3 ms·
I'm not sure how using an unsigned number would help, given that when it overflows you're still going to have some code do unexpected stuff anyway.
by FreeFull 6y ago
I'm not sure how using an unsigned number would help, given that when it overflows you're still going to have some code do unexpected stuff anyway.
- mcguire 6y agoFor one thing, it's a clue you need to step back and think, "What happens when this overflows?" rather than "Oh, it's just a number." For another, that's why you get paranoid. (For a third, I strongly recommend something like Frama-C with the Weakest-Precondition module---it's very good at finding issues like these.)
- sleepydog 6y agoI'm not convinced that it would have been any more obvious to the person who made the error that the variable could overflow if it were unsigned. It's also much easier, IMO, to accidentally underflow an unsigned integer; it's so much more common to work with 0 than it is to work with +/- 2 billion.
- karagenit 6y agoI'm being pedantic, but technically wrapping from 0 to MAX_INT is still considered overflow. Underflow refers to decimal truncation e.g. by integer division.
- koheripbal 6y agowell... at least it takes twice as long to overflow.