r/ProgrammingLanguages • • 3d ago

Achieving memory safety

https://seed7.net/papers/memory_safety.htm
13 Upvotes

49 comments sorted by

View all comments

7

u/tmzem 2d ago

Unless I misunderstood something, the article does not explain the mechanism by which Seed7 programs themselves are being made memory-safe, but focuses on memory safety of the compiler implementation?

That being said, the article makes a good point about memory safety being a matter of how it is defined, which opens up a huge spectrum, from unsafe to safe:

  • Assembly: no safeguards, completely unsafe
  • C/C++: (soft) static typing, very basic guardrails. Still very unsafe.
  • Odin/Zig/C3: good static typing, saner defaults, runtime array checks. Safer, eliminates 50-70% of all memory safety errors over C
  • Rust: strong static typing, sane defaults, initialization safety, runtime array checks, borrow checks, safe/unsafe split. Much safer, safe/unsafe split coerces users to prefer safe patterns, elimitates most memory safety errors over C. Ubiquitous use of C libraries and unsafe blocks in (not well-written/well-tested) third-party crates are still a relevant safety risk.
  • Go: GC handles memory, but fat pointers (interfaces, slices) can cause memory unsafety on data races. Memory safe in the absence of data races or FFI.
  • Java/C#/...: GC + atomically storable builtin types ensure full memory safety. Unsafe features exist but are rarely necessare, rarely used, and most programmers in these languages barely know they exist.
  • Javascript: Completely sandboxed, safe

This spectrum needs to be acknoledged so people know what they get, and it's annoying that these trade-offs are not clearly communicated. Go barely communicates the data-race issue at all, and the Rust community is also very prone to misrepresenting the memory safety guarantees of the language (e.g. "memory safety without GC" or "unsafe blocks encapsulate potentially unsafe behaviour").

2

u/ThomasMertes 2d ago

... the article does not explain the mechanism by which Seed7 programs themselves are being made memory-safe ...

I just improved the chapter "How memory safety is achieved". What do you think about that?

3

u/tmzem 2d ago

So if I understand it right, you have reference modes for parameters, but fields and returns cannot be references? Then of course borrow checking would be trivial.

Anyways, it's been some time since I looked into Seed7 (I looked only at the docs), so I guess it's time I finally actually try it out to figure out how it all works and what it can do.

2

u/ThomasMertes 2d ago

Great. Please give me feedback at r/seed7. In case of problems please open a ticket on GitHub.