https://www.digitalmars.com/articles/C-biggest-mistake.html
i.e. just change:
void foo(char* a)
to: void foo(char[] a)
and that passes a phat pointer (pointer and length) instead of just a pointer, enabling array bounds checking.https://www.digitalmars.com/articles/C-biggest-mistake.html
i.e. just change:
void foo(char* a)
to: void foo(char[] a)
and that passes a phat pointer (pointer and length) instead of just a pointer, enabling array bounds checking. void foo(char a[..])
for passing an array pointer and length, and to eventually deprecate: void foo(char a[])
Personally I like this suggestion, but as the article is 12 years old, I'm obviously in a minority. void foo(char[] a)
instead of what he originally proposed, which is: void foo(char a[..])
If so, that does seem cleaner. I still like the overall suggestion.Which is amazing. It's a simple, backwards compatible solution to buffer overflows. I know it works because it's been used in D for 20 years and has made buffer overflows a thing of the past.
It's also nice because it implicitly documents the difference between a pointer to a single object and a pointer to an array of objects. Just this is a huge win, when used consistently.
It's completely compatible if you use the [..] syntax.
> performance/size penalties
For the proposed scheme, they are essentially non-existent. This is because the array bounds is usually already being passed as a separate argument.
Arrays that rely on a sentinel to determine the end (like 0-terminated strings) one can just not use the new syntax.