6 ms·
hey everyone, author here! happy to answer any questions about the post, our system, or our usage of rust :)
by sujayakar 7y ago
hey everyone, author here! happy to answer any questions about the post, our system, or our usage of rust :)
- quantified 7y agoHow did the decision to use Rust go from idea to acceptance/adoption? Management can be risk-averse in choice of dev platform, and if Rust was adopted more than 18 months ago it was maybe even before the “rewrite it Rust” meme. Lessons learned and preconditions for success on this decision are especially welcomed.
- rbtying 7y agodisclaimer: was on the team, but didn't write the article / don't work on this anymore Rust was adopted at Dropbox for some serving infrastructure use cases more than a year before the sync rewrite was started, which was about four years ago. I'd say we solidly predated the "rewrite it in Rust" meme. I believe that this rewrite was only successful because of Rust's ability to both interact safely/efficiently with underlying OS APIs (they're pretty much all C-like) and to encode complex concepts into the type system and the compiler. Rust isn't the only language with these properties, but it is one of the few -- and it's one that we really enjoyed using.
- palerdot 7y ago> Rust isn't the only language with these properties, but it is one of the few Just curious, what are the other languages that competes with Rust in terms of correctness, safety, ergonomics and efficiency? Go is more on the ergonomics side and Haskell on the correctness side, but are there any serious alternatives for Rust that checks all the boxes?
- The_rationalist 7y agoThe only box that rust has over others is runtime performance. One would consider languages such as Kotlin/modern C# to be the modern sweet spot as they tick all the boxes, and for performance they are ~2 time slower than rust which is just fast enough for anything that isn't HPC/AI/very specific need
- rbtying 7y agoIt depends on what you mean by checking all the boxes: Go is tricky if you run on diverse platforms and want to do a lot of FFI, since cgo overhead is significant. The type system in Go is also not very powerful, which is both good and bad. Haskell tends to hit performance walls that are very difficult to debug, and has a pretty similar learning curve to Rust (most people you hire onto the team won't know the language already). The predominant competitor in this space is probably a high-level dynamic language combined with C/C++ library code. With good tooling and good practices to mitigate footguns, the extensive library support in C++ has a lot to offer. Of course, I think Rust makes a better trade-off there, but early in the project it was not at all obvious that the good parts outweighed the fact that we would probably have been the biggest user of any library we depended on. We had some fun adventures in stress-testing HTTP/2 support here :)
- jp_sc 7y agonim ? https://nim-lang.org/ https://nim-lang.org/
- quantified 7y agoThanks! Genesis had already occurred. I take it there was already a culture that could handle exploiting a rich type system.
- steveklabnik 7y agoVery psyched to see even more Rust at Dropbox!
- CodeWriter23 7y agoI have a question, is hooking filesystem write notifications on macOS hard? As soon as I paid for the Plus Plan, I started having to wait several minutes for a file to upload. Even from one computer to the other with LAN Sync enabled. The day before that, my files would sync faster than I could hit refresh in the browser I was developing in.
- saagarjha 7y agoThere’s API for it, which I’m sure the Dropbox team is aware of. There’s probably another reason why it didn’t sync immediately.
- sujayakar 7y agofor mac it's FSEveents: https://developer.apple.com/documentation/coreservices/file_system_events https://developer.apple.com/documentation/coreservices/file_.... > As soon as I paid for the Plus Plan, I started having to wait several minutes for a file to upload. Even from one computer to the other with LAN Sync enabled. The day before that, my files would sync faster than I could hit refresh in the browser I was developing in. that definitely seems like a bug, could you report it? click on the dropbox tray, click on the dropdown in the top right, and then click "Report Bug." this will collect some information about your client to help us debug.
- saagarjha 7y agoI'm curious if Dropbox could replace their kernel extension and FSEvents usage with an EndpointSecurity client. Would you happen to know if there's any work being done in this area?
- asplake 7y agoInteresting to see Rust praised for its ergonomics, possibly not the first word that springs to mind (to an interested observer, not yet a user). Could you say a bit more about that?
- sujayakar 7y agosure! the rust team has done a fantastic job with the language design, and once a programmer gets over the initial learning curve, the ergonomics of "pair programming" with the compiler are really great. they've put a lot of work into error messages, and the language definitely steers the programmer towards writing correct, efficient code. also, a lot of the standard library APIs are really well thought out, and it's great to then use the type system to build great internal APIs as well. the ability to design APIs to make correct use easy and incorrect use difficult feels like good "ergonomics" to me :)
- _bxg1 7y agoRust is funny because in one sense it's hard and clunky. However, it's only ever precisely as hard and clunky as it needs to be. Everywhere something can be made more concise, or readable, or convenient, without sacrificing any control, it has been. Anytime something is hard or inconvenient, it's because the underlying domain really is exactly that hard or inconvenient. Contrast this with other languages, which are often clunky when they don't need to be and/or "easy" when they shouldn't be.
- ssokolow 7y agoYou're the second person I've seen approach that "Anytime something is hard or inconvenient, it's because the underlying domain really is exactly that hard or inconvenient." point in the last little while. Have you read https://fasterthanli.me/blog/2020/i-want-off-mr-golangs-wild-ride/ https://fasterthanli.me/blog/2020/i-want-off-mr-golangs-wild...?
- jhayward 7y agoVery interesting writeup. Did you consider using formal verification tools such as the TLA family to ensure that your sync protocol is well-specified and consistent?
- sujayakar 7y agoyeah, I'm familiar with those tools, and other teams at dropbox have used TLA+ for verifying their protocols, but we haven't done it for our system yet. we've spent most of our time on testing working on better randomized testing, with the idea that covering more surface area there has higher ROI. but I can definitely see value there, especially once the protocol "settles down" and sees less change over time.
- justicezyx 7y agoBefore the rewriting, how many SWE hours were devoted to the maintenance of this piece of code? Did the maintainer, if any, got meaningful recognition which correctly translate the importance of the work?
- sujayakar 7y agoIIRC, we had a team of about six engineers working on the core system itself plus a few product teams building features on top. and yes, the team did get recognition for their work, which definitely helped when we decided to begin rewriting!
- justicezyx 7y agoWere the six engineers taking part in the rewriting at all?
- sujayakar 7y agoyep! it was 100% critical to have the experts on sync engine classic involved with nucleus. we shared the oncall rotation of maintaining the old system among the entire rewriting team.
- FullyFunctional 7y agoIt is a great article and I really enjoyed it. I fear that people might latch on too quickly to "Rust" and not appreciate that the preciser (formally defined?) data model was key, and that languages like Rust (and Haskell) are merely very suited for this, but not the key. [Reworded to make my point clearer] OT: I really really hate the top bar that drops down and covers what I'm reading when I'm trying to scroll up. It's such a frequent pattern on the modern web and I can't wait for people to get rid of it. (It violates the symmetry of scrolling up and down)
- GordonS 7y agoYears ago when I used Dropbox on Windows, if would poll every single file on startup, which in the days of spinning disks rendered the machine unusable for several minutes - does Dropbox on Windows still do this? Also, after the startup phase, IIRC Dropbox used the `FindFirstChangeNotification` Windows API function, which can miss changes under heavy load - do you still use this method, or have you moved to something else, such as using the NTFS USN journal, or a file system minifilter driver?
- sujayakar 7y agowe still have to check every file on startup, since we use the `ReadDirectoryChangesW` call on windows, but it should be less expensive on nucleus. but, now that we've rolled out nucleus, we can start exploring going beyond sync engine classic feature parity, like using the USN journal on windows.
- GordonS 7y agoFor NTFS volumes (basically all Windows volumes), you could use the change journal to eliminate that painfully expensive startup check of all files - that would be huge for Windows users. Also, have you previously explored the possibility of using the NTFS change journal, and if so, what challenges did you face? (I don't mean to come across negative; I'm genuinely interested to learn why you didn't use this a decade ago, since there must be a reason).
- rbtying 7y agoAs I recall, this was investigated at one point on Sync Engine Classic and is definitely a thing that folks were thinking about for Nucleus, for pretty much exactly this reason. The biggest challenges with this kind of work (not specific to the USN journal) are in the lack of reliable cross-platform support for features which can be shimmed to look similar. The more unique the code path, the harder it is to test en masse. It's also the case that the execution environment on Windows machines tends to be very diverse due to a long history of backwards compatibility and the ability to set complex domain policies -- Dropbox strives for a good user experience, and "go talk to IT to have them change this setting" is rarely one of those. disclaimer: worked on sync at Dropbox; don't work on it anymore; don't have current context