6 ms·
I'm really surprised this isn't in Rust considering security is a priority. However, I think something like this will become increasingly common for high perfor
by dtrailin 7y ago
I'm really surprised this isn't in Rust considering security is a priority. However, I think something like this will become increasingly common for high performance cloud applications. Many programs do not need a full operating system with processes isolation and hardware drivers if they're going to run alone on a VM anyways.
- ncmncm 7y agoThe most urgent goal for this effort is usefulness. Geek trend box-checking has to come second.
- twoodfin 7y agoSo where is it being useful? A quick tour around the website was not enlightening in this regard.
- ncmncm 7y agoIt is mostly used in bespoke, proprietary projects that have extreme performance requirements, and specialized deployments. Not your garden-variety portable app. So, not typically visible. But 99+% of production software in use is more like that than what you can find online.
- dtrailin 7y agoRust is not the right choice because it's trendy, but because it provides memory and thread safety properties that are hard to enforce in C++. For systems software the advantages are huge.
- ncmncm 7y agoRust is also years away from maturity (which it probably will achieve, on schedule). Systems built today need to work with tooling that is mature today. Memory and thread safety properties can be achieved in C++ by operating at a higher level than C with mature, well-debugged, well-optimized libraries. No pointers means no pointer errors. Integer overflows are equally possible in Rust and C++. Both offer debug build modes that can watch for those.
- saagarjha 7y ago> Memory and thread safety properties can be achieved in C++ by operating at a higher level than C with mature, well-debugged, well-optimized libraries. No pointers means no pointer errors. Eh, not to the extent that Rust does. It’s still reasonably easy to get use-after-frees by using a value that has been moved or destroyed. > Integer overflows are equally possible in Rust and C++. Both offer debug build modes that can watch for those. In Rust the behavior is defined regardless of signedness.
- ncmncm 7y agoDefined is not the same as correct.
- saagarjha 7y agoBut undefined is the same as incorrect. Any signed overflow in your C or C++ program is a place where you’ve opened yourself up to some quite problematic consequences.
- ncmncm 7y agoYes, just as in Rust. Pretend correctness is not correctness just because it is not UB. I have the same discussion with people who insist unsigned types in C++ or C are safer than signed types because of the UB boogeyman. They only demonstrate their own limited understanding.
- the_why_of_y 7y ago> No pointers means no pointer errors. Use after free can be perfectly well expressed with C++ references, or invalidated iterators to standard library containers. > Integer overflows are equally possible in Rust and C++. In C++, unsigned integer overflows can often be leveraged into out-of-bounds access; in safe Rust, they cannot.
- ncmncm 7y ago
- klyrs 7y ago> I'm really surprised this isn't in Rust considering security is a priority. The first commits to IncludeOS were 2014, when Rust was in a high state of flux; before the 1.0 release. So I'm certainly not surprised given the historical context of the two projects. Rust has some cool features, but believe it or not, C++ is still a popular language and people continue to develop projects that are older than Rust. So even if you're of the opinion that C++ is entirely deprecated by Rust, we're not going to stop the entire world and rewrite every C++ project in Rust. But good news! You can run your Rust apps in a Rust-based unikernel OS [1]. Since these OSs are meant to run in containers, the ecosystem is big enough for both and we don't need such shedpainting conversations. [1] https://hermitcore.org/ https://hermitcore.org/
- fearingreprisal 7y agoI'm really surprised this isn't in SPARK considering security is a priority. Rust's type system still isn't capable of formal verification of lack of run-time errors... You know, considering security is a priority.