9 ms·
Alpine Linux: Proposal to move Rust to main
- Corrado 5y ago>"With the introduction of Rust to the base system, it may be desirable to oxidize certain components which have high security value in the system." This is such a great way to phrase this activity; I really hope it catches on with other projects.
- Waterluvian 5y agoDo you mind explaining what it means to you and why you love it? My guess is this means “help fuel the advancement of…” but I’m having a slow day. I get that there’s also a pun there I think?
- alderz 5y agoMetals get rust by an oxidation process.
- SV_BubbleTime 5y agoI’m not Latin expert, but I think iron, or ferus metals are the only ones that “rust”. Raw aluminum starts oxidizing the moment air hits it, anodizing is specially oxidizing aluminum then dying it, and of course this is more true for metals like potassium that dull while you are looking at them, but I’ve never heard anyone say these metals “rust”, they oxidize.
- ithkuil 5y agoThe word "rust" has Germanic origins, with the meaning red/reddish. Latin rubigo (rust) also derives from the word for the color red. They may have a common ancestor (I don't know)
- SV_BubbleTime 5y agoGood one, I just assumed Latin. You’re probably closer with Germanic. Still, reddish, we’re likely back to ferrous metals.
- djxfade 5y agoIf iron oxidizes, it turns in to rust
- hutzlibu 5y agoAnd then the oxidized layer protects the rest of the iron.
- ClumsyPilot 5y agoThis is how weathering steel works, but for all other cases the instructions are to remove the oxidized layer and apply a protective coat of paint, because rust is typically pourous and provides no protection, but traps moisture. Also stainless steel has an oxidised protective layer, but its transparent so we don't call it rust
- kaladin-jasnah 5y agoNot OP, but I think "oxidize" here would refer to... rewriting the components in Rust.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- cogburnd02 5y agoI'd assume it meant 'rewrite in rust.'
- bluejekyll 5y agoIt probably means different things to different people. Usually when I see the term "oxidize" it tends to mean rewrite critical parts of software, but not necessarily the entire thing (like swapping out the TLS library in a C implementation for one in Rust, but the rest of the C program remains the same). This would be different from rewriting the entire program in Rust.
- boulos 5y agoDo you specifically mean "oxidize"? If so, that's already the term. If not, did you mean the "high-security value" part? Edit: https://wiki.mozilla.org/Oxidation https://wiki.mozilla.org/Oxidation is an example of the history of the term, though amusingly it doesn't show up on https://en.wikipedia.org/wiki/Rust_(programming_language) https://en.wikipedia.org/wiki/Rust_(programming_language)
- patcon 5y agoI also think it's neat. My read of it was that they were saying it like "hardening at the surface", e.g., https://www.sciencedirect.com/topics/materials-science/surface-hardening https://www.sciencedirect.com/topics/materials-science/surfa... Though technically oxidization can either strengthen or weaken a surface, so it's not a perfect phrasing, if so
- nsajko 5y agoI don't know what do you like about the phrasing, but it's not really friendly. The word "oxidize" used like that is clearly a Rust community slang, so it signals that the author identifies with the (a?) Rust community, but it also has the effect of alienating those who are not members of the subculture. Apart from that, I find it strange that people are so brazen with the whole "rewrite stuff in Rust" agenda.
- alias_neo 5y agoI'm not a member of the Rust community (yet), but there was no great leap to understand the oxidation "in-reference", it may very well be community slang, but the link between oxidation and rust in the English language is not at all misunderstood. As for the agenda of re-write everything in Rust, I cannot comment; as a software engineer I love re-writing things in my new favourite language of the day, so my judgement is clouded.
- bluejekyll 5y agoI read that comment not as "re-write everything in Rust", but more "rewrite a subset of components in Rust where it might help with security and resiliency". Rust can certainly help with the latter, but very few projects will ever have the funding or time to achieve the former.
- zozbot234 5y agoWell, they have to start somewhere. It makes sense that they would be picking the lowest-hanging fruit.
- darig 5y agoI'm not a member of the subculture. It took me half a second to figure out what they meant, and I thought to myself, "clever". Rust community seems like good people. Then, I read your comment and thought to myself, "nope, just a bunch of a infighting retards, just like everywhere else". Apart from that, you suck.
- 5y ago
- jml7c5 5y agoIncidentally, the inspiration for the name may be more due to rusts (the fungi) than to rust (oxidized iron). See: https://www.reddit.com/r/rust/comments/27jvdt/internet_archaeology_the_definitive_endall_source/ https://www.reddit.com/r/rust/comments/27jvdt/internet_archa...
- olingern 5y ago> It is assumed that by following the steps in this proposal that Alpine users will be presented with a functional Rust toolchain which has a maintenance window of 2 years, that is also supportable by the Rust community through its normal support channels. I’m struggling to see the benefit of moving from community to main. It seems more symbolic and geared towards making certain guarantees for end users, but it’s hard to grok that
- EwanToo 5y agoI think without that commitment, it's hard for the overall Alpine distribution and other teams working on it to use Rust as part of their toolchain.
- RcouF1uZ4gsC 5y ago> I’m struggling to see the benefit of moving from community to main I think this is about using Rust in the Alpine distribution itself and having core components actually use Rust.
- edoceo 5y agoAt this point it's just getting ready to have the future option of more core stuff in Rust. Step0:tooling; Step1:packages
- bredren 5y agoThere was a thing in February where Python cryptography required rust, which broke docker-compose installs via pip. [1] There was a fair amount of back and forth about version pinning—it affected a lot of builds. Even the issue on the crypto package about it was fairly tense. Iirc, the dependency was rolled back. [1] https://github.com/docker/compose/issues/8105#issuecomment-775239515 https://github.com/docker/compose/issues/8105#issuecomment-7...
- gpm 5y ago> Iirc, the dependency was rolled back. I am fairly certain it was not, e.g. see this comment (or just notice that there's still rust code in the codebase) https://github.com/pyca/cryptography/issues/5771#issuecomment-775990406 https://github.com/pyca/cryptography/issues/5771#issuecommen... (Edit: Changed link to a better one)
- reaperhulk 5y ago(I'm one of the cryptography authors) We did not roll back our dependency, no, although our current release (3.4.x) allows you to disable Rust compilation via an environment variable specifically so we could understand where in the ecosystem challenges would occur. Our next release (now 35.0 based partially on feedback from the community around our unusual versioning) will hard depend on it for all X509 ASN.1 parsing. During the months since we did our first rust release, however, the `musllinux` specification and implementation has been finished so we expect to be able to ship binary wheels for Alpine very shortly. I am actually working on that today, with the only remaining blocker being an update to warehouse to allow wheel upload.
- newman314 5y agoI think I ran into this problem while trying to Dockerize ansible to be able to run on ppc64le. For other reasons, I have a need to be able to run an up to ansible on Linux on POWER. I think due to a lack of an available wheel for cryptography on ppc64le, I ended up having to include cargo in the dependency chain and subsequently a pretty large docker image (over 200MB). Ugh.
- pdimitar 5y agoThis might be a little side-topic but IMO Alpine is famous for having a small byte size footprint. I love Rust to tears but it produces fairly huge binaries even in release mode and even with some symbols stripping. So if Alpine also plans to include various Rust tools I'd hope that this will prompt the core team to also work on reducing the sizes of the final Rust binaries. I don't want to sound entitled! I am very thankful to the entire Rust team. And Rust is hugely important nowadays. It's just that when it comes to distributing stuff in Dockerfiles (and fly.io, and several others) the Rust binaries stick out like a sore thumb. :\ They're fairly big.
- dijit 5y agoIs alpine really going for “small” though? I’m not saying they’re not small and haven’t done a fantastic job, but my impression is that this is due to being mostly minimal in the default install; The reason I say this (and I could be wrong) is because the use of musl for the libc means each binary kinda needs to include it’s own libc statically. This must make the binaries huge! Also, you can easily make small rust binaries, it’s Golang (of the two) that produces very large binaries. If you just follow the first two bits of advice from: https://github.com/johnthagen/min-sized-rust https://github.com/johnthagen/min-sized-rust you’ll reduce your binary sizes to near C++ levels.
- AndyKelley 5y ago> the use of musl for the libc means each binary kinda needs to include it’s own libc statically. This is factually incorrect. Musl supports dynamic linking and if you run `ldd` on any binary in Alpine you can see that it dynamically links against musl libc.
- dijit 5y agoAh, fair enough. I did a little more digging and it seems you can dynamically link rust binaries too now: https://github.com/rust-lang/compiler-team/issues/422 https://github.com/rust-lang/compiler-team/issues/422
- LAC-Tech 5y agoAlpines biggest issue isn't that it doesn't have rust in main, it's documentation. `apk` is a great package manager but a lot of it is undocumented and you need to read the source.
- user5994461 5y agoIt's unfortunate that the example given is about supporting the Ansible package. Ansible is a python software and Python doesn't support Alpine.
- int_19h 5y agoPython supports Alpine just fine; indeed, the standard Docker Python images include Alpine variants. If you mean binary wheels, PyPA packaging added support for Alpine wheels a few months ago (https://github.com/pypa/packaging/pull/411 https://github.com/pypa/packaging/pull/411), and auditwheel support for the same just shipped today.