4 ms·
It's because Rust is the first production language that is safe and strictly better than C (and that is likely to be strictly better than C++ as well once it ga
by devit 11y ago
It's because Rust is the first production language that is safe and strictly better than C (and that is likely to be strictly better than C++ as well once it gains some missing features).
For decades, it has been known that C and C++ are bad languages due to their unsafety, and the use of C/C++ is probably the top cause of bugs and security holes in software; however, switching required giving up performance or features.
Now that finally a solution to this problem has become available after so much time, it's natural that people are enthusiastic about it.
- nickpsecurity 11y agoThat was Ada and a bunch of Wirth languages which both got regular updates going back decades. Most developers ignored all of them. Rust is a new one going mainstream. As usual, mainstream acts like everything else ever happened. An exception is other one, Go, which intentionally copies Wirth's languages in design. Usually stuff is ignored, though.
- kibwen 11y ago> As usual, mainstream acts like everything else ever > happened. Not Rust. The reference has a long list of languages which have been influential (https://doc.rust-lang.org/reference.html#appendix:-influences https://doc.rust-lang.org/reference.html#appendix:-influence...) and the official book has a list of research papers which have helped to guide the design of the language (http://doc.rust-lang.org/book/academic-research.html http://doc.rust-lang.org/book/academic-research.html).
- nickpsecurity 11y agoI meant the commenter as the example of mainstream audience that acts like other things didn't do it first. Wasn't sure what Rust's official position was. Thanks for link as I'll keep it in mind for future discussions. :) Note: Strange that they draw no inspiration from Ada despite it countering many issues by design. I figure at least its tactics if not syntax would be a nice start on a new language. Least they borrowed from and built on a lot of good ones, though.
- kibwen 11y agoAda actually takes a different approach to memory safety than Rust. Ada requires garbage collection if you want to dynamically allocate, and only statically ensures safety without a GC if you opt into the subset where only static allocation is allowed. Ada also has at least one correctness-aiding feature that Rust lacks, which is the ability to define integral types with an explicitly bounded range.
- nickpsecurity 11y agoThe consistent point, as I mentioned, is that Rust isn't the first, safer, systems language. There's quite a few before it. It does take a different approach and I like Rust's innovations in this space. I'm keeping a distance for now to let it and the associated coding styles evolve. Just reading the experience reports, articles, HN comments, etc for now. Also watching Julia as it has a host of good features with potential to take on Python and R at same time. Especially macros and painless C calls. Note: Btw, good call on integral types. That's quite beneficial. Also, existential types would prevent all sorts of issues that happen when two things are same size but should be treated differently. Like a mi-to-km mismatched that was a downer for one program in particular. ;)
- kibwen 11y agoI agree, Rust isn't the first language to exist in the "safe systems language space". But it's a recurring meme that Rust is somehow related to Ada, when in reality they are divergent lineages. :) > Also, existential types would prevent all > sorts of issues that happen when two things > are same size but should be treated differently. I don't know what existential types are, but we use phantom types for that: https://blog.mozilla.org/research/2014/06/23/static-checking-of-units-in-servo/ https://blog.mozilla.org/research/2014/06/23/static-checking...
- nickpsecurity 11y agoOh, I didn't know about that meme. Explains your reaction to my post. Oh no, mine is more meme that people ignore what exists and miss potential benefits (or just accuracy) for various reasons. So, a consideration of safe, systems programming should include most mature tools (eg Ada) plus any newcomers reaching maturity (eg Rust). I wasn't implying Rust had any connection to Ada: more surprised Ada had no influence on it than anything. I'll be sure to look out for that other meme, too, to call them on their BS. ;) "I don't know what existential types are" Unfortunately, I couldn't find a non-dense explanation of it that had relevant detail. Good news is the Ada book I've been referencing has a great explanation with examples. See Ch 2 "Safe Typing" for the answer in the first, two pages. They call them "Distinct Types" in there (shrugs). Included link to whole book in case you see safety tactics worth copying. http://www.adacore.com/knowledge/technical-papers/safe-secure/ http://www.adacore.com/knowledge/technical-papers/safe-secur... So, they make sure the types and implementation are separate so unique types ("existential types") can catch interface issues that can be subtle and nasty. Casts work around them where necessary while making the risk more obvious. Aim to try to keep overhead down compared to heavy OOP + regular types. Seeing it made me wonder, "Why don't the rest have this!?" "but we use phantom types for that" Thanks for the link! Adding it to my list of things to read and review. :)
- devit 11y agoAda doesn't support safe GC-less memory allocation, which means it's either unsafe, far worse feature-wise than C or requires a GC which also makes it not strictly better than C. As a consequence, it seems that if you use Ada's GC, you might as well use Java instead, and if you don't you might as well use C++ instead, which along with its unattractively verbose and not C-like syntax is probably why Ada is not very popular despite having been around for 30 years.
- nickpsecurity 11y agoAda does most allocation, including local dynamic, on the stack. From there, for the heap, you get to choose whether to manage individual pieces of memory, work from whole pools, or do GC. With these, you get help from the type system in catching or preventing errors. Past that, there's the usual risks. Requires a lot less memory management and runtime overhead than Java while preventing way more problems than C. And, as I often say, the empirical studies all showed C doing far worse in terms of defects introduced. Ada benefiting safety & productivity over C is a proven fact rather than an opinion. So, questions are: (a) should we use it for this project? (b) should we build on a proven solution and make it better?, and especially (c) should we borrow anything in this that made it effective when designing a new language? I especially push for (c) to be applied any time new tech is built. Ada is my reference for safe, systems programming because it did what it promised and is the oldest one still updated/used. Also turned out almost as future-proof as COBOL with a lot safer, easier maintenance. Such longevity, along with safety, benefits enterprises writing mission-critical software. Details on various safety mechanisms: http://www.adacore.com/knowledge/technical-papers/safe-secure/ http://www.adacore.com/knowledge/technical-papers/safe-secur... Far as replacements, Rust is looking promising. Needs to mature a bit and better tools for various situations. A great design, though, with a lot of potential. Not sure how it would fare for embedded, though: Ada was used in microcontrollers and stuff.
- steveklabnik 11y agoRust is actively used on embedded projects. The sticking point is mostly if the architecture is one that LLVM supports, which means that are some platforms we can't support.