25 ms·
Why Ada Is the Language You Want to Be Programming Your Systems With
- 6thaccount2 7y agoI really like the language, but the only compiler I'd trust is the adacore one and I imagine it is pretty pricey for commercial work
- pronoiac 7y agoWhy not FSF’s GNAT? It’s been a while since I used it, but I remember preferring its error messages to some commercial offering we had around.
- mjw1007 7y agoAdaCore's compiler is GNAT. They sell a pro version with bells and whistles but AFAIK the actual compiler is the same.
- 6thaccount2 7y agoYou can't use a lot of the libraries and still get the runtime exception to where it doesn't have to be released as GPL I think.
- johnisgood 7y agoGNAT Community version does not offer support for old versions of Ada, GNAT Pro does, but at the same time GCC's Ada (gcc-ada is the package for Arch Linux, for example) supports all versions of Ada. Funny that. I cannot say I am completely happy with the way they are trying to get money.
- shakna 7y agoSPARK [0], to put it simply. Contracts and static analysis rather than runtime checks takes Ada from being good to being great. I do prefer GNAT's error messages over AdaCore's compilers (despite the compiler frontend still being based on GNAT), but SPARK adds a ton. [0] I should note that SPARK 2014 is also available as a GPL'd "community" edition. EDIT: Asterisk + HN formatting
- pjmlp 7y agoWhy not the other remaining six vendors?
- AceJohnny2 7y agoIf you've done VHDL, you'll be familiar with Ada's syntax. When the DoD commissioned the design of VHDL, they required that its syntax be based on Ada. https://en.wikipedia.org/wiki/VHDL#History https://en.wikipedia.org/wiki/VHDL#History
- vlovich123 7y agoIt's interesting to see how Verilog & C both took over there in the industry. There's probably a chasm where the extra typedness isn't worth the velocity cost at the beginning of a project and when it's valuable the weight of switching can be too great. I think the middle ground is a language where you can relax some of your rules but then as pieces mature you can start enforcing stricter typing rules. I observe the same effect on other things like unit tests except the effect is the reverse of what people typically think. Lots of unit tests early on help you write correct code initially but as code matures it's just wasted automation time & it can end up ossifying some architectural decisions (ie. a change ripples out & causes a large amount of tests to need updating).
- UncleOxidant 7y agoI tend to disagree: strong typing is very valuable in the hardware design space - it's just that you couldn't convince hardware devs of this. If they had exposure to a programming language it was C (and possibly some assembly language) so they wanted something closer to what they were familiar with. When I worked in EDA I was given a project to get rid of linting errors in our generated HDL code. We generated both VHDL and Verilog. Our generated VHDL had very few problems thanks to strong typing. But there were lots of problems to fix in the Verilog code caused by it's weak typing.
- Avamander 7y agoIt's very valuable but not worth acquiring for most developers. I write relatively lot of C, I don't enjoy the familiarity, it just gets the job done for me in 90% less time because the tooling is there, the IDE is there, the documentation and support is good, the libraries are there - it matters a lot in what languages I find tolerable I've noticed. I like PLPGSQL, it's also has all that I've listed, I didn't like Ada and it doesn't have what I listed, because I had to "invent the wheel" so much. In the end, why spend 50-90 % more time to get that last x% of some foggy benefit?
- auvi 7y agoI first read about Ada in JARGON: Ada:: n. A {{Pascal}}-descended language that has been made mandatory for Department of Defense software projects by the Pentagon. Hackers are nearly unanimous in observing that, technically, it is precisely what one might expect given that kind of endorsement by fiat; designed by committee, crockish, difficult to use, and overall a disastrous, multi-billion-dollar boondoggle (one common description is "The PL/1 of the 1980s"; hackers find the exception handling and inter-process communication features particularly hilarious). Ada Lovelace (the daughter of Lord Byron who became the world's first programmer while cooperating with Babbage on the design of his mechanical computing engines in the mid-1800s) would almost certainly blanch at the use her name has been latterly put to; the kindest thing that has been said about it it is that there is probably a good small language screaming to get out from inside its vast, {elephantine} bulk. Maybe the situation is different now?
- dragonwriter 7y agoLanguages with the kind of constraints (sometimes kicked up to 11) that inspired the term “bondage and discipline languages” [0] have come back into vogue in a big way since the heyday of the Jargon File, and are in many cases the new “languages of choice” [1]. [0] http://catb.org/~esr/jargon/html/B/bondage-and-discipline-language.html http://catb.org/~esr/jargon/html/B/bondage-and-discipline-la... [1] http://catb.org/~esr/jargon/html/L/languages-of-choice.html http://catb.org/~esr/jargon/html/L/languages-of-choice.html
- schoen 7y agoI remember reading the first entry many years ago and wondering why anyone would want to use a language with type enforcement when you could have duck typing. (I thought of types as something that had been enforced by the lack of expressive power of old languages in which the types were effectively closer to the machine -- like describing the size of a machine word or something.) Later on I experienced the famous feature of Haskell in which it takes a while to write a valid program that compiles at all, but then the program immediately works correctly the first time and is free of several large classes of bugs. So yeah, excellent description of that trend! Edit: another closely related phenomenon is people gaining a new appreciation for formal grammars and formal specifications, understanding how hard parsing problems are and how bad the consequences of underspecification and undefined behavior can be. I imagine in the Jargon File heyday it would have been made fun of to use formal specifications everywhere, but now some of the most successful systems and tools use them to good effect. Maybe there was a "formal methods winter" or "formalism winter" to parallel the AI Winter? Edit 2: also, as a sibling comment mentions, these tools are much nicer to use now than they were then. Protobuf and friends do something akin to what ASN.1 did, but the tools around them are so much nicer!
- Catsandkites 7y agoWhat is the employment market like for Ada?
- jandrese 7y agoHow much do you like maintaining legacy DoD projects?
- xxxpupugo 7y agoLike not exist. Seems like NSA is the biggest employer.
- imglorp 7y agoThere's some non-DOD avionics floating around that are ADA, I guess because of requirements and regulatory overlaps. http://archive.adaic.com/projects/atwork/boeing.html http://archive.adaic.com/projects/atwork/boeing.html
- non-entity 7y agoInteresting. I imagine most Ada jobs (gov and non-gov) would have similar requirements to embedded jobs?
- cpeterso 7y agoI've read that SpaceX uses C++. I'm surprised safety critical systems like SpaceX and Tesla don't use Ada. It's a mature safe language used in their industry, yet they choose C++. From SpaceX's 2013 Reddit AMA: https://www.reddit.com/r/IAmA/comments/1853ap/we_are_spacex_software_engineers_we_launch/ https://www.reddit.com/r/IAmA/comments/1853ap/we_are_spacex_...
- fjcp 7y agoI don't have any experience on this field, but researching the subject some time ago I found that C/C++ is not unusual too. On the safety matter, when used in critical mission systems they usually follow a guideline or framework to ensure the reliability of the software, like MISRA C[0] for exemple. Another important point is that the development is real slow compared to other segments of software engineering and often takes several years to develop, with lots of tests and rigorous compliance with specifications. Its an interesting field, but feels hard to get into. [0] https://en.wikipedia.org/wiki/MISRA_C https://en.wikipedia.org/wiki/MISRA_C
- octorian 7y agoDuring weekend installfest/hackfest events at a LUG that I used to attend, there was always this one guy who would sit in front of a pair of laptops and code in Ada. One thing I remember about it is just how much it reminded me of Pascal.
- MisterTea 7y agoAda was built on top of Pascal so they are very similar. Another Pascal language is ST or Structured Text, an IEC industrial automation language specification for PLC's. I remember fooling with Ada years ago and I really liked the concurrency and ipc mechanisms which was quite unique in the 00's. It was a little more friendly to use vs. pthreads. Now every new language is baking in concurrency. Since I wrote mostly c code I wound up making a franken program which was a statically linked Ada/c. I used Ada for its concurrency which called my linked in c code. It was a PLC emulator I scrapped.
- bluejekyll 7y agoFirst, this is a great introduction article to Ada. It's a great history lesson, and analysis of where it's used and why. That said, it seems to be arguing for something in a vacuum. Where is the mention of other new programming languages that also fit this category? Where is the mention of Rust? Rust fits all the same requirements: - A general, flexible design that adapts to satisfy the needs of embedded computer applications. - Reliability. The language should aid the design and development of reliable programs. - Ease of maintainability. Code should be readable and programming decisions explicit. - Easy to produce efficient code with. Inefficient constructs should be easily identifiable. - No unnecessary complexity. Semantic structure should be consistent and minimize the number of concepts. - Easy to implement the language specification. All features should be easy to understand. - Machine independence. The language shall not be bound to any hardware or OS details. - Complete definition. All parts of the language shall be fully and unambiguously defined. The exception is possibly the last one, complete definition. But that's debatable as Rust does have a reference, but no one wants to go as far as calling it a spec. (Also, I know some people think Rust has some "unnecessary" complexity, personally I do not). The article goes on to compare to C, but doesn't mention some of the new features of C++ that make it safer, or Rust which is approximately as safe as Ada. So why would I pick Ada over other modern languages? btw, I really enjoyed Steve Klabnik's post on learning Ada: https://words.steveklabnik.com/learning-ada https://words.steveklabnik.com/learning-ada
- falcolas 7y ago> - Easy to implement the language specification. All features should be easy to understand. I'm not sure this is at all applicable to rust. Perhaps once there are more than the one, quickly mutating, implementation, we can say that it's easy to implement the specification. > - Reliability. The language should aid the design and development of reliable programs. This one feels a touch questionable, given the built-in "succeed or die" macros that simplify code at the cost of reliability. There's also the unsafe keyword, and how the impact of an unsafe operation in one section of code (say, an imported library) can have negative impacts on unrelated sections of code otherwise deemed safe. > - No unnecessary complexity. Semantic structure should be consistent and minimize the number of concepts. Borrow checker aside, there is a ton of complexity in Rust (traits, multiple flavors of arrays, multiple flavors of boxed values). > - Machine independence. The language shall not be bound to any hardware or OS details. Rust relies on the LLVM project to provide this, and relies on the contributors to the LLVM project to target different architectures.
- non-entity 7y agoI toyed with Ada some years ago. I was interesting, and I was fascinated by the type system, but never had any real use for it
- GnarfGnarf 7y agoI've developed a set of "strongly typed" classes in C++ that have saved me a ton of grief. Here are some examples. All classes are fundamentally floats. Errors are caught at compilation. cInches i1, i2, i3; cCm cm1, cm2; i1 = 1.f; // error i1 = cInches(1.f); // OK i3 = i1 + i2; // OK cm1 = i1; // error i1 = i2 * 2.f; // OK float f1 = i1 / i2; // OK i1 = i2 * i3; // error! square inches are not inches int add(cInches in1, cInches in2); add(i1, i2); // OK add(cm1, cm2); // error 'Typedef's just don't cut it.
- vardump 7y agoWhy use floats when you can basically have doubles for the same cost? Floats tend to cause nasty surprises when you deal with real world units.
- LPDWORD 7y ago> Why use floats when you can basically have doubles for the same cost? Floats costing the same as doubles is a myth stemming from x87 arithmetic, which is obsolete. On an x64 CPU running 64-bit code, your compiler can often pack four floats into one SSE register. Even when that doesn't happen, CPU microcode can likely do more with floats than with doubles. Lastly, memory bandwidth usage and cache occupancy doubles, which is true even with x87.
- vardump 7y agoThe difference is meaningless in scalar code. Not everything is or can be vectorized. Pretty much no difference between one double and one float in a SSE XMM register. > Even when that doesn't happen, CPU microcode can likely do more with floats than with doubles. I have no idea what that means. As far as I know, there's no CPU microcode dealing with floating point numbers. > Lastly, memory bandwidth usage and cache occupancy doubles, which is true even with x87. So use floats when you have a lot of data.
- LPDWORD 7y ago
- ch_123 7y ago> Ada code controls rockets like the Ariane 4 and 5, many satellites, and countless other systems where small glitches can have major consequences. A somewhat amusing endorsement given that the infamous failure of the maiden launch of the Ariane 5 due to series of interconnected software bugs - a reminder perhaps that the choice of implementation language does not automatically make for a reliable system.
- ahartmetz 7y agoAmusing but only superficially a counterexample because the bug was basically in a specification-implementation mismatch. Nothing in the language can catch that.
- deleted 7y ago[deleted]
- bigbaguette 7y ago105 launches, 2 failures, 3 partial failures. That's a 95,2% success rate.
- sixplusone 7y agoHow many dollars did the failures cost?
- pizzapill 7y agoCa. 370 Mio. USD
- Rexxar 7y agoI nitpick a little but failures were at launch 1 and 14. Partial Failures at launch 2, 10 and 97 so the current effective success rate is much higher than 95,2%. (4 failures in the 14 first launches, but only one partial failure in 91 launches since).
- kragen 7y ago
- jeffdavis 7y agoThere is some overlap in the use cases between Ada-in-the-mainstream (which seems to be what the article is suggesting) and Rust. The existence of Rust will make it even harder for Ada to break out of its existing domains. Both seem to have good ecosystems, but quite different. Ada has more high-assurance tooling and practices. Rust has more in terms of packaging and general-purpose high level libraries. With Ada, it's pretty hard to shake the feeling that it's not as welcoming. Either you are building a spacecraft, or "what are you doing here?". Not that anyone actually says that, and in my limited experience playing with the language, everyone seemed nice. It's just a feeling that's hard to escape. I wish it weren't so, because I think Ada has a lot going for it and it could be good in more donains. One kind of cool thing is that it's designed to get by without so many heap allocations, and it does some interesting things to allow/encourage more stack allocations. It also has more sophisticated runtime checks, like contracts, that are kind of between a unit test and a compile-time check. Rust is great at managing complexity. I keep holding out hope that Ada can somehow give us some simplicity back while still making useful software.
- im_down_w_otp 7y agoI understand what you're getting at here I tbink, but one of the ecosystem challenges we run into is that while Rust is abstractly a fantastic choice for the domain of systems development that would often be served by Ada (in fact we think it's a lot better in some respects because we can do more statically ahead of time, that Ada does dynamically at runtime, by abusing the Rust type system and borrow-checker), the Rust ecosystem isn't really focused on this class of problems. There's significantly more attention provided to things like Wasm than there is to things like embedded use cases for example. The two languages, ecosystems, and communities seem to have largely non-overlapping objectives despite having overlapping technical capabilities.
- Gibbon1 7y ago> ore attention provided to things like Wasm than there is to things like embedded use cases for example. Things might be better, but last time I checked rust's compiler was a lot slower than C and the binaries were several times bigger. That last one is a big deal for embedded.
- Symmetry 7y agoDifferent types for different units is a great idea. Nim borrowed it from Ada and I assume that there are other programming languages that did too.
- wrp 7y agoThis article promotes a popular misconception of the programming situation for defense projects in the 1970s. There may have been "hundreds of specialized programming languages" in existence that could be used, but just a handful actually predominated. Most aeronautical projects were done in JOVIAL. I've talked about this history with engineers from the 1960s-70s. They did not regard the introduction of Ada as a good thing. The JOVIAL language had been developed by engineers and modified through experience over several years to become something they were quite happy with. The impetus that led to Ada came from management and implementation was done by academics.
- hwayne 7y agoWelp, there's my rabbit hole for the week. I've never heard of JOVIAL before, and it looks like there's lot of interesting stuff here. Thank you!
- bdavis__ 7y agofortran with nice syntax and built in bit operations.
- galangalalgol 7y agoNice fixed point types too. A fixed point all to the right of the binary point to represent angles asa semicircle was useful. Table ovelays are evil though. I'd rather have rust than ada for the functional lineage along with the performance, but the thin stdlib combined with the difficulty of getting a crates.io mirror certified clean of malcious code makes it problematic.
- Skunkleton 7y agoNot to say Rust is ready for prime for safety critical systems, but both crates.io and the standard lib are optional for Rust.
- 7y ago
- verisimilitudes 7y agoThis article was a decent introduction, I suppose. I've been learning Ada for about a year now, and I quite like it. It's larger than the previously largest language I know, Common Lisp, but I like the focus on reliability and whatnot; it's a language that has many facilities programs need, but you don't need to use otherwise; it's also segmented well, unlike Common Lisp, but there's advantages to both methods. There's a flaw in the article: Ada doesn't define standard types like int or float... It does, technically, Integer and Float. The rest of the article is fine. Lastly, it's amusing to see the Rust advocates cry out due to this. As I like to write, Ada is used in critical systems such as ballistic missiles and trains, whereas Rust is used in Firefox.
- dpc_pw 7y ago> As I like to write, Ada is used in critical systems such as ballistic missiles and trains, whereas Rust is used in Firefox. You mean to say that Ada is good for much simpler, easier, smaller-scope projects?
- krapht 7y agoOnly a person who has never worked on a safety-critical application would say something ignorant like that. (I am neither a Rust nor an Ada user.)
- dpc_pw 7y agoI have actually worked on safety-critical applications. ISO 26262, MISRA C, ASIL, etc. :D . I even own and drive a car that has my software in it. I am obviously teasing the OP, but there's IMO a lot of truth to it. Safety-critical stuff damn better be simpler, smaller and fundamentally easier or it will fail and kill people. That's why stuff like https://groups.google.com/forum/message/raw?msg=comp.lang.ada/E9bNCvDQ12k/1tezW24ZxdAJ https://groups.google.com/forum/message/raw?msg=comp.lang.ad... makes sense. In a lot of aspects, mission critical-software is much, much "easier": easier to stretch the budgets, easier to not have competition, easier to justify why something can't be done or why it has to take another 3 years of work. While a modern fully functional web browser is a huge pile of complexity, technologies, requirements and yet it is still needs to work under much tighter social, economical and performance pressures. Any bug being widely exploited, could lead to people literally dying or at least having their lives ruined. It's just not as spectacular as "missiles". So I think the OP (and probably you as well :P) is being arrogant by dismissing "firefox", that's all.
- kahlonel 7y agoAs a side note for people like me who have no option other than C for their safety critical projects, remember there's a MISRA-C standard. If that feels too much, [1] is a good starting point. [1] http://pixelscommander.com/wp-content/uploads/2014/12/P10.pdf http://pixelscommander.com/wp-content/uploads/2014/12/P10.pd...
- snazz 7y agoThank you for the link! I think that’s really helpful and those are good explanations for each rule. Does anyone know of a guide for writing C code where you allocate a specific block of memory at the start and then use that for all data from then on? Avoiding malloc is one of the suggestions there and seems like a smart strategy.
- baot 7y agoI've written code exactly like that and realised that it just kicks the can down the road: you're still allocating memory from a fixed block, it's just now the malloc is written by you, with more bugs, and you still need to deal with variable allocation delays and running out of memory. The real issue is if you don't know at compile-time what resources you'll need at run-time. For some problems that can be an intractable problem for making a safe product, including, to my knowledge, everything that runs on a rich OS.
- carlmr 7y ago>The real issue is if you don't know at compile-time what resources you'll need at run-time. For some problems that can be an intractable problem for making a safe product, including, to my knowledge, everything that runs on a rich OS. You're right, but you should still constrain yourself to these few instances to use malloc instead of wildly using it everywhere.
- mypalmike 7y agoI've never seen a guide, but I worked on some console games around 15 years ago where the rule was "malloc is evil". That mindset was enlightening and felt "correct" compared to some of the sloppy memory management I'd seen (and, sadly, implemented) on some PC game titles I'd worked on before. Basically we treated the heap like a stack of large context oriented memory blocks. Each of these blocks contains fixed data loaded from disk (static game resources like bitmaps, UI layouts, etc) and fixed size pools of fixed size game objects. The big blocks would get allocated in a stacked manner at distinct times like game title load and level load. So if your game has bullets, you have a memory pool of say, 100 bullets to maintain the state of each instance. If you try to shoot a 101st bullet, you either don't or you have an ejection strategy. You never malloc or free during gameplay : you only allocate from one of the pools. When it's time to unload the level... boom, you free the whole block at once, popping this stack. This is extremely efficient compared to freeing many individual malloc allocations.
- leshow 7y agoSo one should learn Ada because it doesn't coerce integers? Plenty of modern languages won't do that.
- rurban 7y agoI'm missing SPARK, the restricted and formally defined language based on Ada, extending Ada with contracts and aspects, and disallowing the insecure parts. https://en.wikipedia.org/wiki/SPARK_(programming_language) https://en.wikipedia.org/wiki/SPARK_(programming_language) This is the real highlight of Ada.
- johnisgood 7y agoExactly. See this post: https://news.ycombinator.com/item?id=20934511 https://news.ycombinator.com/item?id=20934511
- altoidaltoid 7y agoFlashbacks to Prof. Feldman's classes
- kshannon 7y agoOr Dr. McCormick's classes. CS 101 with Ada. Students 2 years behind me got to learn Java or Python. He wrote 3 books on Ada. http://www.cs.uni.edu/~mccormic/ http://www.cs.uni.edu/~mccormic/
- waynecochran 7y agoAda was the language of the undergraduate curriculum at the University of Washington when I was there (late 1980's) -- because Boeing. One of the core safety mechanisms was exception handling. * The biggest thing I miss is that every block was inherently a try-block. Just put your exception handlers at the bottom of the block. This provided a nice separation of "normal flow-control" and "exceptional flow-control". Why have try-catch anyway -- I never got used to that later in life. * Exceptions were not synonymous with errors. In fact the way to read a file byte by byte was just to keep reading bytes and never explicitly check for end-of-file. Let the exception handler handle this case. Logic is much cleaner. * Remember that you can't just dump core and shell out to the OS on an un-handled exception -- not if your controlling a ICBM flying of the continent. Ada really forced you to handle all errors at some level of the call-stack with an exception handler. At the outer-most level -- just call self-destruct.
- realusername 7y ago> * The biggest thing I miss is that every block was inherently a try-block. Just put your exception handlers at the bottom of the block. This provided a nice separation of "normal flow-control" and "exceptional flow-control". Why have try-catch anyway -- I never got used to that later in life. That's still the case in Ruby, you can put a rescue at the end of the block.
- waynecochran 7y ago"rescue" seems to imply "error," whereas "exception" means simply an unusual / non-normal condition. Does Ruby encourage exception handling as control-flow besides error conditions?
- ajxs 7y agoI live near Sydney University ( not my alma-mater ). In a rather serendipitous turn, one day on my way home from the shops I was walking past one of the USYD buildings and there was a giant stack of library books that had thrown out onto the sidewalk as rubbish to be collected by the council. It turns out they were old science faculty books that were no longer prescribed material. I started looking through them and found several books on Safety-critical software development in Ada, several books on hardware design and several others on software development. I took them all home, at first thinking the Ada ones would just be some archaic novelty. When I got a chance to read them I was amazed. I was expecting something akin to COBOL from the language. Instead I found a language that was extremely well designed for its domain. I'd already done a bit of embedded and operating system development, and I could immediately see how Ada would benefit a developer in these areas. Even representation clauses alone are such a huge convenience for low-level programming. I haven't looked back since. I was actually in the process of preparing a bare-bones example of operating system development in Ada, if this post had been three days later I'd have been able to link the finished product here right now.
- crucini 7y agoI look forward to seeing your OS example.
- ajxs 7y agoAs I posted in another comment, here's my initial implementation: https://github.com/ajxs/cxos https://github.com/ajxs/cxos Apologies for the double post. I just wanted to ensure that you would see the reply.
- OneWingedShark 7y ago> if this post had been three days later I'd have been able to link the finished product here right now. Well, that was 5 days ago, which means you CAN post the link! (I'd like to see it, quite a lot.)
- ajxs 7y ago
- mickduprez 7y agoWhat about Forth? I quite like the way it eschews too much abstraction and can go from very low level to high level with a lot less code (and less bugs). Given the current interest with IoT and the proliferation of cheap micro controllers it might be due for a resurgence(?).
- kragen 7y agoI like Forth but I always seem to make my programs too clever in it. If I write them in C or assembly instead it takes longer but has less bugs. Probably people with better self-discipline than I have can do wonders in Forth. Current micros are a bit big for Forth, though. You can run C or C++ on them. If you have only 4K or 8K of code space and 128–512 bytes of RAM the case for C over Forth gets a lot weaker. Maybe we'll see a resurgence of Forth when we get nanobots.
- choonway 7y agoI used Ada (GNAT) about 15 years ago. One of the things that struck me was the accuracy of the compiler error messages and the sophistication of the debugger, when compared to C/C++ in Visual Studio / GCC
- mikorym 7y agoI believe the Eurofighter Typhoon was and still is programmed in Ada.
- eb0la 7y agoI believe most NATO weapon systems are programmed in Ada. It just makes natural to integrate anything with the avionics using the available interfaces, specially with the friend-or-foe systems.
- writepub 7y agoNo you shouldn't be writing in Ada. Embedded software running all kinds of sensitive workloads, from pacemakers to routers/switches use C for it's superior tooling, universal support across compilers and chip vendors, massive user base and decades long best practices (like NASA's C coding guidelines) to mitigate some of C's potential inadvertent misuses. Not to mention the bevy of advanced niche features, like SIMD support, and custom GCC extensions that lend superpowers to C coders that other languages typically lack. Sure, ada may have it's benefits for certain narrow use cases, but for non-hobby projects spanning tens/hundreds of engineers, considering real world vendor support for ada and missing talent pool, C is the obvious choice
- irundebian 7y ago- You don't need much tooling and coding guidelines if safety aspects which prevent common C errors are built into language design. Despite that SPARK, a subset of Ada makes it more easy to proof program correctness. I'm not sure if it's similarly easy for C.
- Mikhail_Edoshin 7y agoI once flipped through Ada spec (purely voluntarily) and in my opinion it was a really well designed language. I generally come to believe that a language should offer fewer fancy programming constructs, but advance in specifications and definitions, and Ada looked like a solid step in that direction (as compared to C, for example). As it was recently pointed out by some other discussion here at HN the idea of software development is to document knowledge, and Ada is pretty good at that. The modern trend is very different, unfortunately.
- JulianMorrison 7y agoWhen I played with Ada, my feeling was that it allowed a lot of things to lean on the types, protection is one that gets made a lot of fuss about, but also there's a lot of labour saving. You can size something to the length of something else. You can get the max and min of a type (which are user defined, not tied to byte sizes). You can get an array's bounds. Everything "reflows" if you edit the type definitions. It allows you to be very detailed about what you want, and then let other parts of the program lean on that detail. Types become more than a way to catch mistakes, they become a way to describe your intentions.