A Guide to Undefined Behavior in C and C++ (2010)
blog.regehr.org
blog.regehr.org
I've been growing more skeptical of this claim over time. First, more evidence would be nice instead of "some loops". What is a program (not a benchmark) that has an observable performance difference when compiled with and without -fwrap?
Second, it seems counter productive. The word is now out that if you use signed ints, the compiler is going to fuck you over. So now everybody is (or should be) using unsigned ints, and whatever optimization the compiler was performing, now it can't. A lot of grief for no progress.
Google brings up this old message. It seems to affect the SPEC2000 suite fairly badly. SPEC2000 mostly measures real applications, such as gzip, and is not a series of microbenchmarks.
http://www.archivum.info/autoconf-patches@gnu.org/2007-01/00...
I've been vaguely concerned with how to ensure my C code avoids undefined behavior, but it didn't occur to me that I also need to watch out in being overly conservative because then I'll be causing the optimizers trouble.
I'm not trying to disparage anyone who is actually able to be productive in a C environment, but I'm really hoping something like Rust is able take over that development space.
http://blog.llvm.org/2011/05/what-every-c-programmer-should-...
printf("INT_MAX+1= %lld\n", (long long)INT_MAX + 1LL);
My two problems with undefined behavior is that 1) it is not always obvious that your program is guilty of undefined behavior and 2) when a C program contains undefined behavior the compiler can generate surprising machine code.
I don't have any problem with 8/0 being undefined mathematically, but I do have a problem with a C compiler generating code that will delete my hard drive if it ever occurs (an unlikely but theoretically possible for a conforming C compiler).
INT_MAX + 1 is problematic because most people expect wrap around (and in fact they may be using a compiler that does this). It's more problematic because UINT_MAX + 1 does get wrap around. And finally there's a bunch of difficult to remember auto integer conversion rules. Taken together it's not surprising that many people will find it difficult to determine if their integer usage is correct.
One solution is of course to use a safer language than C (where I unfortunately have to end up). But I personally object to the idea that you have to have undefined behavior in order to get the performance of C (waiting to see how the development of languages like Rust goes to determine if I'm right).
DISCLAIMER: I haven't done any C programming in years, and I wasn't particularly good at it, even then.