Linux Manual Pages development
 help / color / mirror / Atom feed
From: Matthew House <mattlloydhouse@gmail.com>
To: Lennart Jablonka <humm@ljabl.com>
Cc: Alejandro Colomar <alx@kernel.org>, linux-man@vger.kernel.org
Subject: Re: [PATCH] string_copying.7: don't grant strl{cpy,cat} magic
Date: Sat, 29 Jul 2023 17:06:31 -0400	[thread overview]
Message-ID: <20230729210639.1671397-1-mattlloydhouse@gmail.com> (raw)
In-Reply-To: <ZMUmm3hTkrhzq2CW@fluorine.ljabl.com>

On Sat, Jul 29, 2023 at 10:47 AM Lennart Jablonka <humm@ljabl.com> wrote:
> Quoth Matthew House:
> >On Sat, Jul 29, 2023 at 8:29 AM Alejandro Colomar <alx@kernel.org> wrote:
> >> I lied.  I should have said that it writes what is safe to write, and
> >> then uses a somewhat "safer" version of undefined behavior (compared
> >> to other string copying functions).  The standard differentiates
> >> "bounded UB", which doesn't perform out-of-bounds stores, from
> >> "critical UB", which performs them.  In usual jargon, UB is UB, and
> >> there's no mild form of UB; however, the standard prescribes a bounded
> >> form of UB.  However, I'm not sure compilers --and specifically GCC--
> >> follow such a prescription of bounded UB, so it's better to consider
> >> all UB to be critical UB, just to fall on the safe side.
> >
> >Do you have a source for this? As far as I am aware, the standards have
> >always followed the "UB is UB" philosophy, which is why standards-oriented
> >people keep trying to reiterate it. I've never heard of anything like
> >"bounded UB" vs. "critical UB". C17 draft N2176 provides no such
> >distinction in its definition:
>
> Quoth Alejandro Colomar:
> >References:
> >
> ><https://port70.net/~nsz/c/c11/n1570.html#L.2>
>
> Looks like a reference to me.

Ah, thank you, my apologies; it's my fault for somehow failing to notice
that in the email. And then I looked through all the WG14 documents, but
didn't think to just try a full-text search in the standard.

> Yes, UB is UB.  The optional Annex L on Analyzability does define
> bounded and unbounded UB.  No, you don’t care about them.  Yes,
> that is standard terminology.  No, your implementation doesn’t
> define __STDC_ANALYZABLE__.  Yes, that terminology can be useful.

I'm actually somewhat surprised that Annex L hasn't ever come up in the
recurring debates over whether UB is good or bad or interpreted too broadly
by implementations or whatever. Perhaps it's because even though Annex L
defines the distinction, it doesn't give any requirements (and only gives
broad suggestions) to implementations on how the two should be treated
differently. What would defining __STDC_ANALYZABLE__ even imply?

Thank you,
Matthew House

  reply	other threads:[~2023-07-29 21:06 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-07-28 19:22 [PATCH] string_copying.7: don't grant strl{cpy,cat} magic Lennart Jablonka
2023-07-28 22:05 ` Alejandro Colomar
2023-07-28 23:51   ` Lennart Jablonka
2023-07-29 12:04     ` Alejandro Colomar
2023-07-29 14:38       ` Matthew House
2023-07-29 14:47         ` Lennart Jablonka
2023-07-29 21:06           ` Matthew House [this message]
2023-07-29 19:39         ` G. Branden Robinson
2023-07-30 14:05           ` Alejandro Colomar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230729210639.1671397-1-mattlloydhouse@gmail.com \
    --to=mattlloydhouse@gmail.com \
    --cc=alx@kernel.org \
    --cc=humm@ljabl.com \
    --cc=linux-man@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox