This is the mail archive of the
gcc@gcc.gnu.org
mailing list for the GCC project.
Re: [PATCH] C undefined behavior fix
- From: Tim Hollebeek <tim at hollebeek dot com>
- To: Paul Mackerras <paulus at samba dot org>
- Cc: Richard Henderson <rth at redhat dot com>, Tom Rini <trini at kernel dot crashing dot org>, jtv <jtv at xs4all dot nl>, Momchil Velikov <velco at fadata dot bg>, linux-kernel at vger dot kernel dot org, gcc at gcc dot gnu dot org, linuxppc-dev at lists dot linuxppc dot org, Franz Sirl <Franz dot Sirl-kernel at lauterbach dot com>, Benjamin Herrenschmidt <benh at kernel dot crashing dot org>, Corey Minyard <minyard at acm dot org>
- Date: Thu, 3 Jan 2002 17:41:17 -0500
- Subject: Re: [PATCH] C undefined behavior fix
- References: <20020102133632.C10362@redhat.com> <20020102220548.GL1803@cpe-24-221-152-185.az.sprintbbd.net> <20020102232320.A19933@xs4all.nl> <20020102231243.GO1803@cpe-24-221-152-185.az.sprintbbd.net> <20020103004514.B19933@xs4all.nl> <20020103000118.GR1803@cpe-24-221-152-185.az.sprintbbd.net> <20020102160739.A10659@redhat.com> <15411.49911.958835.299377@argo.ozlabs.ibm.com> <20020103003240.A10838@redhat.com> <15412.11822.811712.207946@argo.ozlabs.ibm.com>
- Reply-to: tim at hollebeek dot com
> Also, what does the standard say about casting pointers to integral
> types? IIRC you aren't entitled to assume that a pointer will fit in
> any integral type, or anything about the bit patterns that you get.
Yes, but you're on much safer ground here, since the conversion is
implementation defined. Practical considerations almost guarantee the
implementation choice will be "int == address" for targets where this
makes sense (e.g. has a simple, flat, contiguous address space).
Also, in the latest version of the C standard, you do have a int type
that can contain a pointer.
Allowing people to treat pointers as if they were "just" integers
prevents a whole slew of interesting and useful compiler
transformations, which is why the standard frowns upon such behavior.
Buffer overflow checks are an example. It's possible to build bounded
pointer implementations for strict ANSI C, but impossible for the "all
pointers are just integers" variant.
Do the compiler a favor. If you're playing with pointers as if they
are integers, make them integers. Types are your friend.
-Tim