4 ms·
Story time: Chrome is a Frankenstein of C and C++ code (both directly and through called libraries, static or dynamic). Now C++ has `std::string` obviously. C o
by cletus 2y ago
Story time: Chrome is a Frankenstein of C and C++ code (both directly and through called libraries, static or dynamic). Now C++ has `std::string` obviously. C of course has `const char *`. To facilitate interoperability C++ has various methods to implicitly or explicitly convert between the two.
At one point it was found these every keypress on the OmniBar resulted in 25,000 string copies.
So my point is that you can write C++ as carefully as you can but on any sufficiently complex code base you'll going to need a pointer to something and then you've really lost all control and safety so the safety in C++ is a bit of an illusion.
- senkora 2y agoWell, that's horrifying. Presumably the value is being copied whenever it is converted from a const char * to a std::string? The right thing (TM) would probably be to refactor some of the std::string's into std::string_view's, for instance by adding overloads where it makes sense. I doubt you could avoid all the copies, but I think you could cut it down substantially if you collected metrics and focused on the most egregious cases. Of course, I do not envy the person who is tasked with doing that, and I could be wrong for any number of arcane technical reasons.
- dralley 2y agoI can only imagine that using std::string_view in a massive, complex application would be horrifying. The borrow checker is one of the benefits of Rust in that case, simply because you can avoid copies while actually being able to trust that you're not opening the door to security & maintenance hell in the process.
- benmmurphy 2y agoa lot of the copies might be bits of code defensively copying the string because they don't want to deal with working out lifetime safety.
- steveklabnik 2y agoFun fact: this happened during the standardization of std::string_view, which ended up landing in C++17, a few years after this was fixed. Not that there weren't non-standard versions that existed. In the end they did a number of things to fix this, the patches are linked in the story I linked above. std::string_view has seemed, to this relative outsider, to be semi-controversial. It makes it pretty easy to introduce use after frees, that it's not null terminated can be easy to forget, and isn't bounds checked. So while it helps with some issues, it can create others, meaning it's not always a clear win.
- steveklabnik 2y agoHN thread on this story: https://news.ycombinator.com/item?id=8704318 https://news.ycombinator.com/item?id=8704318
- overgard 2y agoFair but I never said it was safe, just that perfect safety isnt of interest to me