6 ms·
Elixir is still safe
- deleted 3y ago[deleted]
- alex_lav 3y ago[flagged]
- Xeamek 3y agoWell duh, that's what the OG article is about, why the author of this one would need to repeat himself
- alex_lav 3y agoThe original article didn't disprove the existence of vulnerabilities though. Is "Concurrency is hard and I think this concurrency model is easier" "proof"? Did you read either article?
- csoups14 3y agoFrom the original "Elixir is Safe" article: > 3. “Shared nothing” concurrency > Item 3 is the killer one for safety. Like two people, two processes cannot share memory; they can only communicate by sending each other messages. This makes impossible an entire class of thread safety issues. "Elixir is Safer" might have been a better phrasing, but you're misrepresenting the contents of the article if you're claiming that it is limited to expounding "concurrency is hard and I think this concurrency model is easier".
- alex_lav 3y agoIs static typing "safe", and have I demonstrated that simply by publishing a blog about bugs in dynamically typed applications?
- Xeamek 3y agoYes, if you demonstrate that entire class of bugs are ommited simply by the language inherently having some feature (like types) then it's a decent argument that this language is safer, or even completely safe [from the specific type of bugs]
- hosh 3y agoI thought binaries (>= 64 bytes) are one of the exceptions to "share nothing" model? They are still immutable though. Also, ETS, which shares data across processes, and may allow multiple writers. Granted, you have to explicitly opt-in for that. And I am assuming we're not considering NIFs, though Rust NIFs makes a lot of sense here.
- zamalek 3y agoLike the students, I assume that the GP hasn't read the original article - which is very clear about what forms of safety it is discussing.
- kaba0 3y agoJust so people don’t get the bad idea, message passing is still prone to the general category of race conditions, just not data races (without shared memory). Though there are runtime tools to detect live/dead locks.
- aeurielesn 3y agoWhat would normally be the process to debunk a published paper? Simply publishing another paper debunking it in the same journal?
- Fomite 3y agoOften journals will accept "letters" in some form or another if the criticism is brief, and do on occasion publish full papers addressing the shortcomings of another. When that fails, usually one would try another journal or two, and after that it's usually some manner of blog posting and social media.
- e-dant 3y agoWithout stepping on anyone’s toes, I think we can agree that “safety” could be broken down a bit. Memory safety, thread safety, fine… but there’s a whole forest past those trees. Is it a safety feature to type-check regular expressions using dependent types? Is Python a security vulnerability because the performance can be unpredictable? I don’t know. Rust, for that matter, doesn’t protect you from running out of memory from leaking data on the heap — or from running out of stack space because your infinitely recursive function doesn’t halt. Maybe that’s not part of memory safety — but that’s my point. There’s a whole safety forest out there. Whenever I read an article about safety in software, it seems like a comfy blanket statement. “This is a nice definition which I will live in.” I just don’t see how it’s so flat.
- rozap 3y ago> I just don’t see how it’s so flat. Because people like making wild and provocative claims to motivate writing a paper for which the conclusion was already decided. Anyone who has used, I dunno, any of programming languages that are being discussed has a more nuanced take, and isn't spending time trying to force all things into Box A or Box B. Elixir/Erlang has a pleasant concurrency model. It does some things well, it does other things less well. It eliminates a big class of bugs, and yet you can still write bugs in Elixir. These sorts of papers are a waste of space on the internet imo.
- devoutsalsa 3y ago“What is sending a message to my process and making it crash?!” “My synchronous reply timed out, so why I am I getting a message after the timeout?!” “Why did deleting my build directory fix the compile error?!” “How do I keep my app from crashing when my supervisor crashed too many times in a given timeframe?!” So many adventures to be had.
- rozap 3y agoPlenty. But I'd take those trivial issues over a blob of microservices any day of the week. In any case, the answer continues to be "it depends". But people will continue to look for "one weird trick" solutions to every problem.
- greatfilter251 3y ago> Practitioner perceptions are formed through personal experience, and not based on empirical evidence The disagreement here is rooted in the empirical worldview. Empirically, "rarely" and "never" cannot be (reliably) distinguished, and so adherents of this worldview fail to distinguish claims which are meant to distinguish them.
- ano88888 3y agoDeciding which i should use : Elixir or Clojurescript or python or nodejs
- Hasnep 3y agoThat really really depends on what you want to do, can you add a bit more information? Also those choices are not mutually exclusive, you can run Clojurescript on Node.js, but you would probably be better off using normal Clojure.
- somecommit 3y agoIf you are asking out of the blue, it's probably you just need to stick with nodejs, that is the most vanilla I think of
- roguas 3y agoWeird set of choices. So clojure and elixir can be your hooks into fp community. To a degree they are similar in being dynamic fp langs with macro capabilities. Python and node are more like "common dev platforms" these days. I would first establish if I am looking for job market utility (both elixir and clojure offer great utility, but job market is more problematic). Yet if you are looking to learn and expand your dev horizons elixir or clojure are great options (I do clojure so a bit biased towards it).