> Without bounds checks: game crashes, core dump.
I think it's more like (assuming it does actually go out of bounds at some point):
30% chance of core dump right away
20% chance of core dump at some point after errant write
40% chance it never crashes in testing
5% chance it doesn't crash the first year after shipping
5% chance it never crashes
With an explicit bounds check, all of these scenarios result in a crash at the exact location where the program first violated safety[1]. The developer gets a source-level crash and doesn't spend the first 20 minutes just trying to figure out what the crash dump even means.
[1] Hopefully with a complete stacktrace, maybe even the index and length values!
It's time we recognized that all our tooling should be designed to help us programmers who do have bugs in our program. Like, this crashing part is the normal part that all the tools should help deal with.