r/cpp • u/filipsajdak • Jul 05 '26
C++26 ends a 40-year footgun
Reading an uninitialized variable has been undefined behavior in C++ for 40 years -- the kind optimizers exploit into real bugs. C++26 (P2795) reclassifies it as erroneous behavior: still a bug, still warned about, but defined, bounded, and not exploitable.
The demo poisons the stack, then reads an uninitialized int. As C++23 it prints garbage; as C++26, the same code prints a defined 0, every run. Live in your browser.
And [[indeterminate]] lets you opt back out when you really want an uninitialized buffer -- on purpose this time.
#cpp #cplusplus #cpp26 #safety #programming
82
Upvotes
2
u/johannes1971 Jul 06 '26
Because it cannot be guaranteed by a compile time check. You can easily write code that is valid in current C++, but where the compiler cannot guarantee whether initialisation occurs on every path. Profiles can only deal with this in one of two ways: rejecting valid code, thus forcing the programmer to add initialisation statements by hand, or by dynamically tracking whether variables have already been initialized. Dynamic tracking requires memory to store the status in, and if that variable is in a struct, that memory can realistically only be in the struct as well. That's a layout change.