3 ms·
"... In addition, we draw from our experience to propose a new language extension to Rust that would enable it to provide better memory safety tools for event-d
by alanning 9y ago
"... In addition, we draw from our experience to propose a new language extension to Rust that would enable it to provide better memory safety tools for event-driven platforms."
I believe this part also warrants mention. Not only did they share their findings as experts in the field, they also did the extra work of detailing improvements.
My take away is that its painful to make embedded systems in Rust now but its promising enough to make it worth the effort for the embedded community to help guide Rust's development.
- BaronSamedi 9y agoNot my field but I don't understand the rationale behind choosing Rust. Given the performance and security concerns wouldn't Ada be the natural choice here? It may not be the most fashionable language but it seems I read about security problems with embedded and IoT devices on a daily basis. Why not choose a language designed for this problem?
- vertex-four 9y agoAda isn't actually particularly safe in any reasonable sense - or rather, it provides enough escape hatches with little obvious marking that it's costly (in terms of time spent in code review) to ensure safety. Safety of existing Ada programs is primarily a result of the engineering practices that went into them, more than the language itself.
- nickpsecurity 9y agoNonsense. The designer looked at almost every spot where coding mistakes were leading to crashes or corruption. Then, made those safe-by-default wherever possible. They're described in modern form in the book below by Barnes. The effect was confirmed when defects dropped to around half what Mitre et al had been observing on C projects. There was only one case study I saw where Ada made no difference whose control group was C++. An anomaly that might have been same system reimplemented by same people, easily-correct system, or just both super-talented. So, it is a safe language with only exception being temporal safety w/out a GC. Rust delivers on that. http://www.adacore.com/uploads_gems/Ada_Safe_and_Secure_Booklet.pdf http://www.adacore.com/uploads_gems/Ada_Safe_and_Secure_Book... Also, SPARK Ada can straight-up prove common errors don't exist in that code with an automated prover. Most engineers would spend quite a bit of time doing that with pencil-and-paper examination or human-driven provers: https://en.wikipedia.org/wiki/SPARK_(programming_language) https://en.wikipedia.org/wiki/SPARK_(programming_language)
- nickpsecurity 9y agoIt would be. Especially with mature tooling available from AdaCore. Seem my reply to vertex-four for links containing proof. Here's some examples in industry & CompSci just for kicks: http://www.adacore.com/customers http://www.adacore.com/customers Note that the authors are just doing research on seeing how well Rust handles the problem domain. There's nothing wrong with them avoiding Ada to explore another tool or problem area. They should consider each carefully if they were trying to pick best tool for real work.
- naasking 9y ago> Given the performance and security concerns wouldn't Ada be the natural choice here? Ada would be a good choice, but it's way more awkward to program in. It definitely has some nice features of its own that Rust should steal asap though.
- steveklabnik 9y ago> My take away is that its painful to make embedded systems in Rust now Please note that this paper is old and some of it is due to the author's lack of experience with Rust at the time. It has gotten way way easier since then. Fun story: Niko, a Rust core team member, was keynoting the conference where this paper was presented, and ended up sitting down with the authors and working out some stuff. So their hard work was upstreamed even faster than usual! (It ended up being more of a redesign than a language extension, though.) > the embedded commmunity to help guide Rust's development. Yes please!
- alanning 9y agoWow, I totally missed that it was from 2015. Thank you for the update and for your work! I find stories like how Niko met the authors fascinating, so thank you for that as well.
- deleted 9y ago[deleted]
- steveklabnik 9y ago:D Amit, one of the authors, has left a comment on Reddit with some more context about how these problems were solved: https://www.reddit.com/r/rust/comments/655816/ownership_is_theft_experiences_building_an/dg7p2uf/ https://www.reddit.com/r/rust/comments/655816/ownership_is_t...