5 ms·
How many developers are actually versed enough in C/C++ to deal with it? Is re-writing everything in Rust really the answer?
by Tehchops 8y ago
How many developers are actually versed enough in C/C++ to deal with it?
Is re-writing everything in Rust really the answer?
- matis140 8y agoI wonder about analysis tools for c/c++. I know those tools have come a long way. Is the problem the decades of time where those tools were proprietary or expensive or free/open and poor in quality where most of this code was written? Or do these tools actually fall short of their claims of memory safety and the only solution is a rewrite? Or I guess it can be like opening an old solution in visual studio seeing it has 100+ warnings or doesn't even build anymore with current tooling so changes go on the back burner because that small change turns into a few days of work because nobody has built it in the last 10 year's...
- bluGill 8y agoThe tools have come a long ways. However they are not very powerful. C++ the language has come much father in the ability to write memory safe code - but this doesn't do much for the old legacy code out there.
- steveklabnik 8y agoIf the tools were able to get you the equivalent of Rust's safety, we wouldn't have bothered making Rust. These tools are great, and I welcome anything that makes software more safe. But you can't truly retrofit safety onto C or C++. You can improve it, but it's an improvement, not a solution.
- mamcx 8y agoThe alternative is live forever in a worse-than-cobol self-inflicted hell.
- bluGill 8y agoC and C++ are NOT the same language. If you are writing modern C++ you don't have nearly the memory problems. C++ lets you use/create the C backdoors, but that is something that should only be done when you have to - when you have to are times you either cannot use the alternative language, or you do, but those languages suddenly become just as unsafe. Yes there is a lot of old C++ out there. But you can do better in C++ without losing the old features that have been debugged over the years, and without all the money of re-writing things that might or might not have bugs.
- dvfjsdhgfv 8y ago> C++ lets you use/create the C backdoors, but that is something that should only be done when you have to The point is, some other languages won't let you do it anyway, and given the importance of security these days, we should reconsider our priorities.
- aivarsk 8y agoOther languages have other backdoors like Java's sun.misc.Unsafe which is used in many projects to get better performance.
- bluGill 8y agoEither the other languages allow it (though they might make it inconvenient), or they can't do some of the things C++ can do.
- stjohnswarts 8y agoDepends on where you work. Some of us aren't in academia. I simply refactor in modern c++ wherever I can and use "nothing but" whenever we start a new project. You get awesome ideas, and then reality kicks in.
- fithisux 8y agoRust + ATS please. But the problem always is interoperability. People do the C/C++ S&M thing because of interoperability. You cannot call Ruby from Python or vice versa, but you can call C/C++ from both Ruby and Python. This is one of the main reasons why people do not change. We need a better portability layer, Dlang/betterC can be a solution here, but we have to be brave and forward looking.
- jcranmer 8y agoOne thing I'd argue vehemently for is to stop thinking about ABI as purely in terms of C, and start finding ways to describe ABI interoperability between different languages that allow more advanced features (such as Unicode strings).
- stjohnswarts 8y agomodern c++ provides fixes for everything he mentions in the article without completely swapping out all the experience gained from decades of existence. People just aren't using it enough. It's all there.