3 ms·
Compile time guarantees that you didn’t access memory you didn’t really “own”. Dangling pointers are not a thing. No double free. Forces you to think up fron
by whb07 5y ago
Compile time guarantees that you didn’t access memory you didn’t really “own”.
Dangling pointers are not a thing.
No double free.
Forces you to think up front about what are the possible state something could be in, and so you won’t get runtime or weird UB.
lastly, to be more pedantic for everyone who is at Linus-levels, it’s like all the best static analysis and warnings/errors all rolled up natively into the language. Please don’t bombard me with “but I can just run clang’s X and get the same thing”. No you can’t, and if you did this forces you to run it regardless.
- The_rationalist 5y agoIt's quite trivial to enforce the use and absence of X warnings/error from a static analysis tool Y during merge review and CI. C++ with ASAN enforced is quite close, not compile time granted but much more familiar. Btw there are lifetime checker for c++ in development.
- emilfihlman 5y agoAll easily achievable with gcc. Yes, we can.
- bicolao 5y agoPlease show us how. I don't think these can be achieved within current C semantics.
- masklinn 5y agoIn full anyway. Limited subsets? Sure, if you assign a null and immediately try to deref' it Clang and GCC will probably notice and yell at you.
- whb07 5y agoWell, no. You’re talking about using all the flags and tooling like i just mentioned, which 99.99% of people don’t use every time they run a build. Even then the best and strictest of flags + Werror still falls short. Then you still have to run extensive fuzzing and testing to trigger different paths and whatnot. Or you could just use Rust.