3 ms·
> IMHO the zig footgun story with respect to UB behavior is largely unchanged relative to C/C++ The only major UB from C that zig doesn’t address is use after
by davemp 8mo ago
> IMHO the zig footgun story with respect to UB behavior is largely unchanged relative to C/C++
The only major UB from C that zig doesn’t address is use after free afaik. How is that largely unchanged???
Just having an actual strong type system w/o the “billion dollar mistake” is a large change.
- vlovich123 8mo agoDepends how you compile it. If you’re compiling ReleaseFast/ReleaseSmall, it’s not very different from C (modulo as you said it has some language features to make it less likely you do it): * Double free * Out of bounds array access * Dereferencing null pointers * Misaligned pointer dereference * Accessing uninitialized memory * Signed integer overflow * Accessing a union field for which the active tag is something else.
- dnautics 8mo agowow, what a list! all of these are statically analyzable using a slightly hacked zig compiler and a library! https://github.com/ityonemo/clr https://github.com/ityonemo/clr (Btw: you can't null pointer dereference in zig without using the navigation operator which will panic on null; you can't misalign a pointer unless you use @alignCast which will also create a panic)
- vlovich123 8mo agoNeat. Why isn’t this in the main compiler / will it be? I’m happy to retract my statement if this becomes actually how zig compiles but it’s not a serious thing as it’s more a PoC of what’s possible today and may break later
- dnautics 8mo agoIt will never be in the main compiler, since it was written by Claude. I think that's ok. The general concept is sound and won't break (modulo names of instructions changing etc). In fact it will get better. With the new io, concurrency checks will be possible But also, there is no reason why it should have to be in the main compiler. I've architected it as a dlload plugin. It's even crazier! The output is a zig program which you must compile and run to get the final result.
- pjmlp 8mo agoI can also analyse C and C++ code for such issues, while keeping using a mature languages ecosystem.
- dnautics 8mo agoIf you can statically analyze c for memory safety, why did pazlo bother building fil-C?
- pjmlp 8mo agoWhere did I wrote that static analysis was enough on its own?
- dnautics 8mo agoCan you phrase that as a direct answer to my question? Trying to learn something here. Appreciate it!
- pjmlp 8mo agoI the sentence "I can also analyse C and C++ code for such issues, while keeping using a mature languages ecosystem." it is implied there are many tools that perform analysis of C and C++ code. Some of those tools are static, others are dynamic, some require a special build, others are hybrid, others exist on all modern IDEs. So it can be a mix of lint, clang tidy, VS analysis, Clion, ASan, USBsan, hardned runtimes, contracts (Frama-C), PVS, PurifyPlus, Insure++,....
- davemp 8mo agoThis is pretty close to saying Rust is not very different than C because it has the unsafe keyword. That is, either an ignorant (of Zig) or disingenuous statement.
- vlovich123 8mo agoTo me the zig position is akin to saying that because Asan, TSAn and ubsan exist, c++ is safe because you’re just running optimized for performance. If you believe I mischaracterized zig, please enlighten me what I got wrong specifically rather than attacking my ad hominem
- davemp 8mo agoI’m not going to write a detailed response to something that’s extremely close to what an LLM responds to “what UB does zig have?” Arguing about whether certain static analysis should be opt in or opt out is just extremely uninteresting. It’s not like folks are auditing the unsafe blocks in their dependencies anyways. If you want to talk about actual type system issues that’s more interesting.
- vlovich123 8mo agoSo the Fermat defense? “I have the proof but the margin is too small”. The proof is in the pudding. TigerBeetle despite having a quite opinionated style still almost hit by UB and basically got lucky it wasn’t a worse failure. By contrast, even though unsafe isn’t audited for all dependencies, it does in practice seem to make UB extremely unlikely. And there’s work ongoing in the ecosystem to create safe abstractions to remove existing unsafe into well tested and centralized things
- pjmlp 8mo agoIt is worse, because Asan, TSAn and ubsan already have several years of production experience, in a mature ecosystem. There is no point throwing it all away to get back to the starting line.