C Is Not Assembly
james-iry.blogspot.com
james-iry.blogspot.com
if((uintptr_t)buf+len < (uintptr_t)buf)
might fail to give the expected result if the address space is segmented.
Seriously? In 2010? We're still adding pointers to integers instead of working with actual data structures?
gcc did something unexpected. Film at 11.
I am aware of cases where gcc optimizing out this check resulted in security vulnerabilities. (No, I'm not going to give details. I think these were made public, but I'm not absolutely sure.)
Of course, there is http://xorl.wordpress.com/2009/07/17/linux-kernel-devnettun-... (discussion at http://lwn.net/Articles/341773/), but while that is also an instance of gcc doing non-obvious but correct things, it's not the same problem.
C is just a mapping to a generic assembly language. The machine will be adding pointers and integers anyway so this is inevitably reflected in C in one way or another. There are different notations to adding pointers and integers, such as &pointer[index] or casting and adding, but in C you still have to think in terms of pointers and integers.
Why C? The main reason is that it has lots of pragmatic bias for its use. It's simple (unlike C++), it's closeness to assembly makes it a nice candidate for writing low-level layers, and it's supported nearly everywhere (unlike C++). This is hugely important in getting things done even if there were a number of smarter but less pragmatic ways.