Reducing undefined behavior in the C language

(lwn.net)

24 points | by signa11 1 hour ago

7 comments

  • 1vuio0pswjnm7 4 minutes ago
    1790620504 | Reducing undefined behavior in the C language | https://lwn.net/SubscriberLink/1095811/b9325731ea9b61e0/ | https://news.ycombinator.com/item?id=49882419 | 15 comments

    1790673092 | Reducing undefined behavior in the C language | https://lwn.net/SubscriberLink/1095811/efcdbcf080cfa4c6/ | https://news.ycombinator.com/item?id=49890290 | 0 comments

  • chasil 12 minutes ago
    "Some Honeywell machines, for example, had nine-bit bytes."

    OS 2200 has 36-bit words. It is still a supported platform.

    https://en.wikipedia.org/wiki/UNIVAC_1100/2200_series

    This platform was the first SMP UNIX implementation:

    "Any configuration supplied by Sperry, including multiprocessor ones, can run the UNIX system."

    https://www.nokia.com/bell-labs/about/dennis-m-ritchie/other...

  • p1necone 29 minutes ago
    The concept of undefined behaviour specific to C/C++ has always seemed batshit insane to me, and I'm yet to read anything about it that has made it seem any less so.
    • nananana9 3 minutes ago
      It doesn't make sense to define what happens when you e.g. read from NULL because it's hardware specific - if you have virtual memory of some sort, you'd probably get a page mapping error. If you don't (embedded, WASM), you'd read back whatever value is at that address.

      Does Rust define what I get when I dereference NULL in unsafe code? I doubt it, since it would require a NULL check before every pointer dereference.

      The only insane thing about UB is that compiler writers took what everyone understand meant "the compiler emits what it emits and you get what you get" and turned it into "since it's undefined it means it can never happen so we can delete your null check".

    • chasil 6 minutes ago
      It was written for a PDP-11 with 64k of RAM.

      There wasn't room for safe programming practices, and direct manipulation of the hardware was a design requirement.

      It assumes that you know what you are doing.

      There are also ports to the Zilog Z80, an architecture with similar limitations (UZI, FUZIX).

    • mpyne 5 minutes ago
      It's not specific to C or C++, though it is more prominent there.

      Rust's unsafe mode, for instance, has undefined behavior. A whole list of them, in fact.

  • BeaverGoose 17 minutes ago
    Make signed overflow defined please.
  • elais-dev 32 minutes ago
    [dead]
  • jdw64 19 minutes ago
    [dead]
  • jdw64 35 minutes ago
    [dead]