4 ms·
> On the other hand, it probably is less effort to rewrite PolarSSL in Rust than doing that proof. It's probably even less effort to convert to SaferCPlusPlus[
by duneroadrunner 9y ago
> On the other hand, it probably is less effort to rewrite PolarSSL in Rust than doing that proof.
It's probably even less effort to convert to SaferCPlusPlus[1] (essentially a memory-safe subset of C++). There's even an tool[2] (under construction, but functional) to do a lot of the conversion for you.
[1] shameless plug: https://github.com/duneroadrunner/SaferCPlusPlus https://github.com/duneroadrunner/SaferCPlusPlus
[2] https://github.com/duneroadrunner/SaferCPlusPlus-AutoTranslation https://github.com/duneroadrunner/SaferCPlusPlus-AutoTransla...
- pcwalton 9y agoSaferCPlusPlus is not memory safe, according to your documentation. For one thing, the "this" pointer problem is pretty much unsolvable in C++.
- duneroadrunner 9y ago> For one thing, the "this" pointer problem is pretty much unsolvable in C++. Well, you could just avoid/prohibit the explicit and implicit use of the "this" pointer. I.e. prohibit non-static member functions[1], right? [1] https://github.com/duneroadrunner/SaferCPlusPlus#practical-limitations https://github.com/duneroadrunner/SaferCPlusPlus#practical-l...
- pcwalton 9y agoDoes anyone actually want to program in "C++ with instance methods banned"? Why not just use a language designed for memory safety (which is most of them)? It's a whole lot easier, plus you get an ecosystem of actually safe code.
- duneroadrunner 9y ago> Does anyone actually want to program in "C++ with instance methods banned"? Well, passing a "safe this" pointer as the first parameter to a (static) member function isn't that hard to get used to, is it? But I don't disagree with your gist. If memory-safety is your only concern and you're not trying to salvage an existing codebase, then Rust might be a better choice. But if you're trying to add memory safety to, say, an existing C implementation of SSL, the SaferCPlusPlus route would probably be less effort. Even when non-static member functions are banned. > (which is most of them) Personally, I consider RAII (deterministic destructors) an essential feature for safe, efficient programming at scale. That leaves only two choices, C++ and Rust, right? And if there's a memory-safe C++ option available, there are some arguments for choosing it over Rust.