220 37325 <4BDA3D07-62AA-4B30-BCA0-875A446F6B23@gmail.com> article
Path: news.gmane.org!.POSTED!not-for-mail
From: Jonathan Coe <jonathanbcoe@gmail.com>
Newsgroups: gmane.comp.lang.c++.isocpp.proposals
Subject: =?UTF-8?Q?Re=3A_=5Bstd=2Dproposals=5D_Re=3A_Enforcing_safe_coding_techni?=
	=?UTF-8?Q?ques_using_=E2=80=9Csafe=E2=80=9D_and_=E2=80=9Ctrusted=E2=80=9D_function_qualifiers?=
Date: Wed, 14 Mar 2018 00:04:50 -0400
Lines: 225
Approved: news@gmane.org
Message-ID: <4BDA3D07-62AA-4B30-BCA0-875A446F6B23@gmail.com>
References: <245f1f1b-d168-4434-a605-f82bff4a99af@isocpp.org> <1a250082-a1d8-4f36-93a3-8540056ff279@isocpp.org>
Reply-To: std-proposals@isocpp.org
NNTP-Posting-Host: blaine.gmane.org
Mime-Version: 1.0 (1.0)
Content-Type: multipart/alternative;
	boundary=Apple-Mail-BDFF506A-E25C-49B4-A85D-5BEF185A0D5B
Content-Transfer-Encoding: 7bit
X-Trace: blaine.gmane.org 1521000173 26967 195.159.176.226 (14 Mar 2018 04:02:53 GMT)
X-Complaints-To: usenet@blaine.gmane.org
NNTP-Posting-Date: Wed, 14 Mar 2018 04:02:53 +0000 (UTC)
To: std-proposals@isocpp.org
Original-X-From: std-proposals+bncBC2JVFPBRAHBBZN6ULKQKGQEWALQOXA@isocpp.org Wed Mar 14 05:02:49 2018
Return-path: <std-proposals+bncBC2JVFPBRAHBBZN6ULKQKGQEWALQOXA@isocpp.org>
Envelope-to: gclcip-std-proposals@m.gmane.org
Original-Received: from mail-yw0-f198.google.com ([209.85.161.198])
	by blaine.gmane.org with esmtp (Exim 4.84_2)
	(envelope-from <std-proposals+bncBC2JVFPBRAHBBZN6ULKQKGQEWALQOXA@isocpp.org>)
	id 1evxcm-0006sC-2x
	for gclcip-std-proposals@m.gmane.org; Wed, 14 Mar 2018 05:02:48 +0100
Original-Received: by mail-yw0-f198.google.com with SMTP id y196sf2361899ywg.19
        for <gclcip-std-proposals@m.gmane.org>; Tue, 13 Mar 2018 21:04:55 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; t=1521000294; cv=pass;
        d=google.com; s=arc-20160816;
        b=BizviG3IMPddKzmBJq8ZJxmKflXHCEIf2ej8iNbWGmPDBrxEJctkPZA/06uIX6vRhQ
         S0wRD1QVnhpF5lZY39FzlEmOF2LSNIXobpAaJdpPD2+K2BCxkBlGm59kekmqSE0fXymO
         SmycleJIGW37DD0RbWyvkC1pykptGq7elWCBRpCvaNbD9kKZno96BiCPM7M52G+mRuMn
         Ao/dVH+Vf/J3bSU8pEPnFeLLqqKxSIcicNcDSFvRuMqsPKjmS4n6qNM1FJ2kIZwB3Jaf
         wjvrUwkZf25yg1yrArrhlMfV3jvoUiobxgSsEzez0BakbFOdEF0o4WPp17uBJO0XKOC+
         NgIw==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
         :list-id:mailing-list:precedence:reply-to:to:in-reply-to:references
         :message-id:subject:date:mime-version:content-transfer-encoding:from
         :arc-authentication-results:arc-message-signature:dkim-signature
         :arc-authentication-results;
        bh=rEbm1QtwAuDAGv0eOnLP1LukDkRcxJwXTnoVIWddsAY=;
        b=R3fydFwhIiFSf5w14a8qvkyECX1d7ZZDlVmNcaR1I0R6zgjYu3zxB+hfDEmQBrsV3C
         0j1CpFn9pgwa3/5lBadhCxKfNWeZHYYIZk3RyVCc2o0IL0c4Lap89aMtSusUhVuathLs
         8uUXdRy/AB5Vt/NcYRRBF5eqxuwVmN8/Rm6cIVG37e1k+Z3Vg2E8jNQQUK3rmlqp/W2o
         hpeZidz3mJnbwERkNiyZkBPj6fSkRTHCbIwO56ynvj03n1vSCqnuvXZYLKucGcLCdG3Y
         3VHSiAdYL4OUqjeYyDgNn0DJ/Il9C79lujJpg9kARqjvOsVCPe7BJnJJV6ulP8TxKbZq
         rGTQ==
ARC-Authentication-Results: i=2; mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20161025 header.b=iA12qDYW;
       spf=pass (google.com: domain of jonathanbcoe@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=jonathanbcoe@gmail.com;
       dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=isocpp-org.20150623.gappssmtp.com; s=20150623;
        h=from:content-transfer-encoding:mime-version:date:subject:message-id
         :references:in-reply-to:to:x-original-sender
         :x-original-authentication-results:reply-to:precedence:mailing-list
         :list-id:list-post:list-help:list-archive:list-subscribe
         :list-unsubscribe;
        bh=rEbm1QtwAuDAGv0eOnLP1LukDkRcxJwXTnoVIWddsAY=;
        b=bSv7Y5XBlh49hDYImGnrvSbsN5U7hZoSJkjIuIPLVQxWv/HqBXpFR6rYRil8ve95ZZ
         S67R4cHR04gwHO4jcPu+FJOdCv6MyaQLQA3iqDhdF9cf4JhMOL+h7XdyEdNd3hcWONiI
         eTcAtZDTMp5lr0pGmNuy2qb7iT/Gh1eTEHqIMbjCq45JaHOpKGpCROU+XfXYtizbhn0j
         TMq4sh7lYM1ia2xPbF4b+EMRbTI2T1E6FB5qx3NwnEw9/mqIu2ox3YK9jDi6KxsLQW16
         ZS0BRFBJx25YzWvblPHITyY9Gc3wTs8v5O3m2G1HtBYmmbgpDs+krZ743sfjeOxOOVY9
         GOqg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:from:content-transfer-encoding:mime-version:date
         :subject:message-id:references:in-reply-to:to:x-original-sender
         :x-original-authentication-results:reply-to:precedence:mailing-list
         :list-id:x-spam-checked-in-group:list-post:list-help:list-archive
         :list-subscribe:list-unsubscribe;
        bh=rEbm1QtwAuDAGv0eOnLP1LukDkRcxJwXTnoVIWddsAY=;
        b=NSaH4HUl5x+cfOiP2KYE6Gvnxf/vBMJqjkEtk6Jxs5etFwikeXreDTLzv1dLmKFcHM
         hIEFCMDcFQ4eEpxvTqC9Kx9S/AnYpvhmqifbuT5TkrHLOsEPl8yXEQQdZzGUFv+cSp36
         MKUTOj+97SWcEPXRue/yxEqFk1PPJKAgy6e17NDY9IktijKptXYlbMM4Bh2WHiALvQ1g
         dwTU3+Bsim7igjgoEGlfL76NjH8C3ZaKBXzUMNYmPzVKjoOxL5dzb3Z4qeF1axLD0s7R
         0+2JTUNK/bqgee9K6KwIU0qtImxwFs/2Cgfr//KSLTrzKqJqhxyHli8vJ3o6NDAZC9ez
         0d/ 
X-Gm-Message-State: AElRT7ETawgAzh3xe9Sw4h/g8+ggkXwi0tQmEbEIk9F3agy2aNXKUSpP
	nyCik9laafHtz0fqmmTVftGBMg==
X-Google-Smtp-Source: AG47ELt++qK8VL1PNnQPt+qSPfyn2AcuT9dxdn7f39WM4F3/fNzBLMZwMOs9kNXVyBjX4Thk9hW+9g==
X-Received: by 10.129.165.12 with SMTP id c12mr1433096ywh.165.1521000294719;
        Tue, 13 Mar 2018 21:04:54 -0700 (PDT)
X-BeenThere: std-proposals@isocpp.org
Original-Received: by 10.13.210.2 with SMTP id u2ls27067ywd.43.gmail; Tue, 13 Mar 2018
 21:04:53 -0700 (PDT)
X-Received: by 10.129.106.67 with SMTP id f64mr2196270ywc.349.1521000293409;
        Tue, 13 Mar 2018 21:04:53 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1521000293; cv=none;
        d=google.com; s=arc-20160816;
        b=n63FJx05O2UbXD9NdLZT8y95k7zuURTbb4UOZQ2pfDc7go6nhV4F5s1yS8CJ5nSJ4D
         e9XlvhPT+MjcNhcCvEdf+kaWsWKi699SMpinI+4JlBsBijJqKG7xER0ld7EnYoWdaEAM
         l4tv1TtLaXFCfJkUkwJ01qI0kPogL6tO856k6+2mngxN1K8+a8YPYNA9Fp0iDz3sAxtb
         KDCSd6cxvVpIxRZC62NC1IfoHfvtenrMzEfPTE4Zhirmo59tT/bi8EbCVmFxRjxHsG2B
         UoE3ChsCkff8+3f6x+SsbRAJdDi2jhgFKqEFJ6XTe8Q4MdPUzcMmnj+kpZKfCKs6SWs4
         b6gw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=to:in-reply-to:references:message-id:subject:date:mime-version
         :content-transfer-encoding:from:dkim-signature
         :arc-authentication-results;
        bh=GX6so+V5lrdGDrc809uCGuqD7q0JYI8IUYlg2pi4680=;
        b=wO2FKqPum6J7ty+3qTDFQ8HdHJXbHIxhAJL/MvR7u1Yae52oAelxxjho6YeA/H+Csv
         7k7pX+bWD2fN1H3cp3cEUs5BaUmC+GcZhd3pt7HRiglRYqX4WnCfo0o4PW+3gEv0ZWky
         /bNIWlihGnVf4X24FCCh3LW6bf/Q4aU4B9veFsSOEEn8OTIiH9eZ3WYIKUrtX20hYEwe
         KV6ZsljLGB4kmgNVYvWfo0dfgbe8YeTv2GNeYwWtTBwk/tfdm4g7vHmSGwNQEMOPqPXw
         JBsRTrP//981D8FRWEbvnXptuPnr0eJNPPxd8CAd4O5rH3eMnbAONVhvIb2jZw7mm62w
         0H5w==
ARC-Authentication-Results: i=1; mx.google.com;
       dkim=pass header.i=@gmail.com header.s=20161025 header.b=iA12qDYW;
       spf=pass (google.com: domain of jonathanbcoe@gmail.com designates 209.85.220.41 as permitted sender) smtp.mailfrom=jonathanbcoe@gmail.com;
       dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
Original-Received: from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41])
        by mx.google.com with SMTPS id w6-v6sor764892ybk.40.2018.03.13.21.04.53
        for <std-proposals@isocpp.org>
        (Google Transport Security);
        Tue, 13 Mar 2018 21:04:53 -0700 (PDT)
Received-SPF: pass (google.com: domain of jonathanbcoe@gmail.com designates 209.85.220.41 as permitted sender) client-ip=209.85.220.41;
X-Received: by 2002:a25:6ad4:: with SMTP id f203-v6mr2221630ybc.504.1521000292621;
        Tue, 13 Mar 2018 21:04:52 -0700 (PDT)
Original-Received: from [172.20.67.73] ([12.16.51.253])
        by smtp.gmail.com with ESMTPSA id c186sm699555ywe.55.2018.03.13.21.04.50
        for <std-proposals@isocpp.org>
        (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
        Tue, 13 Mar 2018 21:04:51 -0700 (PDT)
In-Reply-To: <1a250082-a1d8-4f36-93a3-8540056ff279@isocpp.org>
X-Mailer: iPhone Mail (15D100)
X-Original-Sender: jonathanbcoe@gmail.com
X-Original-Authentication-Results: mx.google.com;       dkim=pass
 header.i=@gmail.com header.s=20161025 header.b=iA12qDYW;       spf=pass
 (google.com: domain of jonathanbcoe@gmail.com designates 209.85.220.41 as
 permitted sender) smtp.mailfrom=jonathanbcoe@gmail.com;       dmarc=pass
 (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
Precedence: list
Mailing-list: list std-proposals@isocpp.org; contact std-proposals+owners@isocpp.org
List-ID: <std-proposals.isocpp.org>
X-Spam-Checked-In-Group: std-proposals@isocpp.org
X-Google-Group-Id: 399137483710
List-Post: <https://groups.google.com/a/isocpp.org/group/std-proposals/post>, <mailto:std-proposals@isocpp.org>
List-Help: <https://support.google.com/a/isocpp.org/bin/topic.py?topic=25838>, <mailto:std-proposals+help@isocpp.org>
List-Archive: <https://groups.google.com/a/isocpp.org/group/std-proposals/>
List-Subscribe: <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:std-proposals+subscribe@isocpp.org>
List-Unsubscribe: <mailto:googlegroups-manage+399137483710+unsubscribe@googlegroups.com>,
 <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>
Xref: news.gmane.org gmane.comp.lang.c++.isocpp.proposals:37325
Archived-At: <http://permalink.gmane.org/gmane.comp.lang.c++.isocpp.proposals/37325>


--Apple-Mail-BDFF506A-E25C-49B4-A85D-5BEF185A0D5B
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

It might be interesting to add a series of clang tidy checks for unsafe cod=
e which could be selectively enabled. That might give implementation experi=
ence as to what can be checked for.

> On 13 Mar 2018, at 22:51, Nicol Bolas <jmckesson@gmail.com> wrote:
>=20
> Consider this:
>=20
> struct S
> {
>   shared_ptr<S> ptr;
>   int val;
> };
>=20
> auto ptr1 =3D make_shared<S>(nullptr, 4);
> auto ptr2 =3D make_shared<S>(ptr1, 6);
> auto ptr3 =3D make_shared<S>(ptr2, -3);
> ptr1.ptr =3D ptr3;
>=20
> Ignore the fact that `make_shared` doesn't work with aggregates. Can you =
provide a simple rule which would let the compiler decide that this code is=
 "unsafe"? What if each of those pointer creation and assignment functions =
were hidden behind several layers of functions, so that the compiler can't =
see everything?
>=20
> Just because all individual parts are "safe" doesn't mean that the whole =
is. And if you're going to define a subset of C++ that you consider "safe",=
 it had better actually be safe. The last thing C++ programmers need is hav=
ing language features that give them a false sense of security about how "s=
afe" their code is.
>=20
> Now consider this:
>=20
> int arr[3] =3D {5, 2, -13};
> arr[1] =3D 6;
>=20
> This is perfectly, 100% functional code. Given everything we can see here=
, there is zero chance of UB or other such. Would this be considered "safe"=
 code? And if not, why not?
>=20
> From your description of the actions you want to consider "unsafe", what =
you really mean is "low-level" or "not-modern". Neither is genuinely "safe"=
; it may be "safer", but that's a lot different from "safe".
>=20
> And that sort of thing is far better left up to each individual programme=
r and their static analysis tools of choice.
> --=20
> You received this message because you are subscribed to the Google Groups=
 "ISO C++ Standard - Future Proposals" group.
> To unsubscribe from this group and stop receiving emails from it, send an=
 email to std-proposals+unsubscribe@isocpp.org.
> To post to this group, send email to std-proposals@isocpp.org.
> To view this discussion on the web visit https://groups.google.com/a/isoc=
pp.org/d/msgid/std-proposals/1a250082-a1d8-4f36-93a3-8540056ff279%40isocpp.=
org.

--=20
You received this message because you are subscribed to the Google Groups "=
ISO C++ Standard - Future Proposals" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to std-proposals+unsubscribe@isocpp.org.
To post to this group, send email to std-proposals@isocpp.org.
To view this discussion on the web visit https://groups.google.com/a/isocpp=
..org/d/msgid/std-proposals/4BDA3D07-62AA-4B30-BCA0-875A446F6B23%40gmail.com=
..

--Apple-Mail-BDFF506A-E25C-49B4-A85D-5BEF185A0D5B
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=
=3Dutf-8"></head><body dir=3D"auto"><div></div><div>It might be interesting=
 to add a series of clang tidy checks for unsafe code which could be select=
ively enabled. That might give implementation experience as to what can be =
checked for.</div><div><br>On 13 Mar 2018, at 22:51, Nicol Bolas &lt;<a hre=
f=3D"mailto:jmckesson@gmail.com">jmckesson@gmail.com</a>&gt; wrote:<br><br>=
</div><blockquote type=3D"cite"><div><div dir=3D"ltr">Consider this:<br><br=
><div style=3D"background-color: rgb(250, 250, 250); border-color: rgb(187,=
 187, 187); border-style: solid; border-width: 1px; overflow-wrap: break-wo=
rd;" class=3D"prettyprint"><code class=3D"prettyprint"><div class=3D"subpre=
ttyprint"><span style=3D"color: #008;" class=3D"styled-by-prettify">struct<=
/span><span style=3D"color: #000;" class=3D"styled-by-prettify"> S<br></spa=
n><span style=3D"color: #660;" class=3D"styled-by-prettify">{</span><span s=
tyle=3D"color: #000;" class=3D"styled-by-prettify"><br>&nbsp; shared_ptr</s=
pan><span style=3D"color: #660;" class=3D"styled-by-prettify">&lt;</span><s=
pan style=3D"color: #000;" class=3D"styled-by-prettify">S</span><span style=
=3D"color: #660;" class=3D"styled-by-prettify">&gt;</span><span style=3D"co=
lor: #000;" class=3D"styled-by-prettify"> ptr</span><span style=3D"color: #=
660;" class=3D"styled-by-prettify">;</span><span style=3D"color: #000;" cla=
ss=3D"styled-by-prettify"><br>&nbsp; </span><span style=3D"color: #008;" cl=
ass=3D"styled-by-prettify">int</span><span style=3D"color: #000;" class=3D"=
styled-by-prettify"> val</span><span style=3D"color: #660;" class=3D"styled=
-by-prettify">;</span><span style=3D"color: #000;" class=3D"styled-by-prett=
ify"><br></span><span style=3D"color: #660;" class=3D"styled-by-prettify">}=
;</span><span style=3D"color: #000;" class=3D"styled-by-prettify"><br><br><=
/span><span style=3D"color: #008;" class=3D"styled-by-prettify">auto</span>=
<span style=3D"color: #000;" class=3D"styled-by-prettify"> ptr1 </span><spa=
n style=3D"color: #660;" class=3D"styled-by-prettify">=3D</span><span style=
=3D"color: #000;" class=3D"styled-by-prettify"> make_shared</span><span sty=
le=3D"color: #660;" class=3D"styled-by-prettify">&lt;</span><span style=3D"=
color: #000;" class=3D"styled-by-prettify">S</span><span style=3D"color: #6=
60;" class=3D"styled-by-prettify">&gt;(</span><span style=3D"color: #008;" =
class=3D"styled-by-prettify">nullptr</span><span style=3D"color: #660;" cla=
ss=3D"styled-by-prettify">,</span><span style=3D"color: #000;" class=3D"sty=
led-by-prettify"> </span><span style=3D"color: #066;" class=3D"styled-by-pr=
ettify">4</span><span style=3D"color: #660;" class=3D"styled-by-prettify">)=
;</span><span style=3D"color: #000;" class=3D"styled-by-prettify"><br></spa=
n><span style=3D"color: #008;" class=3D"styled-by-prettify">auto</span><spa=
n style=3D"color: #000;" class=3D"styled-by-prettify"> ptr2 </span><span st=
yle=3D"color: #660;" class=3D"styled-by-prettify">=3D</span><span style=3D"=
color: #000;" class=3D"styled-by-prettify"> make_shared</span><span style=
=3D"color: #660;" class=3D"styled-by-prettify">&lt;</span><span style=3D"co=
lor: #000;" class=3D"styled-by-prettify">S</span><span style=3D"color: #660=
;" class=3D"styled-by-prettify">&gt;(</span><span style=3D"color: #000;" cl=
ass=3D"styled-by-prettify">ptr1</span><span style=3D"color: #660;" class=3D=
"styled-by-prettify">,</span><span style=3D"color: #000;" class=3D"styled-b=
y-prettify"> </span><span style=3D"color: #066;" class=3D"styled-by-prettif=
y">6</span><span style=3D"color: #660;" class=3D"styled-by-prettify">);</sp=
an><span style=3D"color: #000;" class=3D"styled-by-prettify"><br></span><sp=
an style=3D"color: #008;" class=3D"styled-by-prettify">auto</span><span sty=
le=3D"color: #000;" class=3D"styled-by-prettify"> ptr3 </span><span style=
=3D"color: #660;" class=3D"styled-by-prettify">=3D</span><span style=3D"col=
or: #000;" class=3D"styled-by-prettify"> make_shared</span><span style=3D"c=
olor: #660;" class=3D"styled-by-prettify">&lt;</span><span style=3D"color: =
#000;" class=3D"styled-by-prettify">S</span><span style=3D"color: #660;" cl=
ass=3D"styled-by-prettify">&gt;(</span><span style=3D"color: #000;" class=
=3D"styled-by-prettify">ptr2</span><span style=3D"color: #660;" class=3D"st=
yled-by-prettify">,</span><span style=3D"color: #000;" class=3D"styled-by-p=
rettify"> </span><span style=3D"color: #660;" class=3D"styled-by-prettify">=
-</span><span style=3D"color: #066;" class=3D"styled-by-prettify">3</span><=
span style=3D"color: #660;" class=3D"styled-by-prettify">);</span><span sty=
le=3D"color: #000;" class=3D"styled-by-prettify"><br>ptr1</span><span style=
=3D"color: #660;" class=3D"styled-by-prettify">.</span><span style=3D"color=
: #000;" class=3D"styled-by-prettify">ptr </span><span style=3D"color: #660=
;" class=3D"styled-by-prettify">=3D</span><span style=3D"color: #000;" clas=
s=3D"styled-by-prettify"> ptr3</span><span style=3D"color: #660;" class=3D"=
styled-by-prettify">;</span><span style=3D"color: #000;" class=3D"styled-by=
-prettify"><br></span></div></code></div><br>Ignore the fact that `make_sha=
red` doesn't work with aggregates. Can you provide a simple rule which woul=
d let the compiler decide that this code is "unsafe"? What if each of those=
 pointer creation and assignment functions were hidden behind several layer=
s of functions, so that the compiler can't see everything?<br><br>Just beca=
use all individual parts are "safe" doesn't mean that the whole is. And if =
you're going to define a subset of C++ that you consider "safe", it had bet=
ter <i>actually be safe</i>. The last thing C++ programmers need is having =
language features that=20
give them a false sense of security about how "safe" their code is.<br><br>=
Now consider this:<br><br><div style=3D"background-color: rgb(250, 250, 250=
); border-color: rgb(187, 187, 187); border-style: solid; border-width: 1px=
; overflow-wrap: break-word;" class=3D"prettyprint"><code class=3D"prettypr=
int"><div class=3D"subprettyprint"><span style=3D"color: #008;" class=3D"st=
yled-by-prettify">int</span><span style=3D"color: #000;" class=3D"styled-by=
-prettify"> arr</span><span style=3D"color: #660;" class=3D"styled-by-prett=
ify">[</span><span style=3D"color: #066;" class=3D"styled-by-prettify">3</s=
pan><span style=3D"color: #660;" class=3D"styled-by-prettify">]</span><span=
 style=3D"color: #000;" class=3D"styled-by-prettify"> </span><span style=3D=
"color: #660;" class=3D"styled-by-prettify">=3D</span><span style=3D"color:=
 #000;" class=3D"styled-by-prettify"> </span><span style=3D"color: #660;" c=
lass=3D"styled-by-prettify">{</span><span style=3D"color: #066;" class=3D"s=
tyled-by-prettify">5</span><span style=3D"color: #660;" class=3D"styled-by-=
prettify">,</span><span style=3D"color: #000;" class=3D"styled-by-prettify"=
> </span><span style=3D"color: #066;" class=3D"styled-by-prettify">2</span>=
<span style=3D"color: #660;" class=3D"styled-by-prettify">,</span><span sty=
le=3D"color: #000;" class=3D"styled-by-prettify"> </span><span style=3D"col=
or: #660;" class=3D"styled-by-prettify">-</span><span style=3D"color: #066;=
" class=3D"styled-by-prettify">13</span><span style=3D"color: #660;" class=
=3D"styled-by-prettify">};</span><span style=3D"color: #000;" class=3D"styl=
ed-by-prettify"><br>arr</span><span style=3D"color: #660;" class=3D"styled-=
by-prettify">[</span><span style=3D"color: #066;" class=3D"styled-by-pretti=
fy">1</span><span style=3D"color: #660;" class=3D"styled-by-prettify">]</sp=
an><span style=3D"color: #000;" class=3D"styled-by-prettify"> </span><span =
style=3D"color: #660;" class=3D"styled-by-prettify">=3D</span><span style=
=3D"color: #000;" class=3D"styled-by-prettify"> </span><span style=3D"color=
: #066;" class=3D"styled-by-prettify">6</span><span style=3D"color: #660;" =
class=3D"styled-by-prettify">;</span><span style=3D"color: #000;" class=3D"=
styled-by-prettify"><br></span></div></code></div><br>This is perfectly, 10=
0% functional code. Given everything we can see here, there is zero chance =
of UB or other such. Would this be considered "safe" code? And if not, why =
not?<br><br>From your description of the actions you want to consider "unsa=
fe", what you really mean is "low-level" or "not-modern". Neither is genuin=
ely "safe"; it may be "safe<u><i><b>r</b></i></u>", but that's a lot differ=
ent from "safe".<br><br>And that sort of thing is far better left up to eac=
h individual programmer and their static analysis tools of choice.<br></div=
>

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups "=
ISO C++ Standard - Future Proposals" group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org">std-proposa=
ls+unsubscribe@isocpp.org</a>.<br>
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org">std-proposals@isocpp.org</a>.<br>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/1a250082-a1d8-4f36-93a3-8540056ff279%=
40isocpp.org?utm_medium=3Demail&amp;utm_source=3Dfooter">https://groups.goo=
gle.com/a/isocpp.org/d/msgid/std-proposals/1a250082-a1d8-4f36-93a3-8540056f=
f279%40isocpp.org</a>.<br>
</div></blockquote></body></html>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org">std-proposa=
ls+unsubscribe@isocpp.org</a>.<br />
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org">std-proposals@isocpp.org</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/4BDA3D07-62AA-4B30-BCA0-875A446F6B23%=
40gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/4BDA3D07-62AA-4B30-BCA0-875A446F6B23%=
40gmail.com</a>.<br />

--Apple-Mail-BDFF506A-E25C-49B4-A85D-5BEF185A0D5B--

.
