4 ms·
The Rust organization maintains, amongst other things, the Rust specification (called The Rust reference). If someone wants to volunteer the 1000 expert man ye
by volta83 5y ago
The Rust organization maintains, amongst other things, the Rust specification (called The Rust reference).
If someone wants to volunteer the 1000 expert man year required to, say in 10 years (with 100 experts), submit a probably 10 year outdated version of Rust that nobody is using anymore for ISO standardization, they are free to do so. Nobody is staying in their way.
I doubt anyone would care about evolving Rust in a way that's compatible with such ISO specification.
Most people interested in "specification" appear to be interested in doing things that add infinitely more value than an ISO specification, like actually formalizing the language in theorem provers / proof assistants, delivering an operational semantics specification like that of WASM, etc. These deliver almost instantaneous value in that they can be used to analyze existing Rust code for "formal" correctness, can be used to implement interpreters that verify and protect Rust programs at runtime, can be used to verify more aggressive optimizations that make Rust programs faster, can be used to extend the language with new powerful features that solve real problems and are built on a strong formal foundation, etc.
If you look at C and C++, which have millions of users, their ISO process only gives a tiny amount of people a lot of control over the language design and evolution. The only barrier of entry is paying the 1000$/year fee or so (no qualification, "Programming Language" background required, etc.). This type of process sounds to me diametrically opposite to anything Rust stands for.
But yeah, if someone wants to submit some subset of Rust for ISO standardization, create their own sub-community, and live happily ever after, they can definitely do it.
- pjmlp 5y agoIn some domains, if Rust wants a seat at C, C++, Ada table, that will be a required step.
- galangalalgol 5y agoAnd many of those domains are the exact ones rust would be a best fit in once mature. Flight controls, industrial control, medical devices etc. The places that want to eliminate undefined behavior at all costs would be interested in rust, though probably not crates.io.
- volta83 5y agoNot really. Source: I use Rust in automotive where MISRA C is required, and the only thing we needed was to certify it. No ISO standard required. We actually also supplied a "fork" of the MISRA C doc, crossing out ~80% of it, since it was just stuff that is just not possible in safe Rust. We covered the remaining 20% with clippy lints. Most of the certification involved is just basic stuff like "using version control system", "has unit test", "tests run on changes", "uses a linter" (really, as vague as just that...), etc. We tried to explain that we used "miri" to run most of our integration tests on top of an interpreter that detects all undefined behavior, but the current safety processes don't even have a concept for this, so we had to left this point out to pass certification (we still do it, it's just not something that's accounted for). The process allows us to use crates.io crates "as is", even those with "unsafe code", as long as these have tests and we run them with our clippy linters enabled. Basically, you just need to pay an entity to say that you don't have absurdly horrible software practices. That's where C and C++ have set the bar, and this bar is absurdly easy to meet with Rust, given that it has support for unit tests, most code available already has tests, has a linter built in, etc.
- pjmlp 5y agoGood it is working for you, although I think it depends how burocratic the customer and government departments might be in each specific project.
- volta83 5y agoThere are many levels of certification. This project is in Central Europe. A different team uses it in satellite micro controllers in the US, but I am not involved with that. I don't know of any safety certification process that requires the programming language to have an ISO standard specification.
- pjmlp 5y agoThanks for sharing, I don't mean that they have, more from burocratic point of view, like checklists in RFPs, given conformance with stuff like these https://www.highintegritysystems.com https://www.highintegritysystems.com > Supports IEC 61508, IEC 62304, FDA 510K Hence why imagine Rust might need some kind of good for high integrity computing stamp, be it ISO, ECMA, or something else.