalyzer: https://paste.centos.org/view/8381f926 https://paste.centos.org/view/8381f926
- google234123 6y agoSadly, that's typical with static analyzers todays...
- asveikau 6y agoLooking at the categories of warnings it produces, I'm not surprised. When I've used similar tools trying to detect the same things, I also saw false positives. It's probably not an easy set of problems, otherwise we'd have it built-in to more tools and enabled by default.
- rwmj 6y agoWe routinely run nbdkit through Coverity and it finds bugs, although it too has false positives. Also the reports produced by Coverity are really nice - long enough to tell you where the bug is, but not too long to be overwhelming. I've been meaning to formally prove one of our internal "mini libraries" using Frama-C. If we did that then no one would be able to complain about bugs in it :-)
- cozzyd 6y agoExcited for this to come to gcc-arm-eabi-none
- liquidify 6y agowish gcc 10 was built into ubuntu 20.04
- RMPR 6y agoGCC 10 is in Fedora 32 though https://fedoramagazine.org/announcing-fedora-32/ https://fedoramagazine.org/announcing-fedora-32/
- Twirrim 6y agoYou want a bleeding edge release in your non-bleeding edge LTS distribution?
- jcelerier 6y agoit does not make sense to pair development toolchain versions with operating system versions.
- klodolph 6y agoWhat do you think LTS entails, exactly? One of the core ideas of working with LTS is that you can build your software on an LTS release and ship it to somebody else on the same LTS release, either as a source or as a binary. If you want the latest GCC, that's fine, you're not forced to use the default compiler distributed with your OS. But it doesn't make sense to update the default compiler used in an LTS release. If you want that, then you don't want LTS.
- jcelerier 6y ago> One of the core ideas of working with LTS is that you can build your software on an LTS release and ship it to somebody else on the same LTS release, either as a source or as a binary. Yes, and updating compilers don't prevent that at all. You can use GCC 10 to ship code that will build and run on Ubuntu 12.04 without issues. Xcode 11 can ship code that works back to macOS 10.6 and Visual Studio 2019 can still optionally target windows fucking XP !
- greendave 6y ago> Several C++20 features have been implemented: > P0912R5, Coroutines (requires -fcoroutines) Nice to see a bunch of C++20 features making it in. Coroutines seems like a big one!
- vmchale 6y agoLovely! Time to see my code go even faster, for free :)
- super_mario 6y agoIt doesn't seem to be available on the main site or any of the mirrors I tried.
- chrisseaton 6y ago> It doesn't seem to be available on the main site Surely it's available from here at the very least? https://gcc.gnu.org/git.html https://gcc.gnu.org/git.html > or any of the mirrors I tried Seems to be to me? ftp://ftp.mirrorservice.org/sites/sourceware.org/pub/gcc/releases/gcc-10.1.0/
- movieswebsite 6y agohttps://tezmovieswebsite.blogspot.com/2020/05/hacked-full-cast-crew-release-date.html https://tezmovieswebsite.blogspot.com/2020/05/hacked-full-ca...
- MauranKilom 6y ago> Extended characters in identifiers may now be specified directly in the input encoding (UTF-8, by default), in addition to the UCN syntax (\uNNNN or \UNNNNNNNN) that is already supported: static const int π = 3; int get_naïve_pi() { return π; } Lovely!
- q92z8oeif 6y agoi don't know if you are being ironic or not, but the non-english speaking world will love it.
- throwaway894345 6y agoThere are lots of other languages that support full UTF-8 in identifiers (e.g, Go) and the non-English-speaking world doesn't take advantage.
- erik_seaberg 6y agoSome do: https://news.ycombinator.com/item?id=14276891 https://news.ycombinator.com/item?id=14276891
- throwaway894345 6y agoI've done a similar thing when I was writing a language (with generics) that compiled to Go and needed to implement name mangling. But in any case, this isn't an example of a non-native speaker using utf-8 to write in his native language. :)
- rurban 6y agoEvery such such language does it insecurely. The only exceptions are Java, rust and cperl. I rather have no unicode identifiers than insecure identifiers, which don't follow the unicode security guidelines for identifiers.
- alufers 6y agoAs a non-English programmer who has seen a lot of code not written using English please, god, NO. The mixture of English and other languages identifiers in the external libraries makes me cry.
- wiz21c 6y ago(side note for RMS, I still have a "RUNGCC" sticker on my car (it's been 5 years !!!))
- FullyFunctional 6y agomemory.c: In function ‘mk_entry’: memory.c:116:12: internal compiler error: in saved_diagnostic, at analyzer/diagnostic-manager.cc:84 116 | return (struct entry) {safe_calloc(end - start, 1), start, end}; | ^ Please submit a full bug report, Goes to look at README.Bugs. Holy cow, I don't have time to to check all those places to see if it has been reported already.
- userbinator 6y agoEvery time I look at GCC's bugtracker, I feel a mix of disgust and astonishment at the state of such a foundational piece of software. I'm amazed it works as well as it does.
- canarypilot 6y agoThe GCC community is normally very good (if blunt) at picking up duplicate bugs and linking them to the right place. https://gcc.gnu.org/bugzilla/ https://gcc.gnu.org/bugzilla/ Is all you need. Just don’t feel bad if your bug is closed!
- FullyFunctional 6y agoThanks, it was fixed already :)
- ryuukk_ 6y agoctrl + f: modules 0 results i guess clang and msvc won the fight