4 ms·
Same. I go one step further and create a macro _STOP which is defined as w/e your language's DebugBreak() is. And if it's really important, _CRASH (this coerces
by YesBox 10mo ago
Same. I go one step further and create a macro _STOP which is defined as w/e your language's DebugBreak() is. And if it's really important, _CRASH (this coerces me to fix the issue immediately)
- creato 10mo agoThe "standard" (typically defined in projects I'm familiar with, and as of C23, an actual standard) is "unreachable": https://en.cppreference.com/w/c/program/unreachable.html https://en.cppreference.com/w/c/program/unreachable.html
- YesBox 10mo agoC++ keeps getting bigger and bigger :D Thanks for sharing
- creato 10mo agoThis is actually C and C++ has not done something similar AFAIK.
- hn_go_brrrrr 10mo agoFortunately the major compiler vendors all have. Routing around the standards committee is getting more and more common.
- Fulgen 10mo agohttps://en.cppreference.com/w/cpp/utility/unreachable.html https://en.cppreference.com/w/cpp/utility/unreachable.html
- TuxSH 10mo agoC++23 does have std::unreachable (as a function), and its counterpart [[assume(expr)]]
- vlovich123 10mo agoThat is not the same thing at all. Unreachable means that entire branch cannot be taken and the compiler is free to inject optimizations assuming that’s the case. It doesn’t need to crash if the violation isn’t met - indeed it probably won’t. It’s the equivalent of having something like x->foo(); if (x == null) { Return error…; } This literally caused a security vulnerability in the Linux kernel because it’s UB to dereference null (even in the kernel where engineers assumed it had well defined semantics) and it elided the null pointer check which then created a vulnerability. I would say that using unreachable() in mission critical software is super dangerous, moreso than an allocation failing. You want to remove all potential for UB (ie safe rust with no or minimal unsafe, not sprinkling in UB as a form of documentation).
- creato 10mo agoYou're right, the thing I linked to do does exactly that. I should have read it more closely. The projects that I've worked on, unconditionally define it as a thing that crashes (e.g. `std::abort` with a message). They don't actually use that C/C++ thing (because C23 is too new), and apparently it would be wrong to do so.
- uecker 10mo agoYou can use the standard feature with the unreachable sanitizer: https://godbolt.org/z/3hePd18Tn https://godbolt.org/z/3hePd18Tn
- skepti 10mo agoFor many types of projects and approaches, avoiding UB is necessary but not at all sufficient. It's perfectly possible to have critical bugs that can cause loss of health or life or loss of millions of dollars, without any undefined behavior being involved. Funnily enough, Rust's pattern matching, an innovation among systems languages without GCs (a small space inhabited by languages like C, C++ and Ada), may matter more regarding correctness and reliability than its famous borrow checker.
- 10mo ago