4 ms·
> If you’re applying arbitrary invariants that aren’t codified in the type system, you may as well just use raw pointers. This isn’t really true, as the charac
by kd5bjo 5y ago
> If you’re applying arbitrary invariants that aren’t codified in the type system, you may as well just use raw pointers.
This isn’t really true, as the character of bug produced is quite different between the two cases. If you make a mistake with offsets, you’ll get a runtime panic that tells you exactly where the problem occurred. If you make the same mistake with raw pointers, however, you’ll get corrupted memory somewhere which won’t necessarily show up as a problem until long after the erroneous code is executed.
- wokwokwok 5y agoWho honestly cares? I sure don’t. Yes, there is a distinction, yes one is worse than the other, but if you got a panic, your application terminated. You’re screwed either way, web server or desktop app; fortunately there’s a simple solution: use whatever means you like to write a safe abstraction that enforces invariants. I’m not advocating particularly for unsafe code; but avoiding unsafe and writing code that blatantly panics at the drop of a hat is ridiculous. Invariants should be enforced by the type system. I don’t care how; if you’re not doing that and just assuming your strings are shorter than 256 characters, you’re writing code that is unsound.
- volta83 5y ago> You’re screwed either way, Not really. If the application terminates, it is infinitely easier to catch this during testing. If the application silently continues, that might be an exploitable security vulnerability, might result in corruption of pretty much anything (data-bases, loss of user data, ...). Pretty much everybody with an exposed web-server would prefer it to terminate with a nice debug message over the alternatives that using raw-pointers would cause. > you’re writing code that is unsound. No you are not, code using offsets is perfectly sound because it does not exhibit undefined behavior (which is how "soundness" is defined in Rust). Your suggestion of using unsafe instead of offsets here would indeed be unsound. Don't do that. > but avoiding unsafe and writing code that blatantly panics at the drop of a hat is ridiculous. This is the most retarded thing I've read all day. `assert` is a tool used on _many_ standard library API to ensure soundness. > I don’t care how; if you’re not doing that and just assuming your strings are shorter than 256 characters, you’re writing code that is unsound. I really have no idea why you sound so angry, but the claim that someone anywhere in this thread is "assuming your strings are shorter than 256 characters" is completely made up. Nobody has suggested that. The offset optimization that the OP proposed is trivial to implement correctly even without bound checks (just put an assert on the methods that take &mut self to ensure that the string doesn't grow beyond that).