---
title: Subsetting and restricting C++ for memory safety
document: p4158r0
date: 2026-03-27
audience: EWG Evolution
reply-to:
  - "Oliver Hunt"
paper-type: proposal
---

##### • Incrementally adopted

##### • 98% adoption in less than a year

##### • 0% performance cost

##### • Additional backstop: extensive allocator hardening, including

#### WebKit vs lifetime safety

##### • Caveat: Focused on reference counting

##### • Most practical form of correct complex lifetime management

##### • Already widely used throughout webkit

##### • Do not try to reason about lifetimes

##### • Require local smart pointer (in WK: Ref, RefPtr, WeakPtr, …)

##### • Or semantically guaranteed ownership (above argument

#### WebKit vs lifetime safety

##### • Incrementally adopted

##### • 90% coverage in less than a year

##### • 0*% Performance cost

##### • Some code did need to be restructured

#### Implementation reality

##### • -Wunsafe-buffer-usage is already in the clang frontend

##### • C++ does not provide a mechanism to

##### • Restrict cast expressions

##### • Specify what objects need to be protected

##### • Specify how they are protected

##### • Enforcement of cast and ownership rules via libAnalyzer

##### • Local enforcement, but static analyzer is used because

### -fbounds-safety

#### • When std::span and similar aren’t an option (C, ABI constraints)

#### • Annotations to specify bounds rules for pointers

#### • No pointer indexing/arithmetic without bounds information

#### • Local pointer variables are wide pointers by default (e.g no

#### • Higher adoption cost than C++ options

#### • Adoption and deployment of -fbounds-safety has prevented

#### • Subsetting C++ is a viable path to *improving* memory safety in

#### • Subsetting supports incremental adoption

#### • Subsetting allows meaningful and effective improvements in

* WebKit’s subsetting trivially break entire classes of exploits,
have been shown to prevent the majority of historical attacks,
and adoption has found bugs that previously would not have
been detected.

### Links

#### • C++ Memory Safety in WebKit - Geoffrey Garen - C++Now 2025

#### • [https://www.youtube.com/watch?v=RLw13wLM5Ko](https://www.youtube.com/watch?v=RLw13wLM5Ko)

#### • [https://schedule.cppnow.org/wp-content/uploads/2025/03/](https://schedule.cppnow.org/wp-content/uploads/2025/03/CPPNow-2025-C-Memory-Safety-in-WebKit.pdf)

#### • 2025 EuroLLVM - Recipe for Eliminating Entire Classes of Memory Safety

#### • [https://www.youtube.com/watch?v=rYOCPBUM1Hs](https://www.youtube.com/watch?v=rYOCPBUM1Hs)

#### • 2023 EuroLLVM - Keynote: “-fbounds-safety”: Enforcing bounds safety

#### • [https://www.youtube.com/watch?v=RK9bfrsMdAM](https://www.youtube.com/watch?v=RK9bfrsMdAM)

### Yet more links

#### • Hardening Techniques from the trenches (hardened stdlib)

#### • https://www.youtube.com/watch?v=t7EJTO0-reg

#### • Clang bounds safety documentation: https://clang.llvm.org/docs/

#### • “Fortify your app” apple WWDR

#### • [Bounds safety: https://youtu.be/UZeSyodAszc?t=13458](https://youtu.be/UZeSyodAszc?t=13458)

* Should be split up at some point. You can also enjoy streaming
of a schedule for the entire period of the lunch breaks, etc.
