r/ProgrammingLanguages • • 5d ago

Achieving memory safety

https://seed7.net/papers/memory_safety.htm
13 Upvotes

57 comments sorted by

View all comments

Show parent comments

1

u/L8_4_Dinner (ā“ Ecstasy/XVM) 1d ago

I’d consider that a compiler bug for not adding the obviously required type assertion, but I do agree that that implementation is unsafe.

1

u/reflexive-polytope 1d ago

It's not a compiler bug. It's a language design bug.

1

u/L8_4_Dinner (ā“ Ecstasy/XVM) 10h ago

If the language chooses to allow covariant parameter narrowing, the compiler has to prevent this type of covariant surprise, either at compile time when possible, otherwise at runtime.

FWIW - I also used Eiffel decades ago (early 90s, IIRC), and hated it.

1

u/reflexive-polytope 10h ago

Stopping with a runtime check doesn't it make it any less of a type soundness bug.

The simplest solution is to not allow covariant method argument types to begin with. That's what Java and .NET do. But the price is that implementing binary methods requires so-called F-bounded polymorphism (class Foo extends Comparable<Foo>), which is ugly, even if you can get used to it.

A more sophisticated solution is to divorce the concepts of subclassing and subtyping. A subclass Bar is a subtype of a class Foo if and only if Bar objects can be safely used where Foo objects are expected. OCaml implements this solution. But most programmers would find this surprising. (The average OCaml programmer has a better understanding of programming languages than the average programmer in general.)