I'm starting to like Undefined Behaviour

Open in a window
Article lobste.rs

I'm starting to like Undefined Behaviour

....when I have warnings that will tell me about it.

So quite a few Rants have gone by about the behaviour of modern compilers around undefined behaviour.

The C standard says what happens when signed integers overflow is undefined.... so some compiler writers conclude that you have written the program so signed integer overflow cannot happen.

This is additional information that the optimizer may use.

Now I have been playing with gcc-7.2's -Wstrict-overflow=N

This warning is not enabled by default or by -Wall or -Wextra.

I hit a largish code base with this and this is the sort of thing it finds, in practice. ie. This isn't a theoretical debate about the merits and expectations of UB, this is a collection of practical examples in an industrial code base.

Examples have been extracted from body of code and simplified for readability reasons..

Message: assuming signed overflow does not occur when distributing negation across division

unsigned u = -i / 10;

Actually that is sort of cool. Especially on this tiny embedded target that doesn't have hardware implemented multiply and divide. So the compilers intent of translating that to

unsigned u = i / -10;

...is actually a fairly sane.

But wait? What is it whinging about?

Aha! The signed int gotcha.

-INTN_MIN is an overflow. It's undefined. So that simple obvious transformation is potentially behaviour changing.

Message: assuming signed overflow does not occur when simplifying division

if(remainder < 0)
{
     remainder = -(remainder);

     if(remainder*10 >  denominator*10/2)
    {

Again: If it ignores the possibility that remainder is INT_MIN to start with, it can assume remainder is positive in the next if.

But honestly, what do you as a programmer expect to happen in a case like that?

Message: assuming signed overflow does not occur when changing X +- C1 cmp C2 to X cmp C2 -+ C1

if( i +1 > 10)

ie. It's transforming that to if( i > 9)

Again, that only makes sense if i+1 doesn't overflow.

Message: assuming signed overflow does not occur when simplifying ‘/’ or ‘%’ to ‘>>’ or ...

(i+1) / 2

Message: assuming signed overflow does not occur when simplifying conditional

These tend to be harder to spot and understand, so I haven't a clear simple example of them. If anyone cares enough I might do the work to extract and prove an example.

So how have I been cleaning up the warnings?

In some cases doing the transformation by hand, as it actually is better and more reliable code.

In some cases say, oh bugger, that's really a bug, the api of the function said it handled an int16_t input parameter, but we don't actually handle the INT16_MIN case correctly at all. So let me fix that.

The notion of a UB by itself sucks, UB optimizations with static warnings is actually surprisingly useful.

Discussion 9 comments · 14 points · JohnCarter · 2018-07-29
Open on Lobsters
Loading the discussion…

Domain filters

Stories from these domains are hidden from every list. Subdomains match too: blocking substack.com also hides danluu.substack.com. The list is kept in this browser only.

Help

Keyboard

j / k
Move down and up the story list. The arrow keys scroll whatever has focus.
Enter
Open the marked story in a window.
]
Open the next story in the list in place of the one in front. Back returns to it.
p
Pin or unpin the marked story, which keeps it in Pinned.
n / N
Move to the next or previous top-level comment in the window in front.
c
Collapse or expand that comment.
f
Hide or show the story list.
Esc
Close a menu or this help.
Access key m
Go to the menu bar. Most browsers take it with Alt on Windows and Linux, and Safari with Control and Option.
?
Show this help.

Windows

Each story opens in a window holding its article above its discussion; drag the bar between them to share the room differently. A window can be moved by its title bar, resized from any edge, snapped to a half or a corner by dragging it there, maximised, or minimised to the bar at the foot of the page. Open several stories to compare them, and switch between them from that bar. A window's Next story link reads on down the list in the same window.

A link in a comment or an article to another Hacker News or Lobsters thread opens that thread in a window too. A link to a single HN comment opens the comment above its replies.

While a story's window is in front, the Story and Discussion menus in the menu bar hold its commands: pinning, Next story, sorting, collapsing every thread, jumping to the first new comment. Each window also remembers where you were in its article and discussion, so a reload, or Back to a story that Next took you past, finds your place again. Closing a window forgets it.

The whole arrangement lives in the address, so a bookmark or a shared link brings it back, and Back undoes the last change. Moving between Hacker News, Lobsters, their lists, Pinned and Find changes only the list, and leaves the windows open.

The list

The pin at the start of a row keeps the story in Pinned, and the cross at its end hides it. Pinned can be narrowed by words in the title, site or author, by source, and to the stories you haven't opened yet, and ordered by when you pinned them, by points or by comments; the filters are part of the address, so a filtered view can be bookmarked. Scroll past the end of the list to load more. Domain filters, in the View menu, hide every story from a site.

Applets

The Applets menu in the menu bar holds three tools, each a window of its own. Replies to me takes your Hacker News user name and lists the replies to your last thirty comments and stories, checking again every three minutes while it is open, and marking what is new since you last marked them read. Look up a user opens a profile on Hacker News or Lobsters, with their submissions and recent comments, as a commenter's name in any discussion does; the bar at the top of a profile looks up someone else in the same window, and Back returns to the one before. Who is hiring? filters the posts of HN's monthly hiring threads by the words you type.

They read only what the sites publish to everyone, so none of them asks for a login, and your user name stays in this browser.

Find

Find takes any link and lists every time it was submitted to Hacker News and Lobsters, so you can read each discussion of it.

About

YAVCHN never sees your Hacker News or Lobsters login. The discussion is fetched from each site's public API; to vote or reply, follow the link above the discussion, or the arrow beside a comment, to the source's own site. Pins, hidden stories, filters and layout are kept in this browser only.

Open source: github.com/paulmooreparks/yavchn. Built with PUDL.