4 ms·
I think `unsafe` would have been more aptly named `compiler_unverifiable`. IMO there would be less apprehension to using `unsafe` when it's needed.
by likeabbas 4y ago
I think `unsafe` would have been more aptly named `compiler_unverifiable`. IMO there would be less apprehension to using `unsafe` when it's needed.
- ZephyrBlu 4y agoAs someone who mainly uses higher level languages, doesn't care for C/C++ and really likes Rust, I'm glad it was named so strongly and that safety and correctness is very important in the community. It creates a strong incentive to only write safe Rust, which is great for the vast majority of people.
- likeabbas 4y agoI think the incentive to write compiler verifiable Rust would be the same as safe Rust, but with less fear for the situations where you do need to bypass the borrow checker such as with cyclical references in graphs (currently doing this right now by re-writing a basic NN in Rust). Even the standard library uses unsafe for certain situations.
- proto_lambda 4y ago> with less fear for the situations where you do need to bypass the borrow checker such as with cyclical references in graphs That's a pretty tricky thing to get right, and with the consequence for getting it wrong being UB, at least a little fear is warranted.
- likeabbas 4y ago`compiler_unverifiable` isn't risky enough for you?
- ZephyrBlu 4y agoIt doesn't have the same connotations as `unsafe`.
- likeabbas 4y agoBut it’s the true definition being stated. Unsafe is subjective, compiler unverifiable isn’t
- ZephyrBlu 4y agoSo? This is like applications adding artificial delay to operations so users aren't surprised they complete so quickly. User understanding is more important than definitional correctness.
- likeabbas 4y agoI don’t understand why you want people to be afraid of code though. It’s just code. We don’t need a scary connotation to make people think they should shoot for completely compiler verifiable rust in every line they can write.
- proto_lambda 4y agoUsers who don't even know the meaning of "unsafe" almost definitely shouldn't be writing unsafe code.
- anonymoushn 4y agoIn this case it would be nice if operations that are type-safe and don't read or write memory at all, such as mm256_shuffle_epi8, were available in safe rust.
- jsheard 4y agoIt's a work in progress, on nightly there is a safe and portable SIMD abstraction under development in std::simd. e.g. "mm256_shuffle_epi8" on X64+AVX2, ARM64+NEON and plain ARM: https://rust.godbolt.org/z/7rjKE93Kn https://rust.godbolt.org/z/7rjKE93Kn It currently only works with constant shuffle masks but dynamic shuffles are on the to-do list.
- anonymoushn 4y agoThis is helpful for the use cases that want to rearrange bytes in a fixed pattern, but it cannot yet express a stream vbyte decoder (out = pshufb(in, shuffle_patterns[len_mask])) or a check for which bytes are in small set of bytes with distinct lower nibbles and the high bit not set (eq(in, pshufb(set, in))) yet. If it's to be portable it needs an extra instruction on one platform or the other because tbl and vpshufb do different things :(
- Yoric 4y ago`unchecked` might be more palatable, but I agree that there is some uncomfortable mismatch between the meanings of "unsafe" and `unsafe`.