4 ms·
Rust has that mapping in the same sense that C does: there exists a fairly simple way to implement every language construct (except maybe for dynamic method inv
by ralfj 4y ago
Rust has that mapping in the same sense that C does: there exists a fairly simple way to implement every language construct (except maybe for dynamic method invocations) in assembly.
However, Rust and C alike have another whole dimension to their semantics, that of Undefined Behavior, which is not reflected in the assembly, and which needs to be taken into account for unsafe code authors (in Rust) / by all programmers (in C). See for example https://www.ralfj.de/blog/2019/07/14/uninit.html https://www.ralfj.de/blog/2019/07/14/uninit.html for what goes wrong when you think of C as just a macro assembler.
- j-pb 4y agoRusts entire trait model is a pretty big deal. The main issue is with memory semantics however, stuff like tagged 64bit pointers are UB land pretty much immediately. MiniRust solves this by providing an explicit memory interface trait.
- ralfj 4y agoYeah okay, traits are super complicated and C doesn't have anything like that, I admit. It's not really part of how to map instructions to the machine, it's more part of how to figure out which function is even being called at a particular call site.
- Rusky 4y ago> The main issue is with memory semantics however, stuff like tagged 64bit pointers are UB land pretty much immediately. MiniRust solves this by providing an explicit memory interface trait. But this is no different from C! The way C programs interact with memory is defined in very similar terms to MiniRust's memory interface trait, using "objects" with some rules for which pointers are allowed to interact with which objects. In both C and Rust, if you want to do pointer tagging or bit packing, you need to consider the language's rules carefully- this does not mean you cannot do it in either case, only that you are stepping close to the boundary of what is supported.
- j-pb 4y agoYes, hence my delight at the creation of MiniRust.
- ralfj 4y agoTo be clear, MiniRust doesn't change any of the rules Rust has, it makes them precise. 64bit tagged pointers are possible in Rust, you just have to do it right, and ideally one day MiniRust will spell out precisely what "right" means. (Maybe that's what you meant, it wasn't entirely clear.)
- j-pb 4y agoYeah that's what I meant. I'm completely fine with difficult semantics in weird corners of the language. I just want to know them tho :D.
- SassyThrowaway 4y agoThe distintion between Rust and C looks interesting. Are there any formal (or formal-ish) grounds for saying that only authors of unsafe code need to be aware of Undefined Behaviour in Rust? With MiniRust, would it be plausible that some sort of "black-box abstraction" theorem could be proven, in a way that makes "safe" code depending on "unsafe" code insensitive to undefined behaviours?
- ralfj 4y ago> Are there any formal (or formal-ish) grounds for saying that only authors of unsafe code need to be aware of Undefined Behaviour in Rust? Yes. It's called type safety / type soundness: you cannot cause UB in safe code. I literally did a PhD on that topic: https://research.ralfj.de/phd/thesis-screen.pdf https://research.ralfj.de/phd/thesis-screen.pdf