5 ms·
And it only takes one programmer mistake to bring the whole house of cards down. Isn't this also true of Rust, with its unsafe keyword? None of these language
by panic 10y ago
And it only takes one programmer mistake to bring the whole house of cards down.
Isn't this also true of Rust, with its unsafe keyword? None of these languages are completely safe against programmer mistakes.
- afarrell 10y agoIs the use of the unsafe keyword a default? I don't know Rust, but from a user interface perspective, it sounds like it has an affordance of "Hey! Pay particular attention to this bit because it is risky!"
- steveklabnik 10y agoIt is very much not the default.
- Manishearth 10y agoIt's more of a "Hey, trust me here when I say that the enclosed code is actually safe" hint to the compiler. It's used sparingly. Not as sparingly as I'd like, but sparingly enough.
- afarrell 10y agoSure, but code is not just instructions to a compiler, but is also a user interface.
- Manishearth 10y agoOh, yes, as a UI it is "be extremely wary of this code" Often folks write long comments around unsafe code explaining why it is safe. Not always, sadly.
- staticassertion 10y agoTotally. But in the case of rust your vulnerabilities are grep'able. For all of the code you have in a project you only have to search for the unsafe keyword when you want to audit it. I think that makes a very significant difference.
- sidlls 10y agoYes. It's trivial in Rust to write unsafe code. It's less trivial to mask the unsafe code and the (unproven, in my opinion) argument is that the explicit "unsafe" keyword makes it prohibitively difficult.
- jdmichal 10y agoThat's less of a mistake, and more of turning off the footgun's safety. Yes, it still only takes one programmer. But they have to purposefully enable such actions, as opposed to neglect to perform actions through the "proper" abstractions.
- jjnoakes 10y agoYou are equating the unsafe keyword in Rust with entire C codebase. Yes, carelessness in either could amount to trouble. No, they are not close to the same amount of risk because the relative amount of code in each is orders of magnitude different, and unsafe blocks can be heavily reviewed.
- dbaupp 10y agoThis is true of every language: e.g. Python has ctypes, Haskell has Foreign, Java has JNI, etc. It's a matter of defaults/conventions rather than something being literally impossible to screw up.
- mrsteveman1 10y ago> Isn't this also true of Rust, with its unsafe keyword? > None of these languages are completely safe No, but the first time I encountered an unexplained segfault in Rust was the first time I've ever found & fixed the cause of a weird segfault message in just a few minutes, because the mistake was in the 12 lines I had written inside a clearly marked unsafe block rather than the other ~3000. Without something like unsafe blocks, finding known bugs and auditing code for other "weird" memory issues means looking much wider (and often, screaming "what the hell are you talking about?!" at the screen on a routine basis).
- EugeneOZ 10y agoEven without `unsafe` programmer can make mistakes in Rust. Logical mistakes are unstoppable.