2 ms·
> when they knowingly claim that they have never even heard of, let alone made, even a single high assurance, robust system in Rust. Huh?! They said you can't
by throwawaygh 5y ago
> when they knowingly claim that they have never even heard of, let alone made, even a single high assurance, robust system in Rust.
Huh?!
They said you can't build safety-critical software in Rust because it's not certified.
Not all high assurance software is safety-critical, not all correct software is certifiable, and FOR SURE not all certifiable software is correct.
> evidence of repeated success at delivering such systems in real-life adversarial environments and succeeding at audits and verification efforts that are demonstrably passed only by robust systems.
Can you name one such process? The old auto and aero software standards from the 90s/early aughts are crufty, have demonstrably failed on any number of occasions, and leave much to be desired.
(BTW, "verification" in those standards means something totally different from what "verification" means to software experts today.)
The Rust compiler and ecosystem would need a thorough audit before its use in safety-critical settings, but I have no doubt that this audit will happen and that when it does the evidence generated y that audit will blow way past the standards applied to MISRA C/Ada/etc.