5 ms·
Rust is not the right choice because it's trendy, but because it provides memory and thread safety properties that are hard to enforce in C++. For systems softw
by dtrailin 7y ago
Rust is not the right choice because it's trendy, but because it provides memory and thread safety properties that are hard to enforce in C++. For systems software the advantages are huge.
- ncmncm 7y agoRust is also years away from maturity (which it probably will achieve, on schedule). Systems built today need to work with tooling that is mature today. Memory and thread safety properties can be achieved in C++ by operating at a higher level than C with mature, well-debugged, well-optimized libraries. No pointers means no pointer errors. Integer overflows are equally possible in Rust and C++. Both offer debug build modes that can watch for those.
- saagarjha 7y ago> Memory and thread safety properties can be achieved in C++ by operating at a higher level than C with mature, well-debugged, well-optimized libraries. No pointers means no pointer errors. Eh, not to the extent that Rust does. It’s still reasonably easy to get use-after-frees by using a value that has been moved or destroyed. > Integer overflows are equally possible in Rust and C++. Both offer debug build modes that can watch for those. In Rust the behavior is defined regardless of signedness.
- ncmncm 7y agoDefined is not the same as correct.
- saagarjha 7y agoBut undefined is the same as incorrect. Any signed overflow in your C or C++ program is a place where you’ve opened yourself up to some quite problematic consequences.
- ncmncm 7y agoYes, just as in Rust. Pretend correctness is not correctness just because it is not UB. I have the same discussion with people who insist unsigned types in C++ or C are safer than signed types because of the UB boogeyman. They only demonstrate their own limited understanding.
- the_why_of_y 7y ago> No pointers means no pointer errors. Use after free can be perfectly well expressed with C++ references, or invalidated iterators to standard library containers. > Integer overflows are equally possible in Rust and C++. In C++, unsigned integer overflows can often be leveraged into out-of-bounds access; in safe Rust, they cannot.
- ncmncm 7y agoUse-after-free can be expressed in C++, but there is no temptation to do it.