4 ms·
> since C doesn't ... check for overflows Because it's a language, not an implementation. An implementation is free to do so (and there are such implementation
by dependenttypes 6y ago
> since C doesn't ... check for overflows
Because it's a language, not an implementation. An implementation is free to do so (and there are such implementations after all).
- quelsolaar 6y agoThat's correct! C doesn't require checking for overflows, but it also doesn't forbid implementations from doing so. both are features.
- Koshkin 6y agoI don’t think it is possible, not without changing some parts of the C’s specification. At the very least you’d need to be able to somehow encode the length of the buffer in the pointer to it. (There is no semantic difference between a pointer to a simple, fixed-length variable and a pointer to an array.)
- bawolff 6y agoWhich is what the article proposed.
- quelsolaar 6y agoYou can keep a list of every allocation and every time the code does a memory read/write the implementation can look up to see if the pointer is within a valid allocation space. I have implemented some things like this: https://www.youtube.com/watch?v=pvkn9Xz-xks https://www.youtube.com/watch?v=pvkn9Xz-xks
- pjmlp 6y agoWhich is what hardware implementations like Solaris SPARC do.
- dependenttypes 6y agovoid f(size_t n, int v[n]) is valid C.
- Koshkin 6y agoSemantically though, the second argument is still just a naked pointer.
- david2ndaccount 6y agoThat’s why you use the proper declaration of void f(size_t n, int (*v)[n]) instead.
- dependenttypes 6y agoIs it? I am pretty sure that v[x] where x >= n is UB.