6 ms·
Exceptions are not non-deterministic, although the control flow can be a bit non obvious of course. I think if you disallow exceptions you run into other probl
by captainmuon 3y ago
Exceptions are not non-deterministic, although the control flow can be a bit non obvious of course.
I think if you disallow exceptions you run into other problems. How can a constructor fail now? You need to have some kind of flag showing if an object is fully constructed. But then that goes against the idea to "make illegal states unrepresentable".
I do wish C++ had more tools to reign in exceptions. Maybe an "onlythrows X" annotation that says only these very specific exceptions may escape from a block, and the checker will complain if it cannot prove that only X can be thrown. The opposite of checked exceptions basically.
- jupp0r 3y agoThe constructor error problem is easily solved by using factory functions and two phase construction. The problem is that the standard library is relying on exceptions quite a bit and major parts become unusable.
- lelanthran 3y agoFor what definition of "easy"? Simply passing by value can result in a constructor that fails, while still bypassing any of the factory functions.
- jupp0r 3y agoEasy as in "competent C++ programmers do this every day"? If the copy constructor can fail and you don't want that, then delete it?
- lelanthran 3y ago> If the copy constructor can fail and you don't want that, then delete it? You're trivialising just how deeply embedded exceptions are into the design of the language. I gave just one example and it was not meant to be exhaustive, just one 'gotcha' that you won't find out till runtime and your program starts (worst case) giving you slightly incorrect results without you knowing about it... So, yeah, if you want to do without exceptions (without having your program execute random code) you need to know in advance what special cases to handle, like unintended copy construction, or failures in overloaded operators, or which std libs can be used and which cannot, or which C++ libraries can be linked, and which cannot. All of which is perfectly possible, but taken together is hardly "easy". It's tedious, error-prone, bloated ... but hardly what someone would call "easy".
- jupp0r 3y agoC++ is complicated, I get it. Things that are "easy" in other languages are "hard" in C++. That doesn't mean that writing C++ code that can't throw isn't something that tens of thousands of engineers are doing every day. One could argue that all of C++ is tedious, bloated and error-prone.
- kwant_kiddo 3y agoit is easy? It is the named constructor idiom. I don't understand why jupp0r is getting downvoted? Most big public c++ projects turn off exceptions, so it seems to be the norm more than anything.
- gpderetta 3y agoBecause two phase construction is a widely disliked idiom. Named constructors retuning optional objects are tolerable though.
- jupp0r 3y agoTwo phase construction isn't widely disliked, it's completely fine if it's used as an implementation detail of a factory.
- pjmlp 3y agoOnly the big public C++ projects that blindly follow Google's style guide, mostly.
- kwant_kiddo 3y agoI don't think this is true, but I don't know this for sure. From what I have read it seems that 'only' Bloomberg, Meta and Microsoft that uses c++ with exceptions. And since both microsoft and meta are adopting rust in their services it seems to me that they are looking for another language than C++. (why else adopt a new language?) Following seems not to use exceptions(?) LLVM: https://llvm.org/docs/CodingStandards.html#do-not-use-rtti-or-exceptions https://llvm.org/docs/CodingStandards.html#do-not-use-rtti-o... AWS: (seems to be using Google's guidelines to be fair) Webkit: https://gist.github.com/derofim/df604f2bf65a506223464e3ffd96a78a https://gist.github.com/derofim/df604f2bf65a506223464e3ffd96... Qt: https://doc.qt.io/qt-6/exceptionsafety.html https://doc.qt.io/qt-6/exceptionsafety.html gcc: https://gcc.gnu.org/codingconventions.html#Exceptions https://gcc.gnu.org/codingconventions.html#Exceptions Unreal: (not totally sure, but I think it uses error codes internally) Most of the embedded world. + any console game you ever played or heard of.
- jandrewrogers 3y agoHandling constructor failure is one of the least valuable use cases for exceptions. Idioms for exception-free construction are straightforward and some cases will require these idioms even with exceptions. Resource exhaustion or hardware failures are the more straightforward use cases for exceptions, but doing anything clever in those cases requires writing similar handling code as you would without exceptions.
- oytis 3y agoIn the domain where Misra is applied, resource exhaustion and hardware failures are totally valid scenarios that need to be processed in the same way as any other error.
- mgaunard 3y agoIt's actually the most useful one. It enables the creation of state invariants.
- GrumpySloth 3y agoMaintaining state invariants is trivial without exceptions thrown from constructors. Just make constructors private and write a public static factory method. Allowing exceptions in constructors on the other hand creates the problem of: what should the destructor of an only partially constructed object do? It’s just unnecessary.
- mgaunard 3y agoThe problem you mention doesn't exist, since destructors are not called when a constructor throws.
- GrumpySloth 3y agoIf you call mmap/VirtualAlloc/open/fopen in your constructor and later it throws, you will have a resource leak, because the destructor won’t clean it up.