4 ms·
The implementation of the Rust abstract machine - miri - stops execution of Rust programs when they exhibit undefined behavior. C, C++, etc. don't even have im
by volta83 5y ago
The implementation of the Rust abstract machine - miri - stops execution of Rust programs when they exhibit undefined behavior.
C, C++, etc. don't even have implementations of their abstract machines. They don't have one existing as a goal. And they are happy to make certain operations exhibit undefined behavior even if that implies that it would make an implementation of the abstract machine that traps impossible.
This is why even if you were to combine valgrind with address sanitizer, memory sanitizer, thread sanitizer, undefined-behavior-sanitizer, and other existing C and C++ tools, there is still a lot of classes of undefined behavior that these tools can't detect.
That's fine in C and C++, but not fine in Rust. In Rust, if we add a new type of undefined behavior, the constraint is that it should be (demonstrably) possible to extend miri to detect it, such that if a user doesn't know whether some program exhibits undefined behavior for some inputs, they can just run it under miri, and miri will precisely pinpoint which part of their code exhibited undefined behavior and why, and how their program execution got there.
- littlestymaar 5y agoThanks! > This is why even if you were to combine valgrind with address sanitizer, memory sanitizer, thread sanitizer, undefined-behavior-sanitizer, and other existing C and C++ tools, there is still a lot of classes of undefined behavior that these tools can't detect. Do you have specific examples of such UB?
- volta83 5y agoSure: TBAA, access to invalid union field (in C++), etc. Many of them are impossible in theory to check, and many are impossible to efficiently check in practice.