logoalt Hacker News

hn_submit • today at 4:41 AM • 3 replies • view on HN

I believe this is barking up the wrong tree since IMHO C is just "high level assembly" for systems programming. As soon as you add runtime behavior to combat Undefined Behavior (UB) you're blowing up execution times. And static analysis can only go so far without blowing up compile times.

C is "the right tool for the right job" which is operating systems and its code which is called thousands of times per second. You cannot afford even one iota of runtime checks in that code. The developer must know what he's doing or he should get out of the kitchen.

We should discourage the usage of C in application programming and prod developers towards memory safe languages like Rust or Go.

And I'm not even sure if Rust solves this case as far as UB is concerned.


Replies

SkiFire13 • today at 5:37 AM

> C is just "high level assembly" for systems programming

It is not, and that's the issue. If it was just "high level assembly" there would be no UB, and no need to have UB. Instead you have UB (although arguably not all of it is really needed) because you need optimizations, which in turn you need because otherwise C would be too slow for that "operating system" job.

> code which is called thousands of times per second

Scripting languages can easily have loops running thousand of times per second and even more. You're off by some order of magnitudes here if you want to describe operations that happen in operating systems.

gizmo686 • today at 5:06 AM

A high level assembly would not have a UB problem, because the generated machine code would closely map to your source code, so even technically undefined behaviour would end up doing the expected thing for the given hardware.

The problem with C is that modern compilers do a lot of transformations between your source code and the final machine code, so the actual behavior could be very far afield from what you would expect.

> And I'm not even sure if Rust solves this case as far as UB is concerned.

If your entire program is inside unsafe, then Rust is actually worse than C as far as UB is concerned. On the other hand, no one writes Rust like that, and Rust restricts all UB to unsafe blocks.

chasil • today at 5:02 AM

C is also famously bad at floating point optimization.

Fortran has historcally led this realm (see the Numerical Recipes book).

Julia is a newer option, and I understand that both are commonly used in Python objects.

https://numerical.recipes/

"Read the older 2nd ed. book in Fortran online for free."

➕ show 2 replies