bk99.de entertain the web since 1997

Why C programs can be reliable despite an unsafe language

Summary

Laurence Tratt examines how conventions, tools and experienced developers limit the well-known safety risks of C. C does not check array bounds automatically. Undefined behaviour allows aggressive compiler optimisations.

Ideas

  • C leaves memory management and bounds largely to the programmer.
  • Few language rules make it easier to map code mentally onto machine operations.
  • Proven libraries encapsulate recurring dangerous operations.
  • Compiler warnings catch numerous bugs before execution.
  • Code reviews spread local experience across the whole project.
  • Tests and runtime analysis supplement the language's weak safety guarantees.

Insights

  • Reliability arises from language, tools, culture and field of use together.
  • Familiarity can reduce risks but also entrench blind spots.
  • A simple language core shifts complexity into programs and processes.
  • Closeness to the system remains valuable when resources and interfaces must be controlled exactly.

Facts

  • Many operating system kernels and runtimes are written mostly in C.
  • Static and dynamic analysis find different classes of bugs.

Recommendations

  • Enable strict compiler warnings and treat them as errors.
  • Additionally test memory accesses with sanitizers and analysis tools.
  • Encapsulate ownership, lifetime and error handling in clear interfaces.

References

Read the original article

Search the Web Archive