5 ms·
Zig is not memory safe and therefore at risk, just like C/C++, of future government legislation that outlaws the use of memory unsafe languages for some or all
by grumpyprole 3y ago
Zig is not memory safe and therefore at risk, just like C/C++, of future government legislation that outlaws the use of memory unsafe languages for some or all projects. The risk of such legislation is not insignificant: https://www.itpro.com/development/programming-languages/369499/move-away-from-memory-unsafe-languages-c https://www.itpro.com/development/programming-languages/3694...
Personally I do not see the point of building an entirely new language and ecosystem that does not fully address this issue.
- quic5 3y agoThat totally misses the point of quality software. What good is memory safety if you medical device crashes because of an out of memory error? What I'm trying to say: There are use cases where areas of safety are required other than memory safety.
- lmm 3y agoThere are use cases where safety beyond memory safety is required. But there are no use cases where memory unsafety is desirable, yet alone required.
- quic5 3y agoThat is absolutely true. But but you can write memory-bug-free code in Zig but you cannot prevent heap allocations in most of the languages listed in the article, making it outright impossible to write certain software in them.
- grumpyprole 3y agoSure one can write memory-bug-free code in x86 assembly too. But how can you prove it? ATS is an example of a low-level systems language where you can prove it.
- ObscureScience 3y agoAs Zig promises "not hidden allocation", I assume you can build your allocator in Rust and then use it for all memory allocation in Zig.
- lmm 3y agoA function that doesn't allocate doesn't mean it's safe. (Indeed if anything the opposite is more likely - copying is safe, if slow, writing to something that was passed in tends to be what breaks).
- ArtixFox 3y agoformalized subsets of x86 assembly exist. Coq can be used as a macro assembler. tools to work with llvm ir exist, x86 can be raised up to llvm ir and proved, kinda bad way tho.
- memefrog 3y agoYou can't prove it in Rust either.
- jdrek1 3y agoWhile that is true, there might be other requirements that prevent memory safe languages from being used. For example not having a heap available instantly disqualifies most of them. Or when you have simulations running where having constant OOB and other checks would be a massive slowdown. Now obviously your code should still be memory safe (because otherwise it's not correct anyway and you should fix the code), but not at the cost of runtime checks.
- memefrog 3y ago>there are no use cases where memory unsafety is desirable, yet alone required. There are plenty of 'use cases' where Rust's guarantees (some vague but unenforceable promises around memory) are not worth the cost of using Rust (a very high cost). This is doubly true if you want to, say, not use any third-party libraries. If you use third-party libraries, you get essentially zero guarantees. And if you don't, you have to reinvent the world - and writing new data structures in Rust is a series of research projects, whereas doing so in C is trivial. There are many situations where guaranteed 'memory safety' (a Rust propaganda term for 'having the guarantees we can provide but not the ones we can't provide') is not very important.
- throwawaymaths 3y ago> But there are no use cases where memory unsafety is desirable, yet alone required. Operating system bootstraps? DMA management/volatile driver access? Doubly linked lists?
- grumpyprole 3y agoMemory safety is one aspect of quality yes, but is there any evidence Zig is a good fit for other quality aspects, e.g. static analysis tooling and correctness proofs? ATS is a low-level language that allows embedded proofs of correctness in the type system.
- johnisgood 3y agoThat article does not even mention Ada/SPARK... So much for safety. :P Yup, there is static analysis with Ada/SPARK and it is great. It is much more general-purpose than ATS, and there are other things in Ada/SPARK that increases safety in general, not only memory safety. For what it is worth, Ada/SPARK has a strong presence in safety-critical domains like aerospace and medical devices, while Rust is gaining popularity in system programming and web development. ^^ I'm surprised that it is not as widespread. That, or lots of misconceptions.
- grumpyprole 3y agoYes Ada/SPARK is a great example.
- TheFragenTaken 3y agoNot to be snarky, but you argument works both ways :). What good is a medical device if it leaks sensitive data, because it had been exploited by a use-after-free?
- nevi-me 3y agoIt sounds like you'd be worrying about n-1 types of safety errors instead of n, which is arguably better.
- Ygg2 3y agoMemory errors are much, much less likely to occur with more memory than use after free.
- bachback 3y agoseriously? "The National Security Agency (NSA) has recommended only using 'memory safe' languages, like C#, Go, Java, Ruby, Rust, and Swift, in order to avoid exploitable memory-based vulnerabilities."
- grumpyprole 3y agoYes seriously. The west is getting hacked and owned on a daily basis. The NSA recommendation shows that governments are starting to identify where the problem is.
- ArtixFox 3y agoah yes the east! The lovers of memory safety. West is getting hacked daily because every country is getting hacked daily.
- DrBazza 3y agolog4shell enters the chat. https://en.wikipedia.org/wiki/Log4Shell https://en.wikipedia.org/wiki/Log4Shell
- pjmlp 3y agoYes, it belongs to the remaining 30% of exploits, when we remove the 70% ones caused by memory corruption.
- dgb23 3y agoAt some level you need languages that are not “memory safe”. Memory safety comes with a cost. Either you pay for a GC runtime (Java) or for reference counting (Swift) or by not being able to express a correct program (Rust). There are plenty of use cases where none of these tradeoffs are feasible. To add, Zig comes with its own story around memory safety. Not at the static type system level and it’s not as comprehensive as other languages.
- grumpyprole 3y ago> At some level you need languages that are not “memory safe”. Perhaps as an escape hatch (unsafe Rust) or a compiler target, but ideally not as a "general purpose language" as Zig is marketed as.
- aldanor 3y ago"Express a correct program" that might end up being incorrect due to programmer's fault. The difference is, you can use unsafe blocks/fns in Rust, in which case it becomes equivalent to C expressiveness-wise; but you can also do the opposite and forbid(unsafe_code) altogether.
- memefrog 3y agoAll programs can be incorrect. You cannot forbid unsafe code. Its use is necessary to implement basic functionality.
- aldanor 3y agoYou absolutely can forbid unsafe code (within a scope of a particular codebases) and some projects happily do it. "The use is necessary" = absolutely not. Lots (most) of projects wouldn't ever need to dip into unsafe code. And then there's another category where authors think they do because "that's how they would do it in C++", but in reality they don't.
- memefrog 3y ago
- BaculumMeumEst 3y agothe united states government is not going to outlaw the use of memory unsafe languages. that is an absurd idea. nothing in your links suggests they would even consider it. "moving the culture of software development" to memory safe language does not mean "we want to put you in jail for writing C".
- grumpyprole 3y agoWhere did you get the idea that jails are involved? Governments are clearly forming a position, if they fund new projects, they are quite likely to enforce that position. That's a significant market already.
- BaculumMeumEst 3y agothey can enforce that position by funding projects that are written in languages that they believe are memory safe. they do not need, or want, to legislate that.
- pjmlp 3y agoFunny that you mention that, EU does sponsor Rust development. "Logical Foundations for the Future of Safe Systems Programming" https://cordis.europa.eu/project/id/683289 https://cordis.europa.eu/project/id/683289 As for US, https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI_SOFTWARE_MEMORY_SAFETY.PDF https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI... "NSA advises organizations to consider making a strategic shift from programming languages that provide little or no inherent memory protection, such as C/C++, to a memory safe language when possible. Some examples of memory safe languages are C#, Go, Java, Ruby™, and Swift®. Memory safe languages provide differing degrees of memory usage protections, so available code hardening defenses, such as compiler options, tool analysis, and operating system configurations, should be used for their protections as well. By using memory safe languages and available code hardening defenses, many memory vulnerabilities can be prevented, mitigated, or made very difficult for cyber actors to exploit."
- dakom 3y ago
- TheRoque 3y agoWhat would happen with existing codebases, sometimes built upon 2 decades of C or C++? Will the we "rewrite everything in Rust" ? lol
- grumpyprole 3y agoMaybe doing it for new projects is better than doing nothing?
- 31tor 3y agoAI will probably find all bugs or re-write all the software in minutes soon enough.
- pjmlp 3y agoNo, we will Rewrite in ChatGPT (or similar), and only architect jobs and the few AI druids that write the tooling will be safe.
- 0xfedbee 3y ago[flagged]
- grumpyprole 3y agoYou might think that, if you live in a small world. I want memory safety, but I am otherwise not a big fan of Rust. Rust tries to be too high-level like C++, making it opaque where allocations are happening. For a low-level systems language, with embedded proofs, I quite like ATS, but Vale is also promising and more like Zig.
- ArtixFox 3y agoThe way zig is designed, I think it will be fairly easy to embed Ada's Spark like proof system in it.
- CyberDildonics 3y agoWhy do you think that?
- graboid 3y agoWhere did he/she even mention Rust?
- johnisgood 3y agoWell, you do not see people mentioning Ada/SPARK whenever memory safety is the topic of discussion, do you? They mention Rust! Well, I do mention Ada/SPARK as much as I can because it is still a much safer language in general than Rust.
- justin66 3y agoI'm sure the federal government's advocacy will aid Rust adoption massively. I mean, look at how Ada's adoption skyrocketed when it received DoD's stamp of approval.
- flohofwoe 3y agoZig enforces much more correctness than C or C++, which also results in much more memory safety, it's just not as extremist as Rust.
- johnisgood 3y agoAnd they have not even mentioned Ada/SPARK... right.
- jmull 3y agoWell, technically, Rust is unsafe, unless they remove “unsafe”. We’re really talking about safety on a continuum, not as a binary switch. Zig has some strong safety features, and some gaps. Well, one notable big gap, UAF. (Perhaps they’ll figure out a way to plug thisin the future? Perhaps by 1.0?) Actually, safety has multiple axes as well. > Personally I do not see the point of building an entirely new language and ecosystem that does not fully address this issue The more safe languages make significant tradeoffs to achieve their level of safety. The promise of zig (I don’t know if it will ultimately achieve this, but it’s plausible, IMO), is “a better C”, including much more safety. For one thing, it has a great C interop/incremental adoption story, which increases the chance it will actually be used to improve existing codebases. The “RIIR” meme is a joke because, of course, there is no feasible way to do so for so many of the useful and widely used vulnerable codebases.
- ksec 3y ago>Well, technically, Rust is unsafe, unless they remove “unsafe”. I am somewhat surprised this is being mentioned. And the whole thread is without the usual people complaining it about unsafe. Interesting changes happening on HN.
- al_be_back 3y agoIF a Gov subcontracts a company to design + impl a system, they as Customer (if you like) have the right to request specifics; maintenance & integration with the wider ecosystem is a massive concern in this case. That's not "legislation" though.
- templix 3y agoI ditched Rust a year ago in favor of Zig and have not regretted since Number of memory bugs in several fairly huge projects: 0 Zig is way more maintainable, leads to less code which translates to fewer bugs How about that?
- throwawaymaths 3y agoSomeone will eventually build a static safety checker for zig. No reason memory safety has to be in the compiler.