14 ms·
I think bringing Rust into Linux was a really bad idea. IMO Rust has yet to prove it isn’t another overly complicated C++ waiting to make projects almost incomp
by ilovecaching 4y ago
I think bringing Rust into Linux was a really bad idea. IMO Rust has yet to prove it isn’t another overly complicated C++ waiting to make projects almost incomprehensible to understand. It does not provide the same easy ramp up that C provided when working on most of the system software stack on Linux. There’s also still too few standalone projects using it to consider it a proper candidate for folding into such a large project forever.
I am surprised Linus agreed to this given that he doesn’t like C++ and usually errs on the side of clear over clever, and we have yet to see tangible benefits of using Rust.
- sedeki 4y agoI have worked as a C++ dev, but am definitely not a C++ expert by any means. My take however is that C++ is inherently a complex language due to deliberately not sacrificing backwards-compatability of the syntax and semantics, which has been creating a mess as the language has evolved: there are many, many things to define semantically in order to "fit" a new piece in this old already-elaborate puzzle that is the C++ standard. You cannot say the same thing about Rust. Please correct me if you see things differently.
- noselasd 4y ago> You cannot say the same thing about Rust. At least not yet. My fear is it's _very_ easy to fall in to the same trap as C++ has, and become a big mess. Scott Meyers have a very nice talk here: https://www.youtube.com/watch?v=KAWA1DuvCnQ https://www.youtube.com/watch?v=KAWA1DuvCnQ about all these traps and pifalls that we have to deal with in C++. That said, I'm starting a bit with rust and enjoy it so a lot, especially the tooling alone is worth it - and if I never have to write another line of C++, I would be very happy (ofc the real world argues I have a lot of C++ code that will need maintenance).
- cassepipe 4y agoWhen I tried Rust I came from Python and it was clearly too much for me to comprehend but after 2 years of C programming and 1 year of C++ programming, the problem Rust tries to solve make a lot more sense and I know understand the problem it's trying to solve. I am trying to use it again things like the borrow checker and Traits now make a lot of sense to me. I am also looking forward at not having to write C++ again. I haven't looked into C++17 and beyond though I must admit.
- phkahler 4y agoIf you stick to a subset of C++ it's not so ugly since that's before all the new stuff got bolted on. Rust might undergo similar uglification, but the clean subset should still be there and is better than any clean subset of C++. I still hope that doesn't happen though.
- blub 4y agoGive it 10 years and people will feel similarly about Rust. They’re both just super-complicated languages. Some devs thrive on that, but most people can’t and shouldn’t have to. And you can see that contrary to what some in the Rust community are saying, there’s a push to use Rust for web. Bonkers.
- hgomersall 4y agoDo you write in Rust much, or do you have your own blub language?
- blub 4y agoNot much, have enough on my plate with C++.
- hgomersall 4y agoIf you get the chance, do take a serious look at Rust (as in, write something significant in it). You might be surprised at just how suitable it is for high level stuff.
- blub 4y agoI (re)wrote a < 1kloc program in it from C++ and I found that it had its good and bad parts, like everything. But there’s too much overlap with C++ and not enough projects. IMO Rust has proven that it can survive, but by far hasn’t reached enough popularity to justify a switch and keeping two complex yet similar languages in ones head is unwise. So I’d rather focus on Go and Python which actually bring something complementary to the table.
- hgomersall 4y agoI guess I had the benefit of not having the C++ experience baggage (mostly C and Python) ;)
- sumtechguy 4y ago
- recuter 4y agoThe way C is written in the kernel is really unlike the C you typically encounter in the wild. Try reading it and tell me how comprehensible you find it and how easily people ramp up into kernel contributions. and we have yet to see tangible benefits of using Rust Is that the royal we? Have you actually (successfully) tried writing something in it? I am surprised Linus agreed to this given that he doesn’t like C++ Maybe Linus has lost the plot after decades of careful stewardship. Or maybe it is an opportune moment for a closer second look. Who knows. Sometimes that is what I try to do when my expectations are subverted if I care enough about the subject.
- megous 4y agoIt's quite like any other C codebase, especially the driver code Rust is targetting initially.
- bigfishrunning 4y agoThe main problem with C++ is it's insistence on being an almost-superset of C. Rust has no such hang-ups
- dezgeg 4y agoCan you share some concrete examples where you think "kernel C" is really unlike normal C? Sure, there will be couple of additional things the programmer needs to be aware of (e.g. special care needed when inside interrupt handlers and when holding spinlocks) but overall it doesn't visually look that different.
- recuter 4y agohttps://docs.kernel.org/process/coding-style.html https://docs.kernel.org/process/coding-style.html
- skemper911 4y agoMacros, the ugly side of C, Rust. Shame Zig didn't come before rust, imagining kernel data structures written in Zig, brings a smile. Right on point that kernel style C is its own unique world, with a steep learning curve, so lets add Rust with its own steep learning curve. Rust readability isn't any better than kernel C, guess I'm missing the 10,000 hours of reading Rust. ./KISS
- nu11ptr 4y ago> IMO Rust has yet to prove it isn’t another overly complicated C++ waiting to make projects almost incomprehensible to understand Rust is relatively easy to read I think. The borrow checker is what gets all the hate, but that is an issue for writing, not reading. If anything, things like pattern matching make otherwise long if chains easier to read IMO > we have yet to see tangible benefits of using Rust Rust eradicates whole classes of errors in safe code, and unsafe code is more safe than the equivalent C or C++. The only theoretical way to not have a tangible reduction in errors would be to believe that a C programmer is good enough to never commit the error classes Rust eradicates, and believe Rust usage would increase the number of logic errors. This seems incredibly unlikely to me.
- nyanpasu64 4y agoUnsafe Rust that exposes & or &mut to safe code is more unsafe than the equivalent C or C++.
- hgomersall 4y agoPerhaps you can clarify - if you're saying unsafe rust that performs undefined behaviour is unsafe regardless of the safe bits, then you'll have no disagreement. If on the other hand you're suggesting that it's possible to have well defined unsafe rust that exposes a lack of safety across the unsafe boundary, then you're going to have to explain a bit more...
- nyanpasu64 4y agoIn Rust, casting a *mut to a &mut (the standard method of allowing safe code to mutate an object) is unsafe if other &, &mut, or Pin<&mut> exists, regardless of whether or not you commit a use-after-free. In C++, the equivalent code interchangeably using * and & is safe until you actually commit a use-after-free. This makes it harder to write correct Rust code mixing safe and unsafe code.
- hgomersall 4y ago
- blub 4y agoThe positive aspect of all of this is that it will be an interesting case study in what happens if you shove a square Rust into a round Kernel.
- spookie 4y agoI guess that's going to be the bigger accomplishment on all of this. People keep talking about memory safety ad nauseam, but I think everyone is missing the point.
- rjsw 4y agoI hope none of the DRM drivers switch to using Rust, would make it even harder to use them in other operating systems.
- sanxiyn 4y agoAsahi Linux DRM driver is already written in Rust, so other operating systems would need to port it to C.
- biorach 4y agoIt's not possible to use the DRM drivers in other operating systems. Or are you talking about NVidia's closed source drivers?
- sanxiyn 4y agoIt is in fact possible. "Linux KPI is the FreeBSD effort for providing a Linux compatibility interface to make it easier to bring Linux DRM drivers to FreeBSD and for them to remain up-to-date against Linux upstream." https://www.phoronix.com/news/DRM-Next-KMOD-On-FreeBSD-11 https://www.phoronix.com/news/DRM-Next-KMOD-On-FreeBSD-11
- biorach 4y agoAh... Well FreeBSD on the Apple M1 is highly unlikely, so this is going to be a non-issue in the near term. And none of the existing DRM drivers are likely to be rewritten in Rust. In the medium term, maybe some in-kernel dependencies might end up getting rewritten in Rust, or maybe some brand-new architecture may have a greenfield development in Rust. I'm going to speculate that FreeBSD on commodity graphics hardware is safe enough for a few years, but that longer term Rust compatibility might have to be added to the Linux KPI.
- sanxiyn 4y agoFreeBSD on Apple Silicon is in fact a work in progress: https://wiki.freebsd.org/AppleSilicon https://wiki.freebsd.org/AppleSilicon
- sanxiyn 4y ago> we have yet to see tangible benefits of using Rust Tell that to Asahi Lina: https://twitter.com/LinaAsahi/status/1577667445719912450 https://twitter.com/LinaAsahi/status/1577667445719912450
- rjzzleep 4y ago> I think bringing Rust into Linux was a really bad idea. IMO Rust has yet to prove it isn’t another overly complicated C++ waiting to make projects almost incomprehensible to understand. Isn't that already the case? Rust now is very different from Rust in the early days and is also exponentially more unintuitive. Maybe that's fine, I don't know, but I'm personally very much struggling with its quirks.
- kibwen 4y agoWhat early days is this referring to? In any case, regardless of one's opinions on Rust's overall difficulty, I find it difficult to argue that the language's ergonomics have done anything but improve over time.
- biorach 4y ago> Rust now is very different from Rust in the early days Rust pre 1.0 kinda doesn't count. The whole point of 1.0 is that there is a guarantee that there will be no more dramatic changes to the language. > exponentially more unintuitive Almost nothing about any programming language is really intuitive. You mean that C uses paradigms that are intuitive to you due to your experience with it or similar languages. Rust uses different paradigms that are more immediately intuitive to people with experience in functional languages. And the borrow checker. Which is probably immediately intuitive to nobody, but worth it.
- rowanG077 4y ago
- wiseowise 4y agoThe issue of C++ is not complexity. It’s issue is that despite being complex it is still unsafe.
- thesuperbigfrog 4y ago>> we have yet to see tangible benefits of using Rust. As a long-time C and C++ programmer, I have to disagree. C and C++ have been great and so much software has been written using them, but the time has come to move on. The majority of software security bugs are due to the lack of controls in C and C++. This is not an opinion or an anecdote, it is a fact: https://www.zdnet.com/article/microsoft-70-percent-of-all-security-bugs-are-memory-safety-issues/ https://www.zdnet.com/article/microsoft-70-percent-of-all-se... https://www.zdnet.com/article/chrome-70-of-all-security-bugs-are-memory-safety-issues/ https://www.zdnet.com/article/chrome-70-of-all-security-bugs... https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI_SOFTWARE_MEMORY_SAFETY.PDF https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI... Operating systems need to be secure. Operating system kernels even more so. The Linux kernel could move to Rust or Ada or Nim or something else, but keeping it in C is an invitation for continued security problems: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=%22linux+kernel%22 https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=%22linux+ke...
- sigzero 4y agoI doubt very much if it is going to move off of C. Linus isn't going to do that.
- thesuperbigfrog 4y ago>> I doubt very much if it is going to move off of C. Time will tell, but Rust support for use in Linux kernel development is increasing. If it solves problems and is easier to use, it will gain traction and see wider adoption.
- Analemma_ 4y agoLinus is more pragmatic than you think. He's cautious and resistant to faddish trends, but he can be convinced. I think Rust has a ways to go before it's ready for the kernel proper (the architecture support being the big thing), but if it does get there I think he can be open to the idea of a switchover.
- krelian 4y ago
- dahfizz 4y agoI am excited for the future of rust, but I am worried about where the language is today. It is simply a young, unstable language. There are lots of features you need the nightly compiler for, and there are large breaking changes with every edition every few years. This is fine for many use cases, but not for the Linux Kernel IMO.
- biorach 4y ago> It is simply a young correct > unstable incorrect > There are lots of features you need the nightly compiler for inaccurate There are lots of features that are currently nightly-only. you may or may not need these depending on what you are doing. In particular kernel development does require quite a few nightly-only features, but there is no reason to think that all of these won't make it into stable rust in due course. > and there are large breaking changes with every edition every few years totally incorrect
- randallsquared 4y ago> inaccurate ...but then you go on to agree?
- samus 4y ago> there is no reason to think that all of these won't make it into stable rust in due course.
- dahfizz 4y agoI feel like you agree with me. All these things that the kernel needs from rust will slowly be stabilized over the next few years. The features will land in future editions of rust. Upgrading to those new editions will involve breaking changes.
- biorach 4y agoYes, but there is no rush to migrate to the new edition - once stabilised the new features will continue to exist in nightly, in the same form as in stable. And yes, presumably at some stage there will be a migration of the kernel from nightly to stable. There may be breaking changes. This will be a one time thing, and, (based on the current difference between nightly and stable and rate of change) not much more of a hurdle than changing C editions or gcc versions. See my other comment.
- oxff 4y agoI find it funny they got it added to Kernel when there is really no good documentation or experience with how the two different memory models will mix together? Maybe I'm missing something obvious.
- tux3 4y agoHere's a pretty good blog post that discusses how the memory models could interact: https://paulmck.livejournal.com/65341.html https://paulmck.livejournal.com/65341.html My understanding is that it might not be entirely settled yet, and is still being discussed. That could explain why there isn't much solid documentation written yet
- biorach 4y agoThere's plenty of discussion out there - just not much in the way of nicely formatted documentation. There is a consensus on the way forward, but it remains to be seem how many tricky details can be resolved.
- deleted 4y ago[deleted]
- School-Cotton 4y agoI have used both Rust and C++ professionally (Rust for nearly four years now) and the advantages of Rust over C++ are still absolutely clear. I’m not a Rust fanboy (I think it’s great in some ways and bad in others) but comparing it to the monstrosity that is C++ is simply wrong.
- plaguepilled 4y agoI use both and Rust is FAR better for anything requiring memory safety. The supposed ramp up is minimal. Have you actually tried Rust or are you just copying talking points?
- klooney 4y agohttps://twitter.com/linaasahi/status/1577667445719912450 https://twitter.com/linaasahi/status/1577667445719912450 the people porting Linux to m1 macs seem bullish