4 ms·
You can even "leak" memory in java if you keep references to objects you don't need anymore xD Also what is the point of .at()? try { myarray.at(invalid_
by randomNumber7 2y ago
You can even "leak" memory in java if you keep references to objects you don't need anymore xD
Also what is the point of .at()?
try {
myarray.at(invalid_index);
} catch(std::exeception& e){
// how do you handle a logic error in your code?
// does that even make sense philosophically?
}
Yet you could also enable bounds checking for debugging on operator [] or use address sanitizer.
- pjmlp 2y agoContrived examples like that can be done in any programming language.
- Someone 2y agoNitpick: the index could come from program input. For example: - if one were to write ‘ed’ in C++, that could be the code that handles going to the n-th line. - in a lzw decompressor, it could be an integer read from the to-be-decompressed data stream. In both cases, using at rather than doing a range check first can be defended because failing the range check is an exceptional case.
- imtringued 2y agoEvery now and then you get comments like this, that are intentionally offensive, like a burning bag of poop. The point of .at() is to check the bounds at runtime. Here is your answer. Regarding the comments. You don't necessarily know if it is a logic error and you certainly don't know if it is in your code. Now onto the how. You handle it like any error. If you don't have a specific error handling strategy, you handle the error at a higher level e.g. your HTTP server returns a 500 http status code and logs the error and the location, so that the developer can fix the bug. As to whether it makes sense philosophically. The only limitation is your lack of imagination. In C, the program would keep executing and create a security problem. The fact that the exception handler got called in the first place implies that at least the security vulnerability has been averted, meaning that you did indeed recover from the error, even if the catch block is completely empty.
- randomNumber7 2y agoUsually it is a logic error, because you can check the index before. You could argue it is ok when you use exceptions for control flow (e.g. what people sometimes do in python), but even there it looks questionable imo.
- MaxBarraclough 2y ago> you can check the index before You can check manually, but we know programmers can't be trusted to do so correctly every time. There's an ocean of security vulnerabilities because of this, as out-of-bounds access of a raw array is undefined behaviour in C and C++. It makes good sense to use at in debug builds especially, where you're less concerned about the performance penalty. In C++ you can define a macro to select between at and [], and while this isn't exactly pretty, it does work: #ifdef DISABLE_RANGE_CHECKS #define AT_METHOD operator[] #else #define AT_METHOD at #endif #include <vector> // ... i = my_vector.AT_METHOD(my_idx); > even there it looks questionable imo Why? Its behaviour is pretty much strictly better than that of raw []. The only downside is a possible performance hit.
- MaxBarraclough 2y ago> how do you handle a logic error in your code? does that even make sense philosophically? In some contexts sure, there's not really much you can do, but in many others it's perfectly clear. In a request-oriented system like a web server, you stop the failed request-handling logic and send back an error code. Exceptions can make this quite natural to implement. Much better than letting the error go undetected, invoking undefined behaviour, and risking mishandling of future requests, or perhaps even a serious security vulnerability. > Yet you could also enable bounds checking for debugging on operator [] or use address sanitizer. I'd flip that around. Why bother with additional platform-specific cleverness when the standard library already gives you what you're after?