4 ms·
> Rust didn't protect me from that, and those are the kind of vulnerabilities that we'll continue seeing regardless of language. It didn't on its own, but it i
by mcronce 4y ago
> Rust didn't protect me from that, and those are the kind of vulnerabilities that we'll continue seeing regardless of language.
It didn't on its own, but it is worth noting that with type-safe languages, you can protect yourself from this by encoding that invariant into the type system.
Using Rust as an example, take a &std::path::Path (or &camino::Utf8Path or whatever) in your public API; have custom InternalPathBuf and InternalPath types that perform validation to ensure they aren't using relative paths to "break out" during construction, and then pass those around in your internal API. Bingo bango, now there's no way (short of transmuting, an `unsafe` operation) to pass invalid paths to the functions that hit the filesystem without a compile error. No redundant runtime checks required, and no need for you as the developer to keep track of which codepaths have already validated a Path and which haven't.
I'm sure you already know this, and I would imagine that Java can do the same, but it's a big step above languages like Python where you can do whatever you want to anything you want.
EDIT: lol while I was typing this you made a post about the same thing below.
- estebank 4y agoGreat minds and all that :) I guess it is also an often used square peg that fits really nicely in the square Rust typesystem hole (no, not talking about those typed holes, haskellers).
- scns 4y agoThis technique is mentioned in the article. It is called the Typestate pattern: http://cliffle.com/blog/rust-typestate/ http://cliffle.com/blog/rust-typestate/