19 ms·
Playing around with the Fuchsia operating system
- sk0g 6y agoI thought it was going to be some boring material UI screenshots, but this is so much more interesting! Susceptible to the usual C bugs, albeit with minor impact. I thought they were switching most of the kernel and drivers to Rust, for some reason. Edit: not a Rust fanboy by any means, hell, I've never even opened a Rust file.
- Q6T46nT668w6i3m 6y agoZircon, the kernel, is written in C++. There’s no programming language requirement for components, e.g. the network component is written in Rust.
- est31 6y ago> I thought they were switching most of the kernel and drivers to Rust, for some reason. Note that zircon itself is not allowed to contain any Rust [0]. It's not exactly specified what they mean by the kernel, but it seems that this includes not just the microkernel but also everything that lives in the zircon top level directory, which is enough to boot the system. tokei says there is not a single line of Rust in that entire directory (but about 1 million lines of C/C++). [0]: https://fuchsia.googlesource.com/fuchsia/+/cb20372465f875ff4fbf2a04f0951430207f7b7a/docs/contribute/governance/policy/programming_languages.md#languages-rust-decision https://fuchsia.googlesource.com/fuchsia/+/cb20372465f875ff4...
- sk0g 6y agoI wonder what the ratio of C:C++ is. Sounds like they're using C as a restricted C++ anyway, which is interesting.
- yjftsjthsd-h 6y agoI know what it means to use C++ as a nicer C, but what does it mean to use C as a restricted C++?
- de_watcher 6y agoC as a restricted C++ could be probably something like GLib: a deeply object-oriented library (nowadays C++ isn't about OOP at all though).
- est31 6y agoAs of commit cb20372465f875ff4fbf2a04f0951430207f7b7a, according to tokei, in all of fuchsia there are 792k lines of C, 880k lines of C header, 1.711M lines of C++, 10k lines of C++ header, and 2.585M lines of Rust. In the zircon subdir, there are 569k lines of C, 300k lines of C header and 473k lines of C++.
- kyaghmour 6y agoThis debate about monolithic vs. micro-kernels has been had many times. Maybe this time the resolution is different, who knows. But FWIW Linux didn't reach its success because someone made a feature comparison between it and what else was out there in a spreadsheet and somehow discovered how Linux was so much better. Instead, Linux won (and continues to win) because it's the Rocky Balboa of operating systems. It may loose the first round, but it always come back. And the reason for that is that Linux's biggest feature isn't necessarily technical. Rather, it's the community of people around it, the fact that it can tolerate a healthy dose of disagreement and infighting before eventually finding and settling on whatever best solution solves the next immediate problem, not some far-into-future idealistic goal. The downside to that development model is that radical changes take several iterations/years while in a centrally-managed OS development model can be shoved in "atomically" -- ex: real-time, tracing, etc. You can devise many a great OSes on paper and even implement them. Bootstrapping an entire ecosystem and, effectively, institutionalize a completely open and nimble development model such as that of the Linux kernel is a whole other story.
- jfb 6y agoKeep in mind, too, that path dependence plays a huge role here. Linux took off when the alternatives were Windows NT, Novell Netware, or commercial Unixes running on underpowered RISC hardware.
- wbl 6y agoBSD was around!
- messe 6y agoIt was, but it was in legal limbo.
- cesarb 6y agoI have also read that, back then, Linux was better at supporting common hardware than the BSDs (https://news.ycombinator.com/item?id=21420338 https://news.ycombinator.com/item?id=21420338). My personal experience at the time is that I didn't even consider the BSDs; Linux had UMSDOS, which allowed me to try it out without having to repartition and/or reformat (then later I noticed that I was nearly always on Linux, so I reformatted a whole partition as ext2 and dedicated it exclusively to Linux).
- bsaul 6y agoI'm both very excited someone is taking a shot at trying something new on kernel side. But i can't help wonder about what would a future look like where 90% of hardware run on a Google-owned operating system.
- logicprog 6y agoWould that really ever happen? Microsoft - a company so dominant it got an antitrust lawsuit - hasn't even been able to get 90% of the market share. No operating system since the very early days of computing has. Not only that, but other older operating systems are always going to have an advantage here anyway: they'll have support, ecosystems, documentation, and people with years of experience with them. Google isn't even a monopoly in search for heaven's sake! Only 87% of people use Google Search. If they can't get a monopoly there - and you really can't get a monopoly in almost any industry without government help - what makes you think they can get a near-monopoly in operating systems?
- Mediterraneo10 6y ago> Only 87% of people use Google Search. Note that some ostensible competitors like Startpage are still powered by Google under the hood.
- logicprog 6y agoAh, interesting.
- ocdtrekkie 6y ago87% of the market is a monopoly by any legal definition.
- mrep 6y agoA monopoly is the sole supplier of a product or service and the fact that bing exists makes search not a monopoly. In the concept of antitrust, the United States Department of Justice does not use that term directly and instead talks about power and the Supreme Court has defined market power as "the ability to raise prices above those that would be charged in a competitive market," and monopoly power as "the power to control prices or exclude competition" [0]. Google does not posses monopoly power over search as they do not exclude you from using bing, nor do they control prices (bing in fact sets a lower price than Googles free in that they will pay you to use their search engine). They do have market power though. [0]: https://www.justice.gov/atr/competition-and-monopoly-single-firm-conduct-under-section-2-sherman-act-chapter-2 https://www.justice.gov/atr/competition-and-monopoly-single-...
- modeless 6y agoIt seems such a waste to spend all the effort to write a whole new OS and all these drivers with the same old buffer overflow bugs we've been fighting since the dawn of time. It doesn't have to be this way anymore!
- logicprog 6y agoIndeed. I wonder why they didn't go with Rust? They seem to be trying to make the perfect architecture from scratch without worries about complexity or how experimental it is or even how long it'll take, and yet they don't go with a language that'll solve a whole other class of problems? Seems like an odd choice. Maybe they're just making use of the existing C++ talent pool at Google.
- nicoburns 6y agoLots of the userland pieces are in Rust. I don't think Rust gives you much advantage for kernel code (esp. in a microkernel), because most of it is unsafe anyway. And Rust has some missing pieces for this kind of code (for example, using custom allocators on a per-data structure basis is still difficult).
- Iolaum 6y agoI wonder if that's true for RedoxOS microkernel [0]? I m not technical enough to make the comparison myself. [0]: https://gitlab.redox-os.org/redox-os/kernel https://gitlab.redox-os.org/redox-os/kernel
- qchris 6y agoI'm not a developer on it, but I've been following the development pretty closely for a while. IIRC, the lead developer Jeremy Soller states that even though the kernel code does require unsafe blocks, it's actually less common than you might think. I can't find the source, but for some reason I have it in my head that the percent of Redox kernel code that is unsafe sits at somewhere around 30%, which especially considering the actual LoC of the microkernel vs. a monolith, means much easier code coverage. Again, the exact number might be wrong, but I do know that the kernel is significantly less that 100% unsafe code.
- ikeyany 6y agoI would love to see an interactive map of Zircon, similar to the one of the (older) Linux kernel - https://makelinux.github.io/kernel/map/ https://makelinux.github.io/kernel/map/
- t43562 6y agoC++....microkernel....reminds me of Symbian. :-)
- pier25 6y agoA couple of years ago it was believed that Fuchsia would replace Android and ChromeOS. Then, IIRC, it was said in a Google IO that it was just some sort of experiment to test new OS ideas. What do you think is Google's masterplan for Fuchsia?
- kenforthewin 6y agoLike most of their products, I don't think there is a master plan.
- jrsj 6y agoAt the very least I expect to see it used in "IoT" devices like Nest thermostats and stuff like that. Whether it ever replaces ChromeOS or Android is impossible to determine at this point though. Almost every attempt at running Android apps on another platform for compatibility has been a failure. Microsoft seems to have given up on it entirely.
- sk0g 6y agoWouldn't that be where Flutter could come in handy? If the same codebase cross compiles to Android and Fuchsia (hell, even iOS), lack of apps won't be an issue. The Android team doesn't seem fond of Dart/ Flutter, but that's not surprising. Who wants to voluntarily sign their death certificate, so to speak?
- pier25 6y agoI could be wrong, but I imagine at least some people in the Android team would like a fresh start.
- pier25 6y agoI don't know. Fuchsia seems like a sufficiently massive effort to at least have some goal other than experimentation.
- rvz 6y ago
- cletus 6y agoAh, Fuchsia... another of Google's solutions looking for a problem. I remember hearing about it and immediately asking "what is the market for this?" and not being satisfied with the answer. On the one side you have Samsung, who are unhappy enough with their dependence on Google that they'll not likely eat the cost of moving from Android to something else that has no strategic benefit to them (as far as I could tell, anyway). So what does that leave? Google making its own devices. I don't know this to be the case but I strongly suspect the intent was for the Pixel line was (and may still be?) intended to be the spark for Google being a vertically integrated first-party seller of mobile devices. What I mean is these aren't just proof-of-concept or developer devices. The problem there is by doing that they'll hurt their relationships with Android OEMs and it'd take a long time to fill that void, if that's even possible. So where else? The obvious answer is... Chromecast. This is a hardware product Google has had a good amount of success with. It's already first-party. A recently leaked report [1] seems to indicate that the next Chromecast will be Android TV. That is (IMHO) bad news for Fuchsia. You have to also take into account that during the time Fuchsia has been around (which must be 4+ years by now?) there's been a change at the top with Sundar replacing Larry. That's always a dangerous time for high-profile and high-cost (literally $billions) projects with no customers. Sundar came from Chrome. Fuchsia didn't. You have to ask questions about who was the original (SVP+) cheerleader who got it off the ground and funded it? Was larry on board? Is Sundar/ Does that sponsor enjoy the same support under Sundar that they did under Larry? I don't know the answer to these questions, just that they matter. marissa Mayer's departure from Google was largely a product of a change at the top as she enjoyed Eric's favour but all signs pointed to Larry not being as big as a fan. Fuchsia probably should've been called Graphene. Graphene can do everything but leave the lab, after all. [1]: https://arstechnica.com/gadgets/2020/06/googles-leaked-tv-dongle-looks-like-a-merger-of-android-tv-and-chromecast/ https://arstechnica.com/gadgets/2020/06/googles-leaked-tv-do...
- deathgrips 6y agoThe market is enforcing DRM at the operating system level. Look it up in the documentation, search "DRM".
- 6y ago
- harryf 6y agoDidn't see the article address power management in the context of things that might be running idle in the background. That would seem to be to be a major incentive for an OS that's going be used on mobile, which needs to respond to changes in environment on the move (changing WLAN, network, beacons etc.) Blackberry's QNX ( https://en.wikipedia.org/wiki/QNX https://en.wikipedia.org/wiki/QNX ) is a microkernel architecture and was designed with this in mind - https://www.qnx.com/developers/docs/6.3.0SP3/neutrino/sys_arch/power.html https://www.qnx.com/developers/docs/6.3.0SP3/neutrino/sys_ar... ... > Traditional power management (PM) is aimed at conserving the power of computers that are usually left on. The general-purpose approach to PM for desktop PCs -- or even for "mobile" PCs, such as laptops -- doesn't take into account the specific demands of embedded systems, which can be off (or on standby) much of the time, yet must respond to external events in predictable ways. I don't know if it's inherently more efficient to implement this type of thing with a microkernel but given the iBeacons and similar effectively "failed" ( https://venturebeat.com/2018/10/27/why-android-nearby-ibeacons-and-eddystone-failed-to-gain-traction/ https://venturebeat.com/2018/10/27/why-android-nearby-ibeaco...) due to power and sensitivity, this could be a big enough incentive to start a new OS
- li4ick 6y agoGreg Kroah-Hartman told me it's 40 times slower than Linux, at least that's what he told me 1 year ago. Wonder how that's changed...
- CyberDildonics 6y agoWhat does that even mean? What specifically was slower?
- deleted 6y ago[deleted]
- SV_BubbleTime 6y agoCTRL-F dart No matches. I wonder how many people can look past the kernel when discussing what this is and how it’s different from Android?
- snarfy 6y agoThe technical reasons for Fuchsia to exist are debatable. The real reason it exists is because Linux is GPL.
- cxr 6y agoIf that were true, then Google could have picked BSD or Linux's progenitor Minix, like Apple and Intel did, instead of starting from near-scratch.
- deleted 6y ago[deleted]
- aquabeagle 6y agoGoogle is king of NIH.
- deathgrips 6y agoNational Institute of Health?
- ModernMech 6y agoNot invented here.
- deleted 6y ago[deleted]
- stronglikedan 6y agoOthers seem to think the real reason is DRM, which seems more googlish to me than Linux being GPL.
- m4rtink 6y agoYeah, theiy already are half there with all Android userspace and tooling being under non-GPL and Google Play Services being outright proprietary.
- ThinkBeat 6y agoI fully welcome some more competiton on the operating system front. I am sad to see WindowsNT, Linux and macOS be the only dominant operating systems. My personal very perhaps unpopular view is that Windows NT has a better technial implentation than Linux. Linux does most things well, form small devices to big iron. That is true now. But when it started, it was as a learning experiment, and damn good one too. An amazing achievement. A lot of work my haorsd of people have since built on top of it, replaced things, epanded things, hardening things, adding drivers, etc. And it has come a long way, but to me as an operating system, technically it is not that inspiring. I wish we had maybe 10 competitve opearing systems, some brand new off the presses. I have run Linux in one form or another since the first Yggdrasil release at the end of 1992. (not very early). It was amazing. Running it on my PC at home and it was faster than the terminals at school (well all shared a few servers so always a lot going on, I am sure if you had it all to yourself it would be faster. I guess that is why some people spent the nights there is they had demanding tasks to run, but htye were not a priority to get access to the better, newer and a lot more dedicated hardware. (It was a complicated process). I could do 90% of what was needed at home, woot. I was very happy when I get my paws on the first WindowsNT release back in 1994 I think. I had preordered it. I cold not wait to install it. processor-independent, multiprocessing and multi-user operating system the end of 1992. After having suffered through the pain that was Widows that had a kinda sorts maybe a little multitasking. Finally an improvement. OF course, a lot of my software refused to run on it, or it refused to run it The first Mac I had with macOS was also very cool, since then OpenBSD, I had NextStep when they released it for Intel. Very cool. Anyways I have been waiting since to get a new operating system that levels up the game, as much as WindowsNT did for Windows 3.11, 95, 98, me. I have not yet had that privilege. I had good hopes for Plan9, QNX, a reimplementation fo BeOS that is still ongoing. (I might have the wrong name on that one. I remember a demo I had at the university of a BeBox with the BeOs and how well it multitasked what backed then seemed like very CPU intensive graphics manipulation while playing a video and some other stuff -at the time-... I never got a BeBox and havent run its OS) There have been, and are some solid research OSs but they have never made it out into the real world. WindowsNT, Linux and macOS cannot be all we are given. What replaces them? Where is WindowsNTNT. Will it take quantum computers to become the norm before we get it? Maybe Linux already runs on that too. (if quantum computers ever become viable or even a good fit for everyday boring computer stuff). Give me a new operating system, written from scratch, to implement every secure feature it should have, harden it, eliminate even the possibility of buffer overflows and assorted tasks, or create them so that the elements that are exposed can fail gracefully and non-destructbily and not leak data or allow inputting of data. I forgot about Qubes OS, that is very interesting. Maybe that is it.
- 6gvONxR4sf7o 6y agoWould an OS like this mean really really tough DRM?
- RivieraKid 6y agoI'm more excited about the possibility of a high quality desktop OS rather than the kernel. The Linux kernel is great but a great open-source desktop OS doesn't exist today. Specifically, this product doesn't exist today: - Desktop environment that matches or surpasses Mac OS in quality, performance and UX design. - It includes seamless synchronization between devices. - Apps are sandboxed, similarly to Android or iOS. - There is a clearly defined platform / SDK, like in Android or iOS. If it works in your development environment, it's guaranteed to work everywhere. - You can easily make a commercial product, like in Android or iOS. - It has 10% on the market (or software creators believe it's on the trajectory to get there). I don't understand why Google hasn't done this yet. Of course, the answer could be that such project just doesn't have the required ROI.
- deleted 6y ago[deleted]
- ForHackernews 6y agoI really doubt Google has any interest in building a "great open-source desktop OS". Everything they've done with Android suggests they'll throw releases over the wall, but keep any interesting or useful bits proprietary & closely tied to Google cloud services.
- mav3rick 6y agoAll of Chrome OS is open.
- pwdisswordfish2 6y agoCan you point me to the source code for verified boot?
- pwdisswordfish2 6y agoCan you point us to the source code for verified boot? How about auto-update?
- miohtama 6y agoAssuming most (not all) vulnerabilities are C-style use after free and buffer overflows. If kernel were written in Rust these vulnerabilities would not be issues? Meaning microkernels only make sense in C world. What am I missing?
- yjftsjthsd-h 6y agoAs you implicitly note yourself; even if "most (not all) vulnerabilities are C-style use after free and buffer overflows" - well, if you reasonably can do something to defend against the things that aren't memory issues, then that will catch those. Also, even Rust lets you use "unsafe" code, and an OS will probably contain some; even if it's minimal, even if it's reviewed, you want any extra protections that you can get.
- wackget 6y ago"Fuchsia is a new operating system developed by Google"- and I'm out.
- jcun4128 6y agoHmm I was looking at this expecting GUI screenshots, but interesting non-the less/beyond me my scope at this time but neat to read about.
- malkia 6y agoI can't get fuchsia to work anymore on my Acer device. It used to work just 10 days ago, hopefully gonna fixed soon :) - https://ci.chromium.org/p/fuchsia/builders/global.ci/workstation.x64-release/b8877947158353867984 https://ci.chromium.org/p/fuchsia/builders/global.ci/worksta...? (e.g. I'm compiling for --release workstation.x64 --with-base ... the kitchen-sink)
- mlang23 6y agoSpooky. I predicted the double descriptor read bug before actually seeing the code. I am not an expert, and I definitely haven't written my own USB stack. Still, I wonder why the original code had this problem, given that this seems to be the classical example of how to attack a USB stack. Somehow reminds me what happened when Cisco started to ship a HTTP server with some switches. One of the first bugs was a buffer overflow on URLs longer then 255 bytes ...
- SeanFerree 6y agoLove it!!
- smallstepforman 6y agoEx BeOS developers are the core team behind Fuchsia (Travis Geiselbrecht and Brian Swetland). Travis wrote NewOS which was adapted to be the Haiku kernel (and Travis still hangs around the Haiku IRC channels every now and then). I wouldn't be suprised to see Haiku R2 transition to Fuchsia kernel since they share the same DNA.