4 ms·
I don't not think that English isn't difficult to parse. I agree completely that it's all about the code you write. You can write nice C++ that is easy to unde
by bArray 4y ago
I don't not think that English isn't difficult to parse.
I agree completely that it's all about the code you write. You can write nice C++ that is easy to understand, easy to debug, and that you can be quite certain is bug free.
Something like Rust appears to eliminate one class of bugs, but then people still write bugs. Just look at the Rust language issue tracker on GitHub [1].
Fundamentally, you cannot get around the need for good code design. Any useful programming language will always have the ability to mishandle data.
[1] https://github.com/rust-lang/rust/issues https://github.com/rust-lang/rust/issues
- galangalalgol 4y agoRust doesn't create any new classes of bugs, and it eliminates some old ones. Isn't that all positive? Rust also turns a lot more bugs from UB and/or exploitable, into a panic. That is still potentially a ddos, but it is better than code injection. And therebare tools like prusti to find panics, and you can use tricks with linking a nostd library to see if you got them all. Probably better ways than that now. We can obviously write bugs in any language, but it is just as obvious that some languages make finding some bugs easier. Rust makes some bugs easy to find, the compuler points them out, and unless it makes other bugs harder to find it is all upside (from the correctness standpoint, not all standpoints)
- kllrnohj 4y ago> Rust also turns a lot more bugs from UB and/or exploitable, into a panic. Sadly for some of them (like integer overflow), that's only true in debug builds. Having a debug build that just force-enables santizers is a great thing, but also one easily replicated in a C/C++ ecosystem, too.
- hra5th 4y agoRust integer overflow bugs in release mode are still much safer than C++ integer overflows -- Rust integer overflow is well-defined to wrap in release mode, whereas it is UB in C++.
- kllrnohj 4y agoThat's not meaningfully safer which is why it's still a panic in debug builds. It's really just kinda worse even. You can't use it as a programmer (because it panics) and the compiler can't use it even though you've already promised (and debug mode verified) that it never happens.
- galangalalgol 4y agoIf you want an add to wrap, you should use a wrapped_add, useful for angle math or whatever. If you want it to saturate, use a saturating_add, and if you want to check for overflow, use a checked_add. If I were to write a rust coding standard it would prohibit + in favor of explicitly using those functions.