Of course, there are probably lots of in-practice exceptions when it comes to embedded, kernel code, mmap() shenanigans, etc.
Of course, there are probably lots of in-practice exceptions when it comes to embedded, kernel code, mmap() shenanigans, etc.
This is an extremely simplified and probably incorrect view of https://open-std.org/jtc1/sc22/wg21/docs/papers/2019/p1434r0.... This is complicated because nobody agrees on what the correct behaviour should be, and we have mountains of legacy codebases that all rely on something slightly different when pointers get converted to ints and back.
Rational built a truly semantic IDE, and the result of that is that if you change a line of source-code somewhere in a huge complicated project, it will know precisely what the consequences of that change are.
Ultimately, this allows it often just recompile that single line.
I love the approach, it's a way to get a lot more memory safety while not giving up a program's flexibility, especially in C's case.
Some languages are opting to disallow pointer arithmetic and conversion between integers and pointers. We'll see how it works out!
[0] https://verdagon.dev/blog/generational-references
[1] https://developer.arm.com/-/media/Arm%20Developer%20Communit...
"hey you allocated it you should know about it right?" right yeah
In C++, I think they added enough magic in that you should now be able to do it (placement new, std::launder and numerous other hacks).
My understanding that reusing the storage would violate the aliasing rules[1] and the rules against overlapping object lifetimes.
[1] while char ptrs can be used to access everything, the reverse is not allowed.
Olde C used to just let you use integers as struct pointers, and there was only one struct member namespace. so code like this was valid and did an integer-size write to address 0177770. old unix did this for device register access; see the lions book.
struct { int integ; };
f() { 0177770->integ = 012345; }
> Attribute malloc indicates that a function is malloc-like, i.e., that the pointer P returned by the function cannot alias any other pointer valid when the function returns, and moreover no pointers to valid objects occur in any storage addressed by P. In addition, the GCC predicts that a function with the attribute returns non-null in most cases.
But it doesn't provide any operations to do the things in this paragraph (create new pointers). The operation that does this is malloc itself.
This will typically not cause problems, but it would if LTO got so good you could include libc in it.