5 ms·
> All if, else if constructs will contain either a final else clause or a comment indicating why a final else clause is not necessary. I actually do this as we
by don-code 9mo ago
> All if, else if constructs will contain either a final else clause or a comment indicating why a final else clause is not necessary.
I actually do this as well, but in addition I log out a message like, "value was neither found nor not found. This should never happen."
This is incredibly useful for debugging. When code is running at scale, nonzero probability events happen all the time, and being able to immediately understand what happened - even if I don't understand why - has been very valuable to me.
- torben-friis 9mo agoI like rust matching for this reason: You need to cover all branches. In fact, not using a default (the else clause equivalent) is ideal if you can explicitly cover all cases, because then if the possibilities expand (say a new value in an enum) you’ll be annoyed by the compiler to cover the new case, which might otherwise slip by.
- uecker 9mo agoAnd I like using enums in C ;-) The compiler tells you to cover all branches. https://godbolt.org/z/bY1P9Kx7n https://godbolt.org/z/bY1P9Kx7n
- rundev 9mo agoThe compiler also tells you that even if you cover all enum members, you still need a `default` to cover everything, because C enums allow non-member values.
- torben-friis 9mo agoRust is a bit smarter than that, in that it covers exhaustiveness of possible states, for more than just enums: fn g(x: u8) { match x { 0..=10 => {}, 20..=200 => {}, } } That for example would complain about the ranges 11 to 19 and 201 to 255 not being covered. You could try to map ranges to enum values, but then nobody would guarantee that you covered the whole range while mapping to enums so you’d be moving the problem to a different location. Rust approach is not flawless, larger data types like i32 or floats can’t check full coverage (I suppose for performance reasons) but still quite useful.
- uecker 9mo agoIn principle C compilers can do this too https://godbolt.org/z/Ev4berx8d https://godbolt.org/z/Ev4berx8d although you need to trick them to do this for you. This could certainly be improved.
- YesBox 9mo agoSame. I go one step further and create a macro _STOP which is defined as w/e your language's DebugBreak() is. And if it's really important, _CRASH (this coerces me to fix the issue immediately)
- creato 9mo agoThe "standard" (typically defined in projects I'm familiar with, and as of C23, an actual standard) is "unreachable": https://en.cppreference.com/w/c/program/unreachable.html https://en.cppreference.com/w/c/program/unreachable.html
- YesBox 9mo agoC++ keeps getting bigger and bigger :D Thanks for sharing
- creato 9mo agoThis is actually C and C++ has not done something similar AFAIK.
- hn_go_brrrrr 9mo agoFortunately the major compiler vendors all have. Routing around the standards committee is getting more and more common.
- Fulgen 9mo agohttps://en.cppreference.com/w/cpp/utility/unreachable.html https://en.cppreference.com/w/cpp/utility/unreachable.html
- TuxSH 9mo agoC++23 does have std::unreachable (as a function), and its counterpart [[assume(expr)]]
- vlovich123 9mo agoThat is not the same thing at all. Unreachable means that entire branch cannot be taken and the compiler is free to inject optimizations assuming that’s the case. It doesn’t need to crash if the violation isn’t met - indeed it probably won’t. It’s the equivalent of having something like x->foo(); if (x == null) { Return error…; } This literally caused a security vulnerability in the Linux kernel because it’s UB to dereference null (even in the kernel where engineers assumed it had well defined semantics) and it elided the null pointer check which then created a vulnerability. I would say that using unreachable() in mission critical software is super dangerous, moreso than an allocation failing. You want to remove all potential for UB (ie safe rust with no or minimal unsafe, not sprinkling in UB as a form of documentation).