220 36616 <CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5LRgzAyc0abLiyQ@mail.gmail.com> article
Path: news.gmane.org!.POSTED!not-for-mail
From: j c <james.a.cooper@gmail.com>
Newsgroups: gmane.comp.lang.c++.isocpp.proposals
Subject: Re: Static analysis and the future of C++
Date: Sun, 14 Jan 2018 15:39:04 +0000
Lines: 239
Approved: news@gmane.org
Message-ID: <CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5LRgzAyc0abLiyQ@mail.gmail.com>
References: <0087c1a4-0b36-40ca-8d43-5bfaf0af62ca@isocpp.org>
Reply-To: std-proposals@isocpp.org
NNTP-Posting-Host: blaine.gmane.org
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="94eb2c0b04de2e3d1c0562be4ce9"
X-Trace: blaine.gmane.org 1515944231 15995 195.159.176.226 (14 Jan 2018 15:37:11 GMT)
X-Complaints-To: usenet@blaine.gmane.org
NNTP-Posting-Date: Sun, 14 Jan 2018 15:37:11 +0000 (UTC)
To: "std-proposals@isocpp.org" <std-proposals@isocpp.org>
Original-X-From: std-proposals+bncBCR6HLXQUAORBGPT5XJAKGQEK6YNT3Q@isocpp.org Sun Jan 14 16:37:06 2018
Return-path: <std-proposals+bncBCR6HLXQUAORBGPT5XJAKGQEK6YNT3Q@isocpp.org>
Envelope-to: gclcip-std-proposals@m.gmane.org
Original-Received: from mail-yw0-f199.google.com ([209.85.161.199])
	by blaine.gmane.org with esmtp (Exim 4.84_2)
	(envelope-from <std-proposals+bncBCR6HLXQUAORBGPT5XJAKGQEK6YNT3Q@isocpp.org>)
	id 1eakLG-0003bb-VW
	for gclcip-std-proposals@m.gmane.org; Sun, 14 Jan 2018 16:37:03 +0100
Original-Received: by mail-yw0-f199.google.com with SMTP id b11sf535482ywc.16
        for <gclcip-std-proposals@m.gmane.org>; Sun, 14 Jan 2018 07:39:07 -0800 (PST)
ARC-Seal: i=2; a=rsa-sha256; t=1515944346; cv=pass;
        d=google.com; s=arc-20160816;
        b=wazuKUG2ZevHMJGuQf3MJJXv/Jtc8m01zZiR5VeD63xaUEqyCvK1VBH4ZZYWOAKL73
         NsdPMcMtSVA5RO6iHJk+9KJ0VaHeIKopsMK3dcIcFVSdflcYo2oZwKG+oQa7TplzLBui
         lHRCgAtHRTiIQv6Xfi2yPJOH3tNiObxiV/XEPrRPMjGte4DfRv/634I0Q1dj2KJOL+VQ
         RMEzJcwMgBYj60uWlU8nTIGnXwvRz1C7oe7dIFR7fPYnJ2iaaQqtxKUThvlHNv8YV+QW
         wEcovatZYpqRCAetSS8GTtUW8VRaumwI13SKLQFYuL2k2i+nb3KB4yzt/iWJAJqHiP4r
         OFqg==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
         :list-id:mailing-list:precedence:reply-to:to:subject:message-id:date
         :from:references:in-reply-to:mime-version:arc-authentication-results
         :arc-message-signature:dkim-signature:arc-authentication-results;
        bh=+t6I+9Xk4rX0k7MIJLxwucKgl9ZkIjh3nz2xLYE4wWk=;
        b=oWXeuBdfbsLb0N/xu9ckOqc8eTrgF1v+0oZu91XYeaZQ1jSvQbdx+F/i+Dtgfs2PCS
         j6CgdzSx5bd16Se4R09ZoQoW0br7bfaHeQm4GsGfkUyAt086qBeUFzamT/PTmxMRByuG
         5EBm9gvzUINLQw5R4bCvrnK9PXmMY4lv3vGWHfwElilqTSw7iXeqcZMGoI+MuzLY0CZI
         lCRXJCXWddoeVNBblfvnBqZvxeNLEinsq7ogmSP1Cj7hkAw5xX9fAcE0P099nds6QtnS
         EE7i+PZwJT/WnxbaXfcb16MXFKA4P/Tp+KxmkmYdJwxDsVIwb0hRxvb1m2kR2hehwITr
         ZVHw==
ARC-Authentication-Results: i=2; mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20161025 header.b=cz3K20dU;
       spf=pass (google.com: domain of james.a.cooper@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=james.a.cooper@gmail.com;
       dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=gmail.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=isocpp-org.20150623.gappssmtp.com; s=20150623;
        h=mime-version:in-reply-to:references:from:date:message-id:subject:to
         :x-original-sender:x-original-authentication-results:reply-to
         :precedence:mailing-list:list-id:list-post:list-help:list-archive
         :list-subscribe:list-unsubscribe;
        bh=+t6I+9Xk4rX0k7MIJLxwucKgl9ZkIjh3nz2xLYE4wWk=;
        b=ufUiccUeo+5PQ4zjN4Ccdw2F026cTzsbQGYRbvHpkCYfeaizLPBbiDyTR2Y11b9I+j
         PWyRsrtTzGLrLipq8cgfG3utPFoxuuNvNs0D/EeAwdTRJlXc7/fSfHGdOmvycSS56wNI
         MYeQ0u074bgeYxf+xvq/qwgf7sHXWDSVERjHCOY/tkeEu5epJ+P42gZo3MAMEUwGqUgm
         Ye8bnpcNK1TeANDnSI/HsqJ1+02JPT90Kx7APnWcG80Nh1oe/yG02DzxzOGpvKUsKF9n
         gkWqm7FHbbWR20BlduqK9K9MRGeHDbaXvSkIMIwe1/NYRzEIECjSnBEUaih6MOuCAILY
         ttoQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:mime-version:in-reply-to:references:from:date
         :message-id:subject:to:x-original-sender
         :x-original-authentication-results:reply-to:precedence:mailing-list
         :list-id:x-spam-checked-in-group:list-post:list-help:list-archive
         :list-subscribe:list-unsubscribe;
        bh=+t6I+9Xk4rX0k7MIJLxwucKgl9ZkIjh3nz2xLYE4wWk=;
        b=VRWgnTzbbLeoTe0M8cJvGcGInnypaLg7v8EypSI0ydRhPjyBOAMJwQ5SGz1mozUmKP
         kbGOMJbglFV1M4R76lOw1f7xtlFY1WKQP9vlgcIpmAER2g131onFj7S0VN/ldOzM7FRo
         kHXQhbHZ6AyO28mwB2BqU5OM1owAJC1XiKQ+p7MuXt2fwyjt/X7hKZSdSlvduT+9Js9A
         APA/ME2ret1Ai6p9gqrKmydMUzxwvZTVxQhyHDqwPEESvkzViwK+G/pPEOfCjCLFmx8V
         oLrkPsOHbBhcaL5fYMLTXCBRQ7vkaENG0qvuCN5M9biOM0CJpoRPIZmGgt9xKQ8uJfX7
         sS/Q==
X-Gm-Message-State: AKwxytclFRfxN7CxIQo3lIZuN/1Bt7zhLc0L2LQEBZSwoTdzZcxIW9V4
	CW8oY9ap73ftAZQcIOf3pEZj+w==
X-Google-Smtp-Source: ACJfBotgQ5lKW3S+q+YcEsUgqXQnLIxQbSdVdBZ9oaNFO8pnGA+LB7jP1I+N22wfCEjMx8N035J/sw==
X-Received: by 10.129.68.6 with SMTP id r6mr8292445ywa.213.1515944346525;
        Sun, 14 Jan 2018 07:39:06 -0800 (PST)
X-BeenThere: std-proposals@isocpp.org
Original-Received: by 10.37.171.207 with SMTP id v73ls278502ybi.17.gmail; Sun, 14 Jan
 2018 07:39:05 -0800 (PST)
X-Received: by 10.13.216.74 with SMTP id a71mr20079916ywe.128.1515944345376;
        Sun, 14 Jan 2018 07:39:05 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1515944345; cv=none;
        d=google.com; s=arc-20160816;
        b=eHSA8RBbxAsgMUiq+9hd2eOt3QK9VVH+UdOJwWl5MtN7LORlL88SfGMmNVAJMSSSNf
         Jhwrl91GDBTsb7d6Ur/M8dUndMgg44WmVCFVisUBQbzl+f+JHSmknfjJBkDKxzMYNi6J
         u1cuYfwp9d1u+IAlOO4/3JfaiJngs5hN2K3WQrZukOyfMxpzMMxi1KZwIrUjkVVXks2j
         PgbG/96u3yFva+aELt3myxmQy7bAXuvh4VOLsD0zWHEi7nkpxdxci1IeScvU8FfaRjDR
         xALtaP+LPrpRrlSerYGYVu1pZNeQ0AsFVH56sZncdDF9ZEeoFn878wBSzzeWaKO04zpR
         WpIA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=to:subject:message-id:date:from:references:in-reply-to:mime-version
         :dkim-signature:arc-authentication-results;
        bh=e1ViUDcPKBYOW3EWKfYH5ZyF0CwurfdxTxgTT5G/wxE=;
        b=Vb8bwYxGeODKoczRrr0HVDeeiDx0Pg5VRFYtk+bxm5Z2hvA57p53ea7TeEYbNIqGrE
         +E7FtzRsqcTy6CEOJfim7jrXrGrX4j/mEzzMRsV/YQx/m3FPlSqU2oJnwwmbYI4HHdcK
         T7N+kpVliKhCmC263OfrCcBBrwdoMjBzy1fyLqTfa2uzdaQ7e0korily9hCoFtt8Ilks
         IueNtT0bCN++/74NhbpoT2UknYK23XPDaZTr1fVUeIt5h8+8VIIi34YuceutAuKe4yoU
         7k7VYfaWZJtU6ynrsQAJ0sZE1yDvp8EfcwdZ5CNaCV0D57iAW9QU2VUtkPuR/AYefB3o
         D1+w==
ARC-Authentication-Results: i=1; mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20161025 header.b=cz3K20dU;
       spf=pass (google.com: domain of james.a.cooper@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=james.a.cooper@gmail.com;
       dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=gmail.com
Original-Received: from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41])
        by mx.google.com with SMTPS id k3sor7752764ywl.165.2018.01.14.07.39.05
        for <std-proposals@isocpp.org>
        (Google Transport Security);
        Sun, 14 Jan 2018 07:39:05 -0800 (PST)
Received-SPF: pass (google.com: domain of james.a.cooper@gmail.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;
X-Received: by 10.129.120.85 with SMTP id t82mr13323966ywc.369.1515944344958;
 Sun, 14 Jan 2018 07:39:04 -0800 (PST)
Original-Received: by 10.37.160.3 with HTTP; Sun, 14 Jan 2018 07:39:04 -0800 (PST)
In-Reply-To: <0087c1a4-0b36-40ca-8d43-5bfaf0af62ca@isocpp.org>
X-Original-Sender: james.a.cooper@gmail.com
X-Original-Authentication-Results: mx.google.com;       dkim=pass
 header.i=@gmail.com header.s=20161025 header.b=cz3K20dU;       spf=pass
 (google.com: domain of james.a.cooper@gmail.com designates 209.85.220.41 as
 permitted sender) smtp.mailfrom=james.a.cooper@gmail.com;       dmarc=pass
 (p=NONE sp=NONE dis=NONE) header.from=gmail.com
Precedence: list
Mailing-list: list std-proposals@isocpp.org; contact std-proposals+owners@isocpp.org
List-ID: <std-proposals.isocpp.org>
X-Spam-Checked-In-Group: std-proposals@isocpp.org
X-Google-Group-Id: 399137483710
List-Post: <https://groups.google.com/a/isocpp.org/group/std-proposals/post>, <mailto:std-proposals@isocpp.org>
List-Help: <https://support.google.com/a/isocpp.org/bin/topic.py?topic=25838>, <mailto:std-proposals+help@isocpp.org>
List-Archive: <https://groups.google.com/a/isocpp.org/group/std-proposals/>
List-Subscribe: <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:std-proposals+subscribe@isocpp.org>
List-Unsubscribe: <mailto:googlegroups-manage+399137483710+unsubscribe@googlegroups.com>,
 <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>
Xref: news.gmane.org gmane.comp.lang.c++.isocpp.proposals:36616
Archived-At: <http://permalink.gmane.org/gmane.comp.lang.c++.isocpp.proposals/36616>

--94eb2c0b04de2e3d1c0562be4ce9
Content-Type: text/plain; charset="UTF-8"

This discussion will be pointless until C++ decides what it should do when
built-in static analysers discover undefined behaviour.
Right now they use it as an excuse to generate heavily optimised, but
ultimately incorrect, programs instead of just bailing out of the compile.

On Sunday, January 14, 2018, <mihailnajdenov@gmail.com> wrote:

> Hello,
> In recent years there is a boom of static analysis - from new languages
> like Rust and Swift to the powerful tools, provided by C++ compilers.
>
> However I don't see it C++ language *mandating* any of these. I have a
> question - is this something the committee is looking into? Is there a
> working group for this?
> If a tool is a lifesaver, why is it not mandatory - who does not what to
> save lifes?
>
> I strongly believe bringing more (any?) static analysis into the language
> is away to keep it modern and relevant, especially, considering C++ very
> static language and has a lot of compile-time information the tools can
> work with.
>
> Any answers and thoughts are welcome.
>
> Now on a concrete idea - to *use static analysis to make *_view classes
> safe(er).*
>
> Here is a suggestion:
>
> struct A_view
> {
>   A_view( [[dependent_lifetime]]  A&& arg) : _a(&arg) {}
>   A* _a;
> };
>
> Now, given the code above using A_view, after ~A() is called on the
> variable arg points to. will be marked as an error:
>
> A_view ref(A{}); //< OK, no use of ref
>
> A_view (A{}).func(); //< OK , A outlives ref
>
> A_view ref(A{});
> ref.func(); //< error/warning, ref used after A is destroyed
>
> I believed this can be enforced by *any* compiler, as* long as *these
> limitations apply.
> 1) A_view is not heap allocated
> 2) We forbid *all* uses of ref, not just uses involving _a;
>
> These two limitations are there to avoid tracking lifetime through
> pointers.
>
> Lifetime contract is exclusively b/w ref and *(&arg).
> Considering the compiler is responsible to destroy both of these, it
> *should* be possible to give a error/warning if variable ref is used
> after variable *(&arg) is destroyed.
> Copies of ref do not contribute to lifetime tracking - assumed is the
> view outlives the viewed the same way it is assumed when the view is
> created from a non-rvalue.
>
> Comments are more then welcome, both on the broader topic about mandating
> static analysis and the concrete proposal.
>
> Thanks
> Mihail Naydenov
>
> --
> You received this message because you are subscribed to the Google Groups
> "ISO C++ Standard - Future Proposals" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to std-proposals+unsubscribe@isocpp.org.
> To post to this group, send email to std-proposals@isocpp.org.
> To view this discussion on the web visit https://groups.google.com/a/
> isocpp.org/d/msgid/std-proposals/0087c1a4-0b36-40ca-
> 8d43-5bfaf0af62ca%40isocpp.org
> <https://groups.google.com/a/isocpp.org/d/msgid/std-proposals/0087c1a4-0b36-40ca-8d43-5bfaf0af62ca%40isocpp.org?utm_medium=email&utm_source=footer>
> .
>

-- 
You received this message because you are subscribed to the Google Groups "ISO C++ Standard - Future Proposals" group.
To unsubscribe from this group and stop receiving emails from it, send an email to std-proposals+unsubscribe@isocpp.org.
To post to this group, send email to std-proposals@isocpp.org.
To view this discussion on the web visit https://groups.google.com/a/isocpp.org/d/msgid/std-proposals/CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5LRgzAyc0abLiyQ%40mail.gmail.com.

--94eb2c0b04de2e3d1c0562be4ce9
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

This discussion will be pointless until C++ decides what it should do when =
built-in static analysers discover undefined behaviour.<div>Right now they =
use it as an excuse to generate heavily optimised, but ultimately incorrect=
, programs instead of just bailing out of the compile.<br><br>On Sunday, Ja=
nuary 14, 2018,  &lt;<a href=3D"mailto:mihailnajdenov@gmail.com">mihailnajd=
enov@gmail.com</a>&gt; wrote:<br><blockquote class=3D"gmail_quote" style=3D=
"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D=
"ltr"><div>Hello, </div><div>In recent years there is a boom of static anal=
ysis - from new languages like Rust and Swift to the powerful tools, provid=
ed by C++ compilers.</div><div><br></div><div>However I don&#39;t see it C+=
+ language <i>mandating</i> any of these. I have a question - is this somet=
hing the committee is looking into? Is there a working group for this?=C2=
=A0</div><div>If a tool is a lifesaver, why is it not mandatory - who does =
not what to save lifes?</div><div><br></div><div>I strongly believe bringin=
g more (any?) <span style=3D"display:inline!important;float:none;background=
-color:transparent;color:rgb(34,34,34);font-family:&quot;Arial&quot;,&quot;=
Helvetica&quot;,sans-serif;font-size:13px;font-style:normal;font-variant:no=
rmal;font-weight:400;letter-spacing:normal;text-align:left;text-decoration:=
none;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p=
x">static analysis into the language is away to keep it modern and relevant=
, especially, considering C++ very static language and has a lot of compile=
-time information the tools can work with.</span></div><div><br></div><div>=
Any answers and thoughts are welcome.</div><div><br></div><div>Now on a con=
crete idea - to <b>use <span style=3D"text-align:left;color:rgb(34,34,34);t=
ext-transform:none;text-indent:0px;letter-spacing:normal;font-family:&quot;=
Arial&quot;,&quot;Helvetica&quot;,sans-serif;font-size:13px;font-style:norm=
al;font-variant:normal;text-decoration:none;word-spacing:0px;display:inline=
!important;white-space:normal;float:none;background-color:transparent">stat=
ic analysis to make *_view classes safe(er)</span>.</b></div><div><b><br></=
b></div><div>Here is a suggestion:</div><div><br></div><div><font face=3D"c=
ourier new,monospace">struct A_view</font></div><div><font face=3D"courier =
new,monospace">{</font></div><div><font face=3D"courier new,monospace">=C2=
=A0 A_view( [[dependent_lifetime]]=C2=A0 A&amp;&amp; arg) : _a(&amp;arg) {}=
</font></div><div><font face=3D"courier new,monospace">=C2=A0 A* _a;</font>=
</div><div><font face=3D"courier new,monospace">};</font></div><div><font f=
ace=3D"courier new,monospace"><br></font></div><div>Now, given the code abo=
ve using A_view, after ~A() is called on the variable arg points to. will b=
e marked as an error:</div><div><br></div><div><font face=3D"courier new,mo=
nospace">A_view ref(A{}); //&lt; OK, no use of ref</font></div><div><font f=
ace=3D"courier new,monospace"><br></font></div><div><span style=3D"text-ali=
gn:left;color:rgb(34,34,34);text-transform:none;text-indent:0px;letter-spac=
ing:normal;font-size:13px;font-style:normal;font-variant:normal;font-weight=
:400;text-decoration:none;word-spacing:0px;display:inline!important;white-s=
pace:normal;float:none;background-color:transparent"><font face=3D"courier =
new,monospace">A_view (A{}).func(); //&lt; OK , A outlives ref</font></span=
></div><div><span style=3D"text-align:left;color:rgb(34,34,34);text-transfo=
rm:none;text-indent:0px;letter-spacing:normal;font-size:13px;font-style:nor=
mal;font-variant:normal;font-weight:400;text-decoration:none;word-spacing:0=
px;display:inline!important;white-space:normal;float:none;background-color:=
transparent"><font face=3D"courier new,monospace"><br></font></span></div><=
div><span style=3D"text-align:left;color:rgb(34,34,34);text-transform:none;=
text-indent:0px;letter-spacing:normal;font-size:13px;font-variant:normal;wo=
rd-spacing:0px;display:inline!important;white-space:normal;float:none;backg=
round-color:transparent"><span style=3D"text-align:left;color:rgb(34,34,34)=
;text-transform:none;text-indent:0px;letter-spacing:normal;font-size:13px;f=
ont-style:normal;font-variant:normal;font-weight:400;text-decoration:none;w=
ord-spacing:0px;display:inline!important;white-space:normal;float:none;back=
ground-color:transparent"><font face=3D"courier new,monospace">A_view ref(A=
{});</font></span></span></div><div><font face=3D"courier new,monospace">re=
f<span style=3D"text-align:left;color:rgb(34,34,34);text-transform:none;tex=
t-indent:0px;letter-spacing:normal;font-size:13px;font-variant:normal;word-=
spacing:0px;display:inline!important;white-space:normal;float:none;backgrou=
nd-color:transparent"><span style=3D"text-align:left;color:rgb(34,34,34);te=
xt-transform:none;text-indent:0px;letter-spacing:normal;font-size:13px;font=
-style:normal;font-variant:normal;font-weight:400;text-decoration:none;word=
-spacing:0px;display:inline!important;white-space:normal;float:none;backgro=
und-color:transparent">.func(); //&lt; error/warning, ref used after A is d=
estroyed</span></span></font></div><div><font face=3D"courier new,monospace=
"><span style=3D"text-align:left;color:rgb(34,34,34);text-transform:none;te=
xt-indent:0px;letter-spacing:normal;font-size:13px;font-variant:normal;word=
-spacing:0px;display:inline!important;white-space:normal;float:none;backgro=
und-color:transparent"><span style=3D"text-align:left;color:rgb(34,34,34);t=
ext-transform:none;text-indent:0px;letter-spacing:normal;font-size:13px;fon=
t-style:normal;font-variant:normal;font-weight:400;text-decoration:none;wor=
d-spacing:0px;display:inline!important;white-space:normal;float:none;backgr=
ound-color:transparent"><br></span></span></font></div><div><span style=3D"=
text-align:left;color:rgb(34,34,34);text-transform:none;text-indent:0px;let=
ter-spacing:normal;font-size:13px;font-variant:normal;word-spacing:0px;disp=
lay:inline!important;white-space:normal;float:none;background-color:transpa=
rent"><span style=3D"text-align:left;color:rgb(34,34,34);text-transform:non=
e;text-indent:0px;letter-spacing:normal;font-size:13px;font-style:normal;fo=
nt-variant:normal;font-weight:400;text-decoration:none;word-spacing:0px;dis=
play:inline!important;white-space:normal;float:none;background-color:transp=
arent"><font face=3D"arial,sans-serif">I believed this can be enforced by <=
i>any</i> compiler, as<i> long as </i>these limitations apply.</font></span=
></span></div><div>1) A_view is not heap allocated=C2=A0</div><div>2) We fo=
rbid <b>all</b> uses of <font face=3D"courier new,monospace">ref</font>, no=
t just uses involving _a;</div><div><br></div><div>These two limitations ar=
e there to avoid tracking lifetime through pointers.</div><div><br></div><d=
iv>Lifetime contract is exclusively b/w <font face=3D"courier new,monospace=
">ref </font><font face=3D"arial,sans-serif">and</font><font face=3D"courie=
r new,monospace"> *(&amp;arg).=C2=A0</font></div><div><font face=3D"arial,s=
ans-serif">Considering the compiler is responsible to destroy both of these=
, it <i>should</i> be possible to give a error/warning if variable <font fa=
ce=3D"courier new,monospace">ref</font> is used after variable=C2=A0<span s=
tyle=3D"display:inline!important;float:none;background-color:transparent;co=
lor:rgb(34,34,34);font-family:courier new,monospace;font-size:13px;font-sty=
le:normal;font-variant:normal;font-weight:400;letter-spacing:normal;text-al=
ign:left;text-decoration:none;text-indent:0px;text-transform:none;white-spa=
ce:normal;word-spacing:0px">*(&amp;arg)<font face=3D"arial,sans-serif"> </f=
ont><font face=3D"arial,sans-serif">is destroyed.</font></span></font></div=
><div><font face=3D"arial,sans-serif">Copies of <font face=3D"courier new,m=
onospace">ref</font> do not contribute to lifetime tracking - assumed is th=
e view outlives the viewed the same way it is assumed when the view is crea=
ted from a non-rvalue.</font><font face=3D"arial,sans-serif"><i><b></b></i>=
</font></div><div><b><i><font face=3D"arial,sans-serif"><br></font></i></b>=
</div><div><font face=3D"arial,sans-serif">Comments are more then welcome, =
both on the broader topic about mandating static analysis and the concrete =
proposal.</font></div><div><br></div><div>Thanks=C2=A0</div><div>Mihail Nay=
denov</div></div>

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org" target=3D"_=
blank">std-proposals+unsubscribe@<wbr>isocpp.org</a>.<br>
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org" target=3D"_blank">std-proposals@isocpp.org</a>.<br>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/0087c1a4-0b36-40ca-8d43-5bfaf0af62ca%=
40isocpp.org?utm_medium=3Demail&amp;utm_source=3Dfooter" target=3D"_blank">=
https://groups.google.com/a/<wbr>isocpp.org/d/msgid/std-<wbr>proposals/0087=
c1a4-0b36-40ca-<wbr>8d43-5bfaf0af62ca%40isocpp.org</a><wbr>.<br>
</blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org">std-proposa=
ls+unsubscribe@isocpp.org</a>.<br />
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org">std-proposals@isocpp.org</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5=
LRgzAyc0abLiyQ%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">htt=
ps://groups.google.com/a/isocpp.org/d/msgid/std-proposals/CAFQaeCDQyFB8zoRo=
BzBJsjQGUi2wJVsW8Yn5LRgzAyc0abLiyQ%40mail.gmail.com</a>.<br />

--94eb2c0b04de2e3d1c0562be4ce9--

.
