Some Programming Language Ideas
davidbos.me
davidbos.me
This is backwards. In Rust, using the indexing operator on an array is a bounds-checked operation; the alternative is the unsafe .get_unchecked method. This is true regardless of debug mode or release mode, and there isn't any flag or configuration variable to override this.
It's integer overflow whose behavior (currently) changes between debug and release mode, where in debug mode it panics and in release mode it's defined to wrap around (and this can be configured as you please via a build flag).
Rust does not have refinement types but Pattern Types are behind a feature flag and will hopefully come soon. Pattern Types are not quite refinement types but they will allow you to define NonZero et al yourself.
https://objectcomputing.com/resources/publications/sett/sept...
C++ contracts might finally land in C++26, after missing two revisions, although in a minimal form.
No integration with Java Pathfinder or JBMC?
It's really weird how much they missed the ball.
GNAT also has validity checks, which are very, very useful. Fuzzing finds so many bugs with those... https://blog.adacore.com/running-american-fuzzy-lop-on-your-...
Many do type flow analysis nowadays.
Variant records in Wirthian languages are another approach, although they lack validation regarding accessing wrong active tags.
Ada/SPARK and Frama-C can do refinement on memory addresses.
https://crates.io/crates/refined_type
https://crates.io/crates/refinement
and
https://crates.io/crates/refined
There are also some interesting optimizations possible around this; see e.g. this discussion on the issue tracker of the latter crate: https://github.com/jkaye2012/refined/issues/9#issuecomment-2...
ConfiguredThing Thing::configure(....) &&;
Where ConfiguredThing and Thing have the exact same members, so doing
auto y = std::move(x).configure(...);
would not copy any data around. It seemed to work with optimizations on, but then there are no guarantees that it will always be the case.
Ideally one would want RAII, but that is not always possible, in particular when wrapping C libraries that may have their own logic. Also, the object could be in different states, with different methods available in each state, and then it would be possible to prevent errors at compile time.
https://en.wikipedia.org/wiki/Expression_problem
This is the problem that makes being a corporate software developer really really suck.
The source code of the widgets we use everyday - such as text editing or graphical editors are or your web browser's Javascript engine, are enormous.
'Just do X, too' is really difficult with what is already there.
It's more or less as horrific as you can imagine...
I also don't see in this particular case why the reference would be taken before the potential resizing push but used after the push. Maybe with a clearer use-case I could see the point?
This would also introduce dynamic checks at compile time, since you need to run the program in order to compile it now, as the overload selection/precondition depends on the runtime state of the Vec. This necessarily requires a less-strict compilation/interpretation mode to be run before the borrow checker/other static analysis is done, since the static analysis can't know which function is being called. I suppose this is similar to compile-time programming.
It strikes me also, that you could do all this at runtime if you wanted, simply by manually incrementing length if length < cap and assigning to the newly created spot.
This is precisely ATS!
Partly kidding of course, it is a super interesting language. It is probably the only language that ever made me feel out depth and I dabble in a lot of niche languages. Pretty cool stuff!