6 ms·
Not a specific target of having to replace C++ for the sake of replacing C++. The way Rust code gets added includes: * A new feature needs an identifiable lib
by hsivonen 8y ago
Not a specific target of having to replace C++ for the sake of replacing C++.
The way Rust code gets added includes:
* A new feature needs an identifiable library, so the new library can be written in Rust to begin with. (Example: U2F token USB integration.)
* Old code needs a rewrite anyway, so the rewrite can be in Rust. (Example: Character encoding converters.)
* Servo has proven a component, so it makes sense to bring
it over. (Examples: Stylo and WebRender)
* History of vulnerabilities in code that was replaced. (Example: MP4 metadata parser)
- Already__Taken 8y agoIs anyone aware of secondary effects this has had? e.g. removed C++ code that has later found to have bugs, or newly re-written crates now more useful to the wider community than the same code locked up in C++.
- hsivonen 8y ago> e.g. removed C++ code that has later found to have bugs The article links to a longer article (https://hsivonen.fi/encoding_rs/ https://hsivonen.fi/encoding_rs/) about encoding_rs. The longer article mentions a bug that got fixed in Firefox ESR after the code had been replaced with encoding_rs in non-ESR Firefox. (I wrote the bug, too, though.) > or newly re-written crates now more useful to the wider community than the same code locked up in C++. encoding_rs is an example of a crate developed for Firefox but also developed as a crates.io crate from the start. ripgrep is probably the best-known Rust-only app that uses encoding_rs. Since Visual Studio Code bundles ripgrep, I believe Microsoft shipped encoding_rs before Mozilla did!
- vtesucks 8y agoIn terms of deploying rust directly to make money- Microsoft is probably the leader right now with actix used in azure iot
- polskibus 8y agoDid you mean this actix? https://github.com/actix/actix https://github.com/actix/actix Is it mature? Can you shed more light on how is it used in production?
- steveklabnik 8y agoThey're referring to https://news.ycombinator.com/item?id=17433142 https://news.ycombinator.com/item?id=17433142 I don't believe that it uses Actix, though. Actix was created by and is maintained by a Microsoft employee.
- pjmlp 8y agoHe has mentioned on an HN comment that they are using it internally, but isn't allowed to disclose how. https://news.ycombinator.com/item?id=17191454 https://news.ycombinator.com/item?id=17191454
- fafhrd91 8y agoWe use actix at azure iot
- steveklabnik 8y agoAh, something that’s not in that repo? That’s awesome!
- nicoburns 8y agoDropbox are also using Rust in both their storage layer, and their desktop client.
- vtesucks 8y agoYou do realize that dropbox has very small profits, right? They made all of 50m in q2
- earenndil 8y ago> removed C++ code that has later found to have bugs I doubt this would ever be discovered; who would analyze code that was formerly a part of Firefox?
- hsivonen 8y ago> who would analyze code that was formerly a part of Firefox? People looking for bugs in Firefox ESR.
- ryacko 8y agoPeople looking for bugs in Waterfox or Pale Moon.
- liopleurodon 8y agoI know it's "extended support release" but I keep reading this as "Firefox Eric S. Raymond"
- nickpsecurity 8y agoThere's actually a lot of people who want actual, experimental data to back a language's claims about safety. A subset of them use C and C++. I occasionally argue with them about safety benefits of other languages. They demand more proof than the design, esp field data. I do keep stuff like this as experimental evidence that will add up for such empiricists over time. Although, I prefer controlled experiments where you teach amateurs C, modern C++, and Rust over a specific time followed by testing (esp fuzzing) of their code to test the safety claims. Run it in a dozen different places to see if results are consistent. There's also folks that just study these things to identify patterns in problems created, prevented, or detected (at what effectiveness) in various languages and techniques in software development. Along similar vein, each bug report also provides (in theory) a test case for automated tools that detect bugs. It's very important to have a huge, diverse pile of code to test those tools with. That's because each one's algorithms might have blind spots missing bugs. The more code and bugs we have, the better we can assess those algorithms' accuracy. And then build better algorithms. :)
- shmerl 8y agoWhy is Mozilla trying to replace components of Firefox with Servo, rather than trying to complete Servo as a full and compliant engine? I.e. it looks like browser.html is not very usable, since Servo itself is quite behind in actual features support compared to Firefox.
- kiriakasis 8y agoI would say that there are only downsides in going that way. If you take on a full rewrite you lose a lot: you can't show that you are incrementally better, you cannot show that it will be a good long term investment, you must rewrite even well maintained core parts that works fine, you don't get to improve the original engine with the good parts and essentially you get nothing in return. For a much better answer than mine: https://www.joelonsoftware.com/2000/04/06/things-you-should-never-do-part-i/ https://www.joelonsoftware.com/2000/04/06/things-you-should-...