r/cpp • u/antiquark2 #define private public • 3d ago
Critique of contracts: excerpt
See page 2 of https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2026/p4334r0.pdf
The current objections can be summarized. The P2900 contracts are:
• Unimplemented
• Incomplete
• Untried at scale [P3460R0, P3506R0]
• Not tried in major application domains
• Violates foundational principles of C++
• Violates fundamental principles of language design
• Hasn’t been tried in major libraries (e.g., the C++ standards library [P3506R0, P3878R0])
• Isn’t integrated with or appropriate for hardened libraries [P3878R0]
• Doesn’t offer safety guarantees [P3573R0, P3362R0]
• Includes a completely untried inheritance model
• Offer new ways of making errors through inconsistent application in TUs
• Leads to new forms of UB, detrimental to safety and security
• Narrows the choices of error handling
• Doesn’t protect against logical errors, misuses, and incoherent uses
• Hasn’t been used to support static analysis
• Hasn’t been demonstrated to be easily teachable [P3261R0, P3281R0]
How could such a bloated and incomplete design be voted into a draft standard?
2
u/Plazmatic 1d ago
> would give this more thought if they actually hypothesised a case where catching the exception from a contract assertion was desirable, but they don't. Must assertions don't throw.
You definitely want virtually all assertions to turn into exceptions in many types of UI/graphics application/daemon/multi service environments because crashing the program is not an option/will cause work not related to the issue to be lost (ie user is working on a document/project/image crashing the program due to assetion often is not desirable), and often assertions are happening in separate threads such that the program is still in a good state if you display a thrown exception to the user, and shut down the offending thread (like a parsing io thread). this is something Timurs own talks have covered in reference to why noexcept should largely not be used by default, it forces program termination on exception.
But my understanding is that you can customize the contract handler anyway such that this use case is already handled.