4 ms·
> it's still a counterexample for "you can't define it because it means sanitizers can't warn for it" Sure, technically you can write a sanitizer for anything.
by dzaima 2mo ago
> it's still a counterexample for "you can't define it because it means sanitizers can't warn for it"
Sure, technically you can write a sanitizer for anything. It just becomes less a "sanitizer" you can always recommend everyone everywhere use, and more of just a heuristic thing that only really works if you design your code for its arbitrary desires.
> and in the cases where it actually is intentional you can suppress the check.
imo it'd be nice to have separate types for wrapping and non-wrapping integers for that, so that you have actual language-level semantics and an easy way to mix things (e.g. wrapping arith for hashing, mixed with non-wrapping arith for loop index or whatever) instead of suppressions.
- aw1621107 2mo ago> It just becomes less a "sanitizer" you can always recommend everyone everywhere use, and more of just a heuristic thing that only really works if you design your code for its arbitrary desires. Sure, and that's basically what I was wondering about with respect to "can't define it" being shorthand for something else > imo it'd be nice to have separate types for wrapping and non-wrapping integers for that I think I'd agree, though I'd imagine it's a bit late for such things to be deeply integrated into the language. At least making your own isn't horrendously difficult.
- dzaima 2mo ago> Sure, and that's basically what I was wondering about with respect to "can't define it" being shorthand for something else Eh, I'd say it's still the same thing; can't define a sanitizer for it if what you define isn't a sanitizer. Depends on a specific definition of "sanitizer" though. > At least making your own isn't horrendously difficult. In C++ perhaps, but impossible in C. (and there are still some funky edge-cases where multiplying two `uint16_t`s can overflow due to implicit promotion to signed int; C's _BitInt solves at least that) Clang does actually have experimental support for these - https://clang.llvm.org/docs/OverflowBehaviorTypes.html https://clang.llvm.org/docs/OverflowBehaviorTypes.html
- aw1621107 2mo ago> Depends on a specific definition of "sanitizer" though. Hrm, I suppose a general definition would be something that you use to check for certain (unintended?) runtime behaviors? Though I also feel that could include hardened implementations and stuff like valgrind.... > In C++ perhaps, but impossible in C. Oh, true I forgot about that.