3 ms·
The reason they don't communicate their bounds is also a performance optimisation. You can certainly do it in C++; use a std::vector for e.g. and use the .at()
by physicsguy 3y ago
The reason they don't communicate their bounds is also a performance optimisation. You can certainly do it in C++; use a std::vector for e.g. and use the .at() method to index on it and it'll throw an exception unless you disable that with a compiler flag.
The thing is, it's fine to take that risk if you're writing HPC simulation software, but it's much less fine if you're writing an operating system or similar.
- pizlonator 3y agoYeah, “also” a performance optimization. It’s also just legacy. We’ve always done it that way so we still do it that way for ABI compat and because it’s hard to find a compiler that does it any other way. Imagine if the story was: “you totally can have a bounds on your ptrs if you pass a compiler flag and accept perf cost”. I bet some of us would find that useful.
- chlorion 3y agoThe performance and power use cost to checking bounds is trivial! Apple has tested this, on mobile devices even, when working on -fbounds-safety. From the slides: System-level performance impact • Measurement on iOS • 0-8% binary size increase per project • No measurable performance or power impact on boot, app launch • Minor overall performance impact on audio decoding/encoding (1%) • System-level performance cost is remarkably low and worth paying for the security benefit Some more specific synthetic benchmarks suites reported ~5% runtime cost for bounds checking. https://www.youtube.com/watch?v=RK9bfrsMdAM https://www.youtube.com/watch?v=RK9bfrsMdAM https://llvm.org/devmtg/2023-05/slides/TechnicalTalks-May11/01-Na-fbounds-safety.pdf https://llvm.org/devmtg/2023-05/slides/TechnicalTalks-May11/... Bounds checking being omitted due to performance is mostly a myth, the only time this should ever be believed is in very specific circumstances such as performance critical code and when the impact has actually been measured!
- physicsguy 3y agoWhether it's trivial or not depends totally on the workflow. A 5% runtime cost can be enormous - when I was in academia I was running thousands of simulations on big clusters like ARCHER, some of which could take up to a fortnight to run. In those cases, a 5% cost can add a whole other working day to the runtime!
- deathanatos 3y ago> Whether it's trivial or not depends totally on the workflow. People here are talking about language defaults, and that the default should be safe, and while, yes, technically you can construe a workflow they're not going to work for, they work for most. That doesn't prevent your ARCHER simulation from calling — hopefully only at sites that profiling indicates need it — .yolo_at(legit_index_totes) (or whatever one might call the method) & segfaulting after burning a few days worth of CPU time away.
- paulddraper 3y agoDo you believe that is a common case, or an exceptional one?
- physicsguy 3y agoI don't think it's particularly exceptional for the sorts of people that are still using C++ (and making a conscious decision to do so over Rust for e.g.). If you're writing 'standard' C++ these days, you're probably already making use of std::array, std::vector, etc. anyway. The only area where people are working on modern codebases I've not seen so much of that is in HPC stuff and embedded.
- JohnFen 3y ago> You can certainly do it in C++ You can do it in C as well, although it's a lot clunkier. I've been doing so for decades when the effort is appropriate to the task.