But with static analysis it's still possible to miss some leaks or to have false-positives. That's why an integrated language mechanism preventing such leaks is much better.
Yes, so you pick "false positives" instead of "missing some leaks" and you build a way to mark code as "unsafe".
This is not fucking rocket science
> That's why an integrated language mechanism preventing such leaks is much better.
No categorical difference, except one is opt-in. You can even design your static analyzer so it analyses the code of dependencies that haven't opted in.
Making things opt-in means that it will happen less often, making them opt-out that they will happen more often. In this case, on the one hand you have destructors that don't run when they should, and on the other you have destructors running at a more granular level than you'd want sometimes. I know which human failure mode I prefer.
They don't play nicely with arena allocators. And arenas is what you reach for if you have clear lifetime bounds: e.g. a single request with arena never de-allocates individual objects, nukes arena when done. That gives you an easy verifiable protection against leaks, data (and cache) locality and deallocation that cost zero cpu cycles.
Have a boxed object have implemented drop, then when the box leaves some scope the Box will clean up it's stuff (drop implementation if there is any) and deallocate it's memory using the allocator (which the arena will treat as noop).
It's technically possible to perform arena-based allocation and still have compiler checks. The compiler just need to track objects allocated with an allocator and prevent destructing the allocator itself as long as there is at least one object using it.
It's like view span objects in rust. The compiler knowns that a span is logically connected to the parent object and don't allow destroying it when such span exists.
Rust supports arena allocator <a href="https://docs.rs/bumpalo/latest/bumpalo/" rel="nofollow">https://docs.rs/bumpalo/latest/bumpalo/ and the dropping plays well with arena as long as you use bumpalo::boxed::Box
Panzerschrek · · focus · HN ↗
That's why having no auto-destructors is a dead-end. This is the greatest mistake of such languages like Zig or Odin.
dnautics · · focus · HN ↗
Panzerschrek · · focus · HN ↗
dnautics · · focus · HN ↗
This is not fucking rocket science
> That's why an integrated language mechanism preventing such leaks is much better.
No categorical difference, except one is opt-in. You can even design your static analyzer so it analyses the code of dependencies that haven't opted in.
estebank · · focus · HN ↗
dnautics · · focus · HN ↗
IshKebab · · focus · HN ↗
dnautics · · focus · HN ↗
Anyways: its possible, I am building it as a very side project.
github.com/ityonemo/clr
delamon · · focus · HN ↗
tcfhgj · · focus · HN ↗
Have a boxed object have implemented drop, then when the box leaves some scope the Box will clean up it's stuff (drop implementation if there is any) and deallocate it's memory using the allocator (which the arena will treat as noop).
delamon · · focus · HN ↗
tcfhgj · · focus · HN ↗
delamon · · focus · HN ↗
tcfhgj · · focus · HN ↗
Panzerschrek · · focus · HN ↗
It's like view span objects in rust. The compiler knowns that a span is logically connected to the parent object and don't allow destroying it when such span exists.
delifue · · focus · HN ↗