220 36622 <CALvx3hYc2dwGc=U7N7tcnaFpk6Wa-vhNeAgrhQ=qCCciF_G9-A@mail.gmail.com> article
Path: news.gmane.org!.POSTED!not-for-mail
From: Richard Hodges <hodges.r@gmail.com>
Newsgroups: gmane.comp.lang.c++.isocpp.proposals
Subject: Re: Static analysis and the future of C++
Date: Sun, 14 Jan 2018 17:24:54 +0100
Lines: 300
Approved: news@gmane.org
Message-ID: <CALvx3hYc2dwGc=U7N7tcnaFpk6Wa-vhNeAgrhQ=qCCciF_G9-A@mail.gmail.com>
References: <0087c1a4-0b36-40ca-8d43-5bfaf0af62ca@isocpp.org> <CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5LRgzAyc0abLiyQ@mail.gmail.com>
Reply-To: std-proposals@isocpp.org
NNTP-Posting-Host: blaine.gmane.org
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="001a113fbfc6187d0c0562bef0f7"
X-Trace: blaine.gmane.org 1515946986 14550 195.159.176.226 (14 Jan 2018 16:23:06 GMT)
X-Complaints-To: usenet@blaine.gmane.org
NNTP-Posting-Date: Sun, 14 Jan 2018 16:23:06 +0000 (UTC)
To: std-proposals@isocpp.org
Original-X-From: std-proposals+bncBD4PBM7UWAHRBV4I53JAKGQERZQC7TY@isocpp.org Sun Jan 14 17:23:02 2018
Return-path: <std-proposals+bncBD4PBM7UWAHRBV4I53JAKGQERZQC7TY@isocpp.org>
Envelope-to: gclcip-std-proposals@m.gmane.org
Original-Received: from mail-it0-f72.google.com ([209.85.214.72])
	by blaine.gmane.org with esmtp (Exim 4.84_2)
	(envelope-from <std-proposals+bncBD4PBM7UWAHRBV4I53JAKGQERZQC7TY@isocpp.org>)
	id 1eal3d-0002jB-8P
	for gclcip-std-proposals@m.gmane.org; Sun, 14 Jan 2018 17:22:53 +0100
Original-Received: by mail-it0-f72.google.com with SMTP id i67sf11948049ith.1
        for <gclcip-std-proposals@m.gmane.org>; Sun, 14 Jan 2018 08:24:57 -0800 (PST)
ARC-Seal: i=2; a=rsa-sha256; t=1515947096; cv=pass;
        d=google.com; s=arc-20160816;
        b=sOwfKzvfhvb0Zue4T/KHwqr8t/+04lkgOwGHL7UZZSoikDGDsY4WgOzl2zPQYCRbtR
         uolur5sEvaKzkcNkRg718jnoj9yEundh0M79b5+fB/za0rPIrbtpa/jYvESW5BQh3s2H
         ld0KyRN7mGWDF/TawVaQvcmNGUilipGeWxYil4Is1c00XMyG2DErS75SRmuUar+QwRJV
         7eOUq1NUzl7svsfvk6bJ934GDkawYK0/4FLOP7cGvkT+pPQLZ1hUVHy+MYU3AhyrW2NI
         2nkz3d5gkDnUNeY20vn+hGsgIk8YYvkU42VjMeNXTolasbzjHn8L1IiNtXI4+nF0zoic
         TeTg==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
         :list-id:mailing-list:precedence:reply-to:to:subject:message-id:date
         :from:references:in-reply-to:mime-version:arc-authentication-results
         :arc-message-signature:dkim-signature:arc-authentication-results;
        bh=5TtQXMEppOw57nahaeRqkh31o0YqXnyn4YNRJzLHP1w=;
        b=t4op9RNTxgx8l0gf7pRDT0WyAnsTr59ba8upx3EfjLTb3mS0tdxNguGYVF30ZaXDxn
         pq2EoSCIZYe0JWeAyOAZDRBVeLkxSOBygAgiJIzA4H63MkOdhPDr7Rsx8VfA3wg9j2d1
         vyN3XiyAk1OfBnfPD5H5HRa8wLjzTUoCDOo+tVCOkkpeZF+Bv8iKm6DugokgbaabKiA/
         AIPrwmb72FJ5XqPxIPZjql1DBl30Q0d6kW/KGrUMvebceoMAC2P2AOmydWgZkqZ3LPij
         HkGLnk2HY51AHXmXEOFqqMVXP6duLKDJzQ13sJ6EfQORRIXaefHawfDKCKaPevPlrEha
         x9Tg==
ARC-Authentication-Results: i=2; mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20161025 header.b=ZvshVGqJ;
       spf=pass (google.com: domain of hodges.r@gmail.com designates 209.85.220.65 as permitted sender) smtp.mailfrom=hodges.r@gmail.com;
       dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=gmail.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=isocpp-org.20150623.gappssmtp.com; s=20150623;
        h=mime-version:in-reply-to:references:from:date:message-id:subject:to
         :x-original-sender:x-original-authentication-results:reply-to
         :precedence:mailing-list:list-id:list-post:list-help:list-archive
         :list-subscribe:list-unsubscribe;
        bh=5TtQXMEppOw57nahaeRqkh31o0YqXnyn4YNRJzLHP1w=;
        b=VmbcVq+ebyszsuYRAm/I6mHNR95Lf+44a/aqskyEkhAf9BNqccqCPq4lamsugk23s7
         HV9M6CqxOz/3FXly52BaJr/4WWHeYEEwpqNMcdCthi/uSov7hxT6PgLEIn6K9bU9buNo
         YeTRZWQ63IReYpnkZ46M4BknE2LZ2nyXcb4jmiWuhlSOeuaxYGH36laMPp1CUYCOZYAr
         oW6SbrOyiO6ppHH8ecjS0PXDtcYMeVJXJUQMRBTb6A23M6VbQvYG3N4b+6zzynUHVgdg
         /8IXRbIbNtbcQu7BG5IU9HsaUQHqQ7pm3b57JP2xaGs9PSW0DEqihzgINhPRGoibACTa
         Y79Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:mime-version:in-reply-to:references:from:date
         :message-id:subject:to:x-original-sender
         :x-original-authentication-results:reply-to:precedence:mailing-list
         :list-id:x-spam-checked-in-group:list-post:list-help:list-archive
         :list-subscribe:list-unsubscribe;
        bh=5TtQXMEppOw57nahaeRqkh31o0YqXnyn4YNRJzLHP1w=;
        b=B2K/JCJ/5KRFOBe+6466TRaSDCqb0mrSOSJ97I3wjT0wPXptZ0oWFnYSIZ0rGPm28L
         DaQXpiOHvwnmgdBeFpWUNvWMfqZZrPXWiKnKLcmSLNYKSE5b2lT6KN9v/7VjohDR5u3k
         a76Yxnht1XsArf9MXd5/H7e+4vXHgJU1MhNWE7Rc1BmBLVwCOQWaLym1Mxjp0xzmtoHO
         5sh3Hv4lSnc+YLAugy1+f0AsYDAXNchr5diAJi90+HRrFHpoJBR2kxAb6LycWsTtLJFH
         aT/xQJWQrYnA9fK58nQlhMMp9qFhZ2n6h+ax9F3ukHwUimz3AorRVfs3gscNXmJBntav
         YC8Q==
X-Gm-Message-State: AKwxytdJsoomE48Bz7huy4cdhCyKugc3wQMQT1F00j7Tg58hRMtAZuVX
	W5/q0uGGD+cbt4LNktW7aNzkRw==
X-Google-Smtp-Source: ACJfBosLzG3zSlXfFjS+jC4kMOg9UIPDemIHcWQZl6sbux4V3pJeZIOLd/xuIAphvClS1fnkm5KGeQ==
X-Received: by 10.107.190.70 with SMTP id o67mr10307347iof.59.1515947096883;
        Sun, 14 Jan 2018 08:24:56 -0800 (PST)
X-BeenThere: std-proposals@isocpp.org
Original-Received: by 10.36.148.207 with SMTP id j198ls940450ite.1.canary-gmail; Sun,
 14 Jan 2018 08:24:55 -0800 (PST)
X-Received: by 10.36.203.131 with SMTP id u125mr12200359itg.78.1515947095548;
        Sun, 14 Jan 2018 08:24:55 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1515947095; cv=none;
        d=google.com; s=arc-20160816;
        b=Az7bGtsHlVYQ3PvmCZFCI1coZKdO+Ib5jZRkzRV4iqMyvI8KYZEBvJ/5jzttGHee1R
         leR4pYG81Iq1+AfDjtyR60Xso7yD82jaasv6C3E8hcbRFcDYcGnPYsHg7EjUvJT8S/vg
         EpXjA+3soimVCHUBPniU5O/56OagvY5p7M31b0f0AbVdj4wH7TyuCUssyJw/p4pGjYtY
         CuX3X1OlK2SQM+HovKBgxMhINdrm7aA2Qoxsa5XB8SuKh3OS3QLjmAN7FVXRNycmJ/p9
         U2ZMU2a+g6RdiW/1dbdaz7CDfl9Eg2Ajz5Ltce8/PlzW1hIavJxyDvdy/kDo/84u8uee
         90og==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=to:subject:message-id:date:from:references:in-reply-to:mime-version
         :dkim-signature:arc-authentication-results;
        bh=wVirbNTZInVUFONn0SIObTcV5iSWwDq0/fSFMMgcheQ=;
        b=lRvvg8598uamg7scMMOMzRPO+51oZ+Tltv+7KPg+sVHnUmazkApjIFmrIWIEEm/tGm
         XizEI8I4We/Hedew+9jq7fgpvW1ww4Oo/fJ98pM0EbyUpRSIzQ/N8XUigZiEEDflvxUn
         bB0Q2EK7EyUOYlTt7wIdMOUYwCJURZ1gG0wzpZvlOYStP6krTbWLIJ47tpUDZt5C4yLj
         r+H92B81iTdlijUQvHBxXsOmNj7wrHfsfpWoZgz7QOWEdVLQz2hRcC0MteAhMe02QmLI
         DNebiUFzJKXhEJiVKyFxF18IbcxrhwPWsKE1OWNsZYwKdJoDctB5i7CHlI9nD81m4WmI
         MB8w==
ARC-Authentication-Results: i=1; mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20161025 header.b=ZvshVGqJ;
       spf=pass (google.com: domain of hodges.r@gmail.com designates 209.85.220.65 as permitted sender) smtp.mailfrom=hodges.r@gmail.com;
       dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=gmail.com
Original-Received: from mail-sor-f65.google.com (mail-sor-f65.google.com. [209.85.220.65])
        by mx.google.com with SMTPS id n204sor13548566ion.229.2018.01.14.08.24.55
        for <std-proposals@isocpp.org>
        (Google Transport Security);
        Sun, 14 Jan 2018 08:24:55 -0800 (PST)
Received-SPF: pass (google.com: domain of hodges.r@gmail.com designates 209.85.220.65 as permitted sender) client-ip=209.85.220.65;
X-Received: by 10.107.135.208 with SMTP id r77mr11148438ioi.248.1515947094997;
 Sun, 14 Jan 2018 08:24:54 -0800 (PST)
Original-Received: by 10.2.126.75 with HTTP; Sun, 14 Jan 2018 08:24:54 -0800 (PST)
In-Reply-To: <CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5LRgzAyc0abLiyQ@mail.gmail.com>
X-Original-Sender: hodges.r@gmail.com
X-Original-Authentication-Results: mx.google.com;       dkim=pass
 header.i=@gmail.com header.s=20161025 header.b=ZvshVGqJ;       spf=pass
 (google.com: domain of hodges.r@gmail.com designates 209.85.220.65 as
 permitted sender) smtp.mailfrom=hodges.r@gmail.com;       dmarc=pass (p=NONE
 sp=NONE dis=NONE) header.from=gmail.com
Precedence: list
Mailing-list: list std-proposals@isocpp.org; contact std-proposals+owners@isocpp.org
List-ID: <std-proposals.isocpp.org>
X-Spam-Checked-In-Group: std-proposals@isocpp.org
X-Google-Group-Id: 399137483710
List-Post: <https://groups.google.com/a/isocpp.org/group/std-proposals/post>, <mailto:std-proposals@isocpp.org>
List-Help: <https://support.google.com/a/isocpp.org/bin/topic.py?topic=25838>, <mailto:std-proposals+help@isocpp.org>
List-Archive: <https://groups.google.com/a/isocpp.org/group/std-proposals/>
List-Subscribe: <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:std-proposals+subscribe@isocpp.org>
List-Unsubscribe: <mailto:googlegroups-manage+399137483710+unsubscribe@googlegroups.com>,
 <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>
Xref: news.gmane.org gmane.comp.lang.c++.isocpp.proposals:36622
Archived-At: <http://permalink.gmane.org/gmane.comp.lang.c++.isocpp.proposals/36622>

--001a113fbfc6187d0c0562bef0f7
Content-Type: text/plain; charset="UTF-8"

> This discussion will be pointless until C++ decides what it should do
when built-in static analysers discover undefined behaviour.

It's obvious to anyone but the isocpp committee what it should do. It
should fail to compile and issue a meaningful diagnostic, whenever
possible, for any and all UB unless that UB has been specifically opted-in
through pragmas and/or attributes.

Any other course of action is indefensible.



On 14 January 2018 at 16:39, j c <james.a.cooper@gmail.com> wrote:

> This discussion will be pointless until C++ decides what it should do when
> built-in static analysers discover undefined behaviour.
> Right now they use it as an excuse to generate heavily optimised, but
> ultimately incorrect, programs instead of just bailing out of the compile.
>
>
> On Sunday, January 14, 2018, <mihailnajdenov@gmail.com> wrote:
>
>> Hello,
>> In recent years there is a boom of static analysis - from new languages
>> like Rust and Swift to the powerful tools, provided by C++ compilers.
>>
>> However I don't see it C++ language *mandating* any of these. I have a
>> question - is this something the committee is looking into? Is there a
>> working group for this?
>> If a tool is a lifesaver, why is it not mandatory - who does not what to
>> save lifes?
>>
>> I strongly believe bringing more (any?) static analysis into the
>> language is away to keep it modern and relevant, especially, considering
>> C++ very static language and has a lot of compile-time information the
>> tools can work with.
>>
>> Any answers and thoughts are welcome.
>>
>> Now on a concrete idea - to *use static analysis to make *_view classes
>> safe(er).*
>>
>> Here is a suggestion:
>>
>> struct A_view
>> {
>>   A_view( [[dependent_lifetime]]  A&& arg) : _a(&arg) {}
>>   A* _a;
>> };
>>
>> Now, given the code above using A_view, after ~A() is called on the
>> variable arg points to. will be marked as an error:
>>
>> A_view ref(A{}); //< OK, no use of ref
>>
>> A_view (A{}).func(); //< OK , A outlives ref
>>
>> A_view ref(A{});
>> ref.func(); //< error/warning, ref used after A is destroyed
>>
>> I believed this can be enforced by *any* compiler, as* long as *these
>> limitations apply.
>> 1) A_view is not heap allocated
>> 2) We forbid *all* uses of ref, not just uses involving _a;
>>
>> These two limitations are there to avoid tracking lifetime through
>> pointers.
>>
>> Lifetime contract is exclusively b/w ref and *(&arg).
>> Considering the compiler is responsible to destroy both of these, it
>> *should* be possible to give a error/warning if variable ref is used
>> after variable *(&arg) is destroyed.
>> Copies of ref do not contribute to lifetime tracking - assumed is the
>> view outlives the viewed the same way it is assumed when the view is
>> created from a non-rvalue.
>>
>> Comments are more then welcome, both on the broader topic about mandating
>> static analysis and the concrete proposal.
>>
>> Thanks
>> Mihail Naydenov
>>
>> --
>> You received this message because you are subscribed to the Google Groups
>> "ISO C++ Standard - Future Proposals" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to std-proposals+unsubscribe@isocpp.org.
>> To post to this group, send email to std-proposals@isocpp.org.
>> To view this discussion on the web visit https://groups.google.com/a/is
>> ocpp.org/d/msgid/std-proposals/0087c1a4-0b36-40ca-8d43-
>> 5bfaf0af62ca%40isocpp.org
>> <https://groups.google.com/a/isocpp.org/d/msgid/std-proposals/0087c1a4-0b36-40ca-8d43-5bfaf0af62ca%40isocpp.org?utm_medium=email&utm_source=footer>
>> .
>>
> --
> You received this message because you are subscribed to the Google Groups
> "ISO C++ Standard - Future Proposals" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to std-proposals+unsubscribe@isocpp.org.
> To post to this group, send email to std-proposals@isocpp.org.
> To view this discussion on the web visit https://groups.google.com/a/
> isocpp.org/d/msgid/std-proposals/CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJ
> VsW8Yn5LRgzAyc0abLiyQ%40mail.gmail.com
> <https://groups.google.com/a/isocpp.org/d/msgid/std-proposals/CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5LRgzAyc0abLiyQ%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>

-- 
You received this message because you are subscribed to the Google Groups "ISO C++ Standard - Future Proposals" group.
To unsubscribe from this group and stop receiving emails from it, send an email to std-proposals+unsubscribe@isocpp.org.
To post to this group, send email to std-proposals@isocpp.org.
To view this discussion on the web visit https://groups.google.com/a/isocpp.org/d/msgid/std-proposals/CALvx3hYc2dwGc%3DU7N7tcnaFpk6Wa-vhNeAgrhQ%3DqCCciF_G9-A%40mail.gmail.com.

--001a113fbfc6187d0c0562bef0f7
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">&gt;=C2=A0<span style=3D"font-size:12.8px">This discussion=
 will be pointless until C++ decides what it should do when built-in static=
 analysers discover undefined behaviour.</span><div><span style=3D"font-siz=
e:12.8px"><br></span></div><div><span style=3D"font-size:12.8px">It&#39;s o=
bvious to anyone but the isocpp committee=C2=A0what it should do. It should=
 fail to compile and issue a meaningful diagnostic, whenever possible, for =
any and all UB unless that UB has been specifically opted-in through pragma=
s and/or attributes.</span></div><div><span style=3D"font-size:12.8px"><br>=
</span></div><div><span style=3D"font-size:12.8px">Any other course of acti=
on is indefensible.</span></div><div><span style=3D"font-size:12.8px"><br><=
/span></div><div><span style=3D"font-size:12.8px"><br></span></div></div><d=
iv class=3D"gmail_extra"><br><div class=3D"gmail_quote">On 14 January 2018 =
at 16:39, j c <span dir=3D"ltr">&lt;<a href=3D"mailto:james.a.cooper@gmail.=
com" target=3D"_blank">james.a.cooper@gmail.com</a>&gt;</span> wrote:<br><b=
lockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px =
#ccc solid;padding-left:1ex">This discussion will be pointless until C++ de=
cides what it should do when built-in static analysers discover undefined b=
ehaviour.<div>Right now they use it as an excuse to generate heavily optimi=
sed, but ultimately incorrect, programs instead of just bailing out of the =
compile.<div><div class=3D"h5"><br><br>On Sunday, January 14, 2018,  &lt;<a=
 href=3D"mailto:mihailnajdenov@gmail.com" target=3D"_blank">mihailnajdenov@=
gmail.com</a>&gt; wrote:<br><blockquote class=3D"gmail_quote" style=3D"marg=
in:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"=
><div>Hello, </div><div>In recent years there is a boom of static analysis =
- from new languages like Rust and Swift to the powerful tools, provided by=
 C++ compilers.</div><div><br></div><div>However I don&#39;t see it C++ lan=
guage <i>mandating</i> any of these. I have a question - is this something =
the committee is looking into? Is there a working group for this?=C2=A0</di=
v><div>If a tool is a lifesaver, why is it not mandatory - who does not wha=
t to save lifes?</div><div><br></div><div>I strongly believe bringing more =
(any?) <span style=3D"display:inline!important;float:none;background-color:=
transparent;color:rgb(34,34,34);font-family:&quot;Arial&quot;,&quot;Helveti=
ca&quot;,sans-serif;font-size:13px;font-style:normal;font-variant:normal;fo=
nt-weight:400;letter-spacing:normal;text-align:left;text-decoration:none;te=
xt-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">stat=
ic analysis into the language is away to keep it modern and relevant, espec=
ially, considering C++ very static language and has a lot of compile-time i=
nformation the tools can work with.</span></div><div><br></div><div>Any ans=
wers and thoughts are welcome.</div><div><br></div><div>Now on a concrete i=
dea - to <b>use <span style=3D"text-align:left;color:rgb(34,34,34);text-tra=
nsform:none;text-indent:0px;letter-spacing:normal;font-family:&quot;Arial&q=
uot;,&quot;Helvetica&quot;,sans-serif;font-size:13px;font-style:normal;font=
-variant:normal;text-decoration:none;word-spacing:0px;display:inline!import=
ant;white-space:normal;float:none;background-color:transparent">static anal=
ysis to make *_view classes safe(er)</span>.</b></div><div><b><br></b></div=
><div>Here is a suggestion:</div><div><br></div><div><font face=3D"courier =
new,monospace">struct A_view</font></div><div><font face=3D"courier new,mon=
ospace">{</font></div><div><font face=3D"courier new,monospace">=C2=A0 A_vi=
ew( [[dependent_lifetime]]=C2=A0 A&amp;&amp; arg) : _a(&amp;arg) {}</font><=
/div><div><font face=3D"courier new,monospace">=C2=A0 A* _a;</font></div><d=
iv><font face=3D"courier new,monospace">};</font></div><div><font face=3D"c=
ourier new,monospace"><br></font></div><div>Now, given the code above using=
 A_view, after ~A() is called on the variable arg points to. will be marked=
 as an error:</div><div><br></div><div><font face=3D"courier new,monospace"=
>A_view ref(A{}); //&lt; OK, no use of ref</font></div><div><font face=3D"c=
ourier new,monospace"><br></font></div><div><span style=3D"text-align:left;=
color:rgb(34,34,34);text-transform:none;text-indent:0px;letter-spacing:norm=
al;font-size:13px;font-style:normal;font-variant:normal;font-weight:400;tex=
t-decoration:none;word-spacing:0px;display:inline!important;white-space:nor=
mal;float:none;background-color:transparent"><font face=3D"courier new,mono=
space">A_view (A{}).func(); //&lt; OK , A outlives ref</font></span></div><=
div><span style=3D"text-align:left;color:rgb(34,34,34);text-transform:none;=
text-indent:0px;letter-spacing:normal;font-size:13px;font-style:normal;font=
-variant:normal;font-weight:400;text-decoration:none;word-spacing:0px;displ=
ay:inline!important;white-space:normal;float:none;background-color:transpar=
ent"><font face=3D"courier new,monospace"><br></font></span></div><div><spa=
n style=3D"text-align:left;color:rgb(34,34,34);text-transform:none;text-ind=
ent:0px;letter-spacing:normal;font-size:13px;font-variant:normal;word-spaci=
ng:0px;display:inline!important;white-space:normal;float:none;background-co=
lor:transparent"><span style=3D"text-align:left;color:rgb(34,34,34);text-tr=
ansform:none;text-indent:0px;letter-spacing:normal;font-size:13px;font-styl=
e:normal;font-variant:normal;font-weight:400;text-decoration:none;word-spac=
ing:0px;display:inline!important;white-space:normal;float:none;background-c=
olor:transparent"><font face=3D"courier new,monospace">A_view ref(A{});</fo=
nt></span></span></div><div><font face=3D"courier new,monospace">ref<span s=
tyle=3D"text-align:left;color:rgb(34,34,34);text-transform:none;text-indent=
:0px;letter-spacing:normal;font-size:13px;font-variant:normal;word-spacing:=
0px;display:inline!important;white-space:normal;float:none;background-color=
:transparent"><span style=3D"text-align:left;color:rgb(34,34,34);text-trans=
form:none;text-indent:0px;letter-spacing:normal;font-size:13px;font-style:n=
ormal;font-variant:normal;font-weight:400;text-decoration:none;word-spacing=
:0px;display:inline!important;white-space:normal;float:none;background-colo=
r:transparent">.func(); //&lt; error/warning, ref used after A is destroyed=
</span></span></font></div><div><font face=3D"courier new,monospace"><span =
style=3D"text-align:left;color:rgb(34,34,34);text-transform:none;text-inden=
t:0px;letter-spacing:normal;font-size:13px;font-variant:normal;word-spacing=
:0px;display:inline!important;white-space:normal;float:none;background-colo=
r:transparent"><span style=3D"text-align:left;color:rgb(34,34,34);text-tran=
sform:none;text-indent:0px;letter-spacing:normal;font-size:13px;font-style:=
normal;font-variant:normal;font-weight:400;text-decoration:none;word-spacin=
g:0px;display:inline!important;white-space:normal;float:none;background-col=
or:transparent"><br></span></span></font></div><div><span style=3D"text-ali=
gn:left;color:rgb(34,34,34);text-transform:none;text-indent:0px;letter-spac=
ing:normal;font-size:13px;font-variant:normal;word-spacing:0px;display:inli=
ne!important;white-space:normal;float:none;background-color:transparent"><s=
pan style=3D"text-align:left;color:rgb(34,34,34);text-transform:none;text-i=
ndent:0px;letter-spacing:normal;font-size:13px;font-style:normal;font-varia=
nt:normal;font-weight:400;text-decoration:none;word-spacing:0px;display:inl=
ine!important;white-space:normal;float:none;background-color:transparent"><=
font face=3D"arial,sans-serif">I believed this can be enforced by <i>any</i=
> compiler, as<i> long as </i>these limitations apply.</font></span></span>=
</div><div>1) A_view is not heap allocated=C2=A0</div><div>2) We forbid <b>=
all</b> uses of <font face=3D"courier new,monospace">ref</font>, not just u=
ses involving _a;</div><div><br></div><div>These two limitations are there =
to avoid tracking lifetime through pointers.</div><div><br></div><div>Lifet=
ime contract is exclusively b/w <font face=3D"courier new,monospace">ref </=
font><font face=3D"arial,sans-serif">and</font><font face=3D"courier new,mo=
nospace"> *(&amp;arg).=C2=A0</font></div><div><font face=3D"arial,sans-seri=
f">Considering the compiler is responsible to destroy both of these, it <i>=
should</i> be possible to give a error/warning if variable <font face=3D"co=
urier new,monospace">ref</font> is used after variable=C2=A0<span style=3D"=
display:inline!important;float:none;background-color:transparent;color:rgb(=
34,34,34);font-family:courier new,monospace;font-size:13px;font-style:norma=
l;font-variant:normal;font-weight:400;letter-spacing:normal;text-align:left=
;text-decoration:none;text-indent:0px;text-transform:none;white-space:norma=
l;word-spacing:0px">*(&amp;arg)<font face=3D"arial,sans-serif"> </font><fon=
t face=3D"arial,sans-serif">is destroyed.</font></span></font></div><div><f=
ont face=3D"arial,sans-serif">Copies of <font face=3D"courier new,monospace=
">ref</font> do not contribute to lifetime tracking - assumed is the view o=
utlives the viewed the same way it is assumed when the view is created from=
 a non-rvalue.</font><font face=3D"arial,sans-serif"><i><b></b></i></font><=
/div><div><b><i><font face=3D"arial,sans-serif"><br></font></i></b></div><d=
iv><font face=3D"arial,sans-serif">Comments are more then welcome, both on =
the broader topic about mandating static analysis and the concrete proposal=
..</font></div><div><br></div><div>Thanks=C2=A0</div><div>Mihail Naydenov</d=
iv></div>

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org" target=3D"_=
blank">std-proposals+unsubscribe@isoc<wbr>pp.org</a>.<br>
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org" target=3D"_blank">std-proposals@isocpp.org</a>.<br>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/0087c1a4-0b36-40ca-8d43-5bfaf0af62ca%=
40isocpp.org?utm_medium=3Demail&amp;utm_source=3Dfooter" target=3D"_blank">=
https://groups.google.com/a/is<wbr>ocpp.org/d/msgid/std-proposals<wbr>/0087=
c1a4-0b36-40ca-8d43-<wbr>5bfaf0af62ca%40isocpp.org</a>.<br>
</blockquote></div></div></div><div><div class=3D"h5">

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org" target=3D"_=
blank">std-proposals+unsubscribe@<wbr>isocpp.org</a>.<br>
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org" target=3D"_blank">std-proposals@isocpp.org</a>.<br></div></div>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJVsW8Yn5=
LRgzAyc0abLiyQ%40mail.gmail.com?utm_medium=3Demail&amp;utm_source=3Dfooter"=
 target=3D"_blank">https://groups.google.com/a/<wbr>isocpp.org/d/msgid/std-=
<wbr>proposals/<wbr>CAFQaeCDQyFB8zoRoBzBJsjQGUi2wJ<wbr>VsW8Yn5LRgzAyc0abLiy=
Q%40mail.<wbr>gmail.com</a>.<br>
</blockquote></div><br></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org">std-proposa=
ls+unsubscribe@isocpp.org</a>.<br />
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org">std-proposals@isocpp.org</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/CALvx3hYc2dwGc%3DU7N7tcnaFpk6Wa-vhNeA=
grhQ%3DqCCciF_G9-A%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter"=
>https://groups.google.com/a/isocpp.org/d/msgid/std-proposals/CALvx3hYc2dwG=
c%3DU7N7tcnaFpk6Wa-vhNeAgrhQ%3DqCCciF_G9-A%40mail.gmail.com</a>.<br />

--001a113fbfc6187d0c0562bef0f7--

.
