4 ms·
You get rid of bugs by working hard and testing, not language features. I feel like the safety that Rust offers is balanced out by the complexity it introduces
by jonnypotty 6y ago
You get rid of bugs by working hard and testing, not language features.
I feel like the safety that Rust offers is balanced out by the complexity it introduces. I don't understand why anyone would rewrite in Rust to try and get rid of bugs. You never get a more reliable product after this process.
- thesuperbigfrog 6y ago>> You get rid of bugs by working hard and testing, not language features. Hard work and testing do not solve all problems. There is a certain amount of inherent complexity in system-level and high performance application development that is not guaranteed to disappear through hard work and testing alone. >> I feel like the safety that Rust offers is balanced out by the complexity it introduces. Rust is merely exposing the complexity that is inherent to system-level and high performance application development. The same problem exists whether you use C, C++, Rust, or other programming languages that target system-level and high performance applications. The difference is that Rust points out the problems instead of the C / C++ approach of "the developer knows what they are doing".
- ddevault 6y agoTo some extent, Rust exposes the complexity inherent in systems programming, through features like the borrow checker. However, it's disingenous to say that all of Rust's complexity is a reflection of complexity inherent in systems. Rust is a very complicated language, much more so than is strictly necessary to achieve its goals. It has a lot of language features which have nothing to do with addressing the complexity of systems.
- thesuperbigfrog 6y agoI agree that Rust is opinionated and complex. But most of the other widely-supported programming languages (that I use) for low-level and embedded development are also opinionated and complex: C++ and Ada. C is obviously not as complex, but it that is because it offers so much less. Depending on what is needed, C may be a great choice, but it generally means bringing or creating a bunch of library code for string-handling, data structures, etc.
- ddevault 6y ago>C is obviously not as complex, but it that is because it offers so much less. Depending on what is needed, C may be a great choice, but it generally means bringing or creating a bunch of library code for string-handling, data structures, etc. Yes, water is wet. I think that Rust is a great alternative to C++, but I wasn't using C++, either. Part of what makes C good and desirable for those of us that use it is that very simplicity which Rust eschews.
- Thiez 6y agoWhich features would you remove?
- pornel 6y agoThere are projects like Chromium that work extra hard, and yet they keep having memory safety bugs. Do they need to work harder? Get better programmers? Take security more seriously? Check out slides from this talk: https://www.usenix.org/conference/enigma2021/presentation/palmer https://www.usenix.org/conference/enigma2021/presentation/pa... At some point you have to admit that the language is the problem. Eliminating entire classes of bugs by construction is much more effective than testing for them. For example, sum types prevent most cases of unexpected nulls and uses of returned values without error checking. Languages can't eliminate all bugs, but the more they can prevent, the more you can focus on testing the rest.
- jonnypotty 6y agoI agree that trying to eliminate a class of bugs through language design is a good thing to try, absolutely. I just mean to say that the idea that you inherently make your software more reliable by "rewriting in Rust" is false. I don't contend that it could have benifits but I think to some extent you swap one set of problems for another and maybe in a language you don't understand as well as the one you're coming from.
- pornel 6y agoI have first-hand experience that yes, Rust does make software more reliable. It noticeably changes the class of bugs you deal with. The low-level bugs like memory corruption or dangling pointers disappear. You're left dealing with mainly high-level issues, like features not implemented up to the spec, and deficiencies in the program architecture or algorithms (which you still have in any language). It's not some Ying/Yang balance of force or a contract with the devil where getting rid of sneaky Undefined Behaviors must be paid for with another evil. In C I've struggled with multi-threaded software, and even relatively tame solutions like OpenMP ended biting me. OTOH I haven't had to debug a data race in Rust yet (I've caused a bunch of deadlocks, but these are relatively easy). In C, despite my best efforts, I've occasionally had buffer overflows, leaks, and UAFs. In Rust I've had these only when interacting with C libraries via FFI. You could probably say that my C bugs were my fault, and I'm just not a good C programmer. Well, I haven't got any smarter, but I'm a good Rust programmer.
- nine_k 6y agoBy working hard, testing, and moving very slowly. This is how you build pyramids. If you want to build something taller and in 1% of the time, you relegate most of the work to machines.
- Ar-Curunir 6y agoEr every major tech company regularly reports that 70% of vulns in their C/C++ code bases are memory-safety related. How would rewriting in Rust, a language where those bugs are impossible, not prevent those bugs?