4 ms·
I suspect it's this bug: https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/ https://blog.cloudflare.com/incident-report
by lobster_johnson 8y ago
I suspect it's this bug: https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/ https://blog.cloudflare.com/incident-report-on-memory-leak-c...
HN: https://news.ycombinator.com/item?id=13718752 https://news.ycombinator.com/item?id=13718752
- sligor 8y agoThe blog post says that this bug is inside code written in C and Ragel (a parser generator), Rust seems not to be involved in this bug
- tptacek 8y agoThat's the point; Rust operates in the places they needed C before, and C is unsafe.
- pjmlp 8y agoThere is a huge difference between being able to track down unsafe statements and a language where 100% of the source code is unsafe, given the 200+ cases of UB, implicit conversions and lack of data integrity validations. Sure logic errors can always happen, but moving away from C would already get a portion of memory corruption issues out of the table. Unless you are asserting that Mesa/Cedar, NEWP, Oberon, Oberon-07, Active Oberon, Modula-2, Modula-2+, Modula-3, Object Pascal, Concurrent Pascal, Component Pascal, Basic, D, Ada, SPARK, Sing#, Midori, BLISS, PL/I, PL/S, PL/8, PL/M, Swift, HPC# are all unsafe as C.
- masklinn 8y agoThe slide is a bit unclear, the whole deck is terse and clearly not intended to be consumed independently from the presentation, so "Safe (we had a bug once…)" should be interpreted as "safe (we kind-of had a not-very-small bug in our C code once)" not "Safe (we've only had one Rust bug)"
- steven_pack 8y agoIndeed. It was very much just prepared as some talking points for the folks in the room. Makes more sense with the video. Note to self: Stuff about Rust always makes it to HN. :)
- buro9 8y agoRust was not the cause of the bug. It was a C bug and was exposed during the process of deleting the code in question (adding the new code to replace it actually exposed the old bug). It has given us a very keen awareness of just how bad such bugs can be, and hence "we had a bug once" might be considered the soft way of saying "no more effing C". Of course we'll still have C and C++ as we're heavily invested, but if there are safer alternatives that we can use those will definitely be considered first.
- thurston 8y agoWhat rarely gets discussed in this case was that old, working code was modified in a critical way in order to accommodate new code when that didn't need to be done at all. It was actually a failure in the software development process.
- hellofunk 8y agoI can't tell if the OP is suggesting the bug they had was due to Rust, or if they adopted Rust for a safe language they once had a bug?
- lobster_johnson 8y agoThe latter. I think it's a sheepish admission that the bug (caused by unsafe C code) is a reason to prefer Rust's safety, which should help them prevent another one like it.
- StavrosK 8y agoIt is, the person presenting says so in the video.
- serioussecurity 8y agoThe cloudflare bug was a memory safety issue in C code, which is basically the whole point of trust
- MikkoFinell 8y agoHah, could you imagine, someone saying they found a bug in a piece of Rust code? I haven't read the HN terms of service, but I'm guessing they you'd get banned pretty quick for something as egregious as that.