C isn't a hangover and Rust isn't a cure
scribe.rip
scribe.rip
Bounds checks themselves aren’t that expensive, if you already have the length to check against in a register or some other convenient spot.
And - if the bounds are convenient to find and known to be immutable then it does make it easier for the compiler to eliminate those checks using the same techniques it would use to eliminate all kinds of redundancies. C has many redundancies that we don’t have to think about because they’re straightforward for the compiler to reason about.
But C/C++ pointers don’t. You can add bounds checking to all C/C++ pointers and there are many projects that do that (CCured, SoftBound, CHERI, Fil-C, CheckedC, -fbounds-checked) but they all come at cost (new hardware, language changes, or reduced perf).
For comparison "C++ shared_ptr is only safe with tree-shaped structures" would be getting-at-the-truth-but-kinda-weirdly-worded in some similar ways.
Go in particular has a lot of the advantages of C/C++ and Rust--fully-compiled binary, easy access to system calls, high performance--without the overhead of needing to constantly think about memory management.
The rust part of the product is significantly better, the code is much saner and the team velocity is also much faster.
- enums
- const-ness without immutable types
- no null
- no iterator invalidation
- no surprising captures in closures/lambdas
- no "spooky action at a distance"
- Cargo
There are a lot more practical and lucrative skills for a young programmer to focus on than C or C++. Many will be able to have good careers without going that low level.
What impact will that have on the economics of legacy C/C++ code bases in the 15-30 year time frame?