5 ms·
Considering how much I got downvoted no I don't want to comment more about this. But I'll let you ponder why while using rust has you could get a use after free
by ArrayBoundCheck 4y ago
Considering how much I got downvoted no I don't want to comment more about this. But I'll let you ponder why while using rust has you could get a use after free sometimes https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45720 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4572...
- hyperpape 4y agoHere's the commit: https://github.com/jeromefroe/lru-rs/pull/121/commits/416a2d480547f6b88ef6d23aa34b1fea292f65fb https://github.com/jeromefroe/lru-rs/pull/121/commits/416a2d.... I don't think this does much for your initial claim. Take the most generous reading you can--Rust isn't any better at preventing UAF than C/C++. That doesn't make safe C/C++ a thing, it means that Rust isn't an appropriate solution.
- ArrayBoundCheck 4y agoYou missed the point. Just like the author did when he disqualified all the C++ tools Writing unsafe code and removing tools "because production" gets you unsafe code as shown in that rust cve
- XelNika 4y agoWith Zig and Rust you have to explicitly opt-out with `ReleaseFast` and `unsafe` respectively, that makes a big difference. Rust has the added safety that you cannot (to my knowledge at least) gain performance by opting out with a flag at compile-time, it has to be done with optimized `unsafe` blocks directly in the code. Lazy C++ is unsafe, lazy Zig is safe-ish, lazy Rust is safe. Given how lazy most programmers are, I consider that a strong argument against C++.
- ArrayBoundCheck 4y ago[dead]
- Arnavion 4y ago>It has nothing to do with opting out. It does. The original code compiled because the borrow is computed using `unsafe`. That `unsafe` is the opt-out. >Zig, Rust and no language saves you when you write incorrect unsafe code. My original point is disqualifying c tools is misleading and everything suffers from incorrect unsafe code And the other people's point is that if one language defaults to writing unsafe code and the other language requires opting out of safety to write unsafe code, then the second language has merit over the first.
- Ar-Curunir 4y agoSure, but unlike C/C++, in Rust my entire codebase is not enclosed in a gigantic unsafe block
- alfiedotwtf 4y ago> Rust isn't any better at preventing UAF than C/C++ Maybe I'm missing something here?