But this is a something that even experts fail to do.
But this is a something that even experts fail to do.
https://github.com/google/sanitizers/
Sure, Google is primarily a C++ shop, you could say that C++ is to blame and it has nothing to do with C.
But why the need for KASAN then? Which has a big track record at this point, by the way.
Mozilla decided that it was such a difficult task in C/C++ that they created their own language.
I hadn't ruled out calling outside platform API functions, which were all written in C. You can't do that in any language, unless you're writing a pure text filter or calculator for the Unix command line environment (and don't count the I/O and math functions).
I still use C++ as one of my favourite hobby languages and althought it has improved a lot, using C++20 best practice across a team (lets assume it is already available), with binary dependencies, is still a challange to make it 100% memory safe.
It was 100% written by me.
Note that the Rust devs made an entire 100% written-by-them-language to make the same claims.
In C++ static analysis is optional, while it is part of language in Rust.
Then there is the whole language culture.
While me coming from stronger system languages, always strived for bounds checking enabled on my own C++ projects, good luck selling that to most C++ teams, even though in 99% of the use cases its impact is negligible.
Finally going all the way back to NEWP, system languages that require explicit unsafe blocks are much easier to do code review, than those where every line of code can possibly trigger unsafe behaviour, and C++ inherited lot of such cases from C.
> that overflow is as severe as memory bug in C/C++
In practice, it isn't. In many traditional compilers it has predictable behavior (two's complement wrapping), if we're not talking about floating-point overflow.
Some programs explicitly rely on it. Compiler support can be provided for those programs.
It's simply not in the same category as memory corruption bugs.
Of course, ISO C and C++ have just one category for undefined! However, note that "undefined behavior" is a formal term which extends over beneficial areas such as documented extensions and the use of third-party libraries and headers.
Okay, you were serious about safety. Congratulations, you are the first one I have ever come across.
I have never seen anyone else wrap integers in a class in order to use them with stable semantics.
Twenty years ago, C++ was still hot and there was a lot of interest in all sorts of techniques. Books, seminars, papers, blogs, you name it.
There is a way to use C++ template partial specialization to mimic the built-in conversion rules, like "int op long" promoting the left operan to "int". You can mirror the language in itself and bend the rules.