3 ms·
To be fair, this sort of thing doesn't have to be so much worse in C++ (yes, it would have been nice if it had been built into the language itself to begin with
by spyrja 1y ago
To be fair, this sort of thing doesn't have to be so much worse in C++ (yes, it would have been nice if it had been built into the language itself to begin with). You just need a function to do a back-and-forth conversion which then double-check the results, ie:
#include <exception>
#include <sstream>
template <typename From, typename To>
void convert_safely_helper_(From const& value, To& result) {
std::stringstream sst;
sst << value;
sst >> result;
}
// Doesn't throw, just fails
template <typename From, typename To>
bool convert_safely(From const& value, To* result) {
From check;
convert_safely_helper_(value, *result);
convert_safely_helper_(*result, check);
if (check != value) {
*result = To();
return false;
}
return true;
}
// Throws on error
template <typename To, typename From>
To convert_safely(From const& value) {
To result;
if (!convert_safely(value, &result))
throw std::logic_error("invalid conversion");
return result;
}
#include <iostream>
template <typename Buy, typename Quantity, typename Price>
void sendOrder(const char* symbol, Buy buy, Quantity quantity, Price price) {
std::cout << symbol << " " << convert_safely<bool>(buy) << " "
<< convert_safely<unsigned>(quantity) << " " << convert_safely<double>(price)
<< std::endl;
}
#define DISPLAY(expression) \
std::cout << #expression << ": "; \
expression
template <typename Function>
void test(Function attempt) {
try {
attempt();
} catch (const std::exception& error) {
std::cout << "[Error: " << error.what() << "]" << std::endl;
}
}
int main(void) {
test([&] { DISPLAY(sendOrder("GOOG", true, 100, 1000.0)); });
test([&] { DISPLAY(sendOrder("GOOG", true, 100.0, 1000)); });
test([&] { DISPLAY(sendOrder("GOOG", true, -100, 1000)); });
test([&] { DISPLAY(sendOrder("GOOG", true, 100.5, 1000)); });
test([&] { DISPLAY(sendOrder("GOOG", 2, 100, 1000)); });
}
Output:
sendOrder("GOOG", true, 100, 1000.0): GOOG 1 100 1000
sendOrder("GOOG", true, 100.0, 1000): GOOG 1 100 1000
sendOrder("GOOG", true, -100, 1000): GOOG 1 [Error: invalid conversion]
sendOrder("GOOG", true, 100.5, 1000): GOOG 1 [Error: invalid conversion]
sendOrder("GOOG", 2, 100, 1000): GOOG [Error: invalid conversion]
Rust of course leaves "less footguns laying around", but I still prefer to use C++ if I have my druthers.
- pjmlp 1y agoYes, from safety point of view Rust is much better option, however from the ecosystems I care about (language runtimes and GPU coding), both professionally and as hobby, C++ is the systems language to go, using Rust in such contexts would require me to introduce extra layers and do yak shaving instead of the actual problem that I want to code for.
- spyrja 1y agoWell, precisely. Such is the price of "general-purpose safety". The biggest irony IMO is that the security features of Rust are so often skirted in the name of speed, efficiency, etc, with the end result being a program which isn't much more secure than its C++ equivalent. ¯\_(ツ)_/¯
- steveklabnik 1y ago> The biggest irony IMO is that the security features of Rust are so often skirted in the name of speed, efficiency, etc, with the end result being a program which isn't much more secure than its C++ equivalent. Citation needed. The empiric evidence I’ve seen has shown the opposite.
- spyrja 1y agoOverall it does indeed seem to be the case for roughly 25% of Rust crates: https://rustfoundation.org/media/unsafe-rust-in-the-wild-notes-on-the-current-state-of-unsafe-rust/ https://rustfoundation.org/media/unsafe-rust-in-the-wild-not... https://thenewstack.io/unsafe-rust-in-the-wild/ https://thenewstack.io/unsafe-rust-in-the-wild/ https://github.com/sslab-gatech/Rudra/blob/master/rudra-sosp21.pdf https://github.com/sslab-gatech/Rudra/blob/master/rudra-sosp... https://internals.rust-lang.org/t/canvas-unsafe-code-in-the-wild/4990/16 https://internals.rust-lang.org/t/canvas-unsafe-code-in-the-... Again, not a criticism of the language itself per se, and certainly not trying to imply that all Rust programmers go around writing unsafe code all day long. It's just kind of funny to me that it is touted as being so much more safe than C++ when the reality is that at least some of those features are in fact disabled for one reason or another in real-world programs.
- steveklabnik 1y ago> Most of these Unsafe Rust uses are calls into existing third-party non-Rust language code or libraries This is very different than > in the name of speed, efficiency, etc And also does not demonstrate that > the end result being a program which isn't much more secure than its C++ equivalent. At all.