3 ms·
> Because usize has a platform-dependent size and generally the logic of the program should be platform-agnostic. Fair point, but it really only matters if the
by proto_lambda 4y ago
> Because usize has a platform-dependent size and generally the logic of the program should be platform-agnostic.
Fair point, but it really only matters if the overflow is handled gracefully. If it's handled as an unrecoverable error condition, it often 1. doesn't happen during normal operation and 2. can be invoked by a determined attacker, regardless of the exact size. Sure, the exact characteristics might be different, but in the end it doesn't make much of a difference.
Petgraph has a great API, and in general using newtypes over integers for collection indices is a great way to avoid another logic bug: mixing up indices for different collections.
- nextaccountic 4y agoDefining a newtype avoids confusing indexes of, say, a graph and a Vec, but doesn't avoid confusing indexes of two graphs Rust has a design pattern called lifetime branding (also called generativity), which uses phony lifetimes to prevent, at compile time, confusing indexes of two separate collections of the same type. This can also enable disabling out of bounds checks without triggering UB (because, with branding, we can be sure that the index is on bounds at the moment of creating it; essentially we move bounds check from the indexing time to the index creation time) Here's an earlier mention of that [0] (7 years ago), and here's a crate from 3 years ago, indexing [1] but I'm not sure about recent developments on that. Now, petgraph doesn't use branding for its index types, so if you have two graphs you can confuse their indexes. On the other hand, petgraph was specifically designed so that you can reuse the node and edge numbering across many graphs (so that if you have a subgraph for example, the nodes and edges share the same ids), in this situation it's kind of hard to use branding There's another pattern for not confusing index types which is to make different index types for each different collection and make the collection work only with that type; this is done eg. in typed-indexed-collections [2] - but it doesn't use branding so two collections with same index type have interchangeable indexes Anyway right now this stuff is mostly folklore but I wish it were more used. [0] https://www.reddit.com/r/rust/comments/3oo0oe/sound_unchecked_indexing_with_lifetimebased_value/ https://www.reddit.com/r/rust/comments/3oo0oe/sound_unchecke... [1] https://github.com/bluss/indexing https://github.com/bluss/indexing https://docs.rs/indexing/0.4.1/indexing/ https://docs.rs/indexing/0.4.1/indexing/ https://crates.io/crates/typed-index-collections https://crates.io/crates/typed-index-collections https://www.reddit.com/r/rust/comments/hr6xcu/announcing_typedindexcollections_010_slice_and/ https://www.reddit.com/r/rust/comments/hr6xcu/announcing_typ...