4 ms·
Compilers such as clang/LLVM and GCC do support a memory-safe mode (e.g. AddressSanitizer) which is not what you want because they add large overheads and thus
by dataking 6y ago
Compilers such as clang/LLVM and GCC do support a memory-safe mode (e.g. AddressSanitizer) which is not what you want because they add large overheads and thus are not intended for production use.
There's an ongoing effort to design extensions to C that allows efficient enforcement of memory safety, Checked C from Microsoft Research is an interesting and current effort in this direction.
For all the challenges of getting comfortable with Rust (which I 100% acknowledge), it does provide a very interesting tradeoff between performance, safety, and compatibility with C.
- rcxdude 6y agoAsan and co are not just not intended/recommended for production use because of performance issues. They are designed as debugging aids, not security hardening features. As such they are likely to introduce security vulnerabilities, not prevent them (they effectively expose a larger attack area).