12 ms·
Bare-metal Rust in Android
- frankjr 3y agoIs there similar effort from Apple?
- monocasa 3y agoI don't believe Apple has embraced Rust the same way Google has. Particularly their firmware is still very based on C.
- dagmx 3y agoSpecifically a dialect called Firebloom (supposedly anyway) https://saaramar.github.io/iBoot_firebloom/ https://saaramar.github.io/iBoot_firebloom/
- mrpippy 3y agoPossible related to the ‘-fbounds-safety’ feature they’ve proposed for Clang https://discourse.llvm.org/t/rfc-enforcing-bounds-safety-in-c-fbounds-safety/70854 https://discourse.llvm.org/t/rfc-enforcing-bounds-safety-in-...
- jonpalmisc 3y agoFirebloom == `-fbounds-safety`
- jonpalmisc 3y agoFirebloom is more of a custom compiler/toolchain than a dialect of C—apart from annotations to relate pointer+length parameters, etc., it is still just C.
- jd3 3y agoReminds me of this blurb from djb's qmail security guarantee [0]: > I've mostly given up on the standard C library. Many of its facilities, particularly stdio, seem designed to encourage bugs. A big chunk of qmail is stolen from a basic C library that I've been developing for several years for a variety of applications. The stralloc concept and getln() make it very easy to avoid buffer overruns, memory leaks, and artificial line length limits. [0]: http://cr.yp.to/qmail/guarantee.html http://cr.yp.to/qmail/guarantee.html
- sigsev_251 3y agoI mean, the annotations are supposed to be simple C attributes wrapped in macros, so even them are just C
- jonpalmisc 3y agoThe other commenter mentioning Firebloom is correct that some firmware (iBoot family) has been using C w/ Firebloom extensions for a while. Parts of SEPOS also use Swift, which would make more sense as a non-C language than Rust, from Apple's perspective at least.
- candiddevmike 3y agoWhat benefit would Apple get from this? They want you all in on an ecosystem they control. EDIT: Thought OP was talking about writing iOS apps using Rust.
- steveklabnik 3y agoApple does use Rust, though from job postings, we can infer it's more like network services than firmware. Regardless though, I don't see how the implementation language of your firmware is locking you into a specific ecosystem, so this criticism seems misguided to me.
- pjmlp 3y agoApparently people keep forgetting Swift exists. "CppNow 2023:Introducing a Memory-Safe Successor Language in Large C++ Code Bases" https://www.youtube.com/watch?v=lgivCGdmFrw https://www.youtube.com/watch?v=lgivCGdmFrw
- adastra22 3y agoSwift is a different class than rust though.
- pjmlp 3y agoNot for Apple, > Swift was designed from the outset to be safer than C-based languages, and eliminates entire classes of unsafe code. -- https://www.swift.org/about/ https://www.swift.org/about/ > Swift is a successor to the C, C++, and Objective-C languages -- https://developer.apple.com/swift/ https://developer.apple.com/swift/
- diogenes4 3y agoSorry, what does swift have to do with this?
- pjmlp 3y agoSwift is Apple's answer to replacing C derived languages, they don't need Rust. > Swift is a successor to the C, C++, and Objective-C languages -- https://developer.apple.com/swift/ https://developer.apple.com/swift/ They also mention plans for kernel and firmware targets on that talk.
- ireallywantthat 3y agoOk, now enable us to let create Android Applications entirely in Rust (including the GUI). Let's get rid of Kotlin/Java monopoly in Android App development. Shall we?
- wredue 3y agoWhat would rust achieve aside from just enabling another, entirely distinct from the existing workflow, language? Haven’t android apps been compiled to native code since like 2012? (I actually don’t know, I left android a while ago and stopped caring what they do)
- cogman10 3y agoI don't think it's a good idea, mainly because android is multiplatform and rust, by it's nature, is only available for what it's built for. Unless you are giving google your rust code to compile, your app will be limited on it's reach. All that said. Rust doesn't have a GC so it'd (likely) have a lower memory consumption and could possibly be lighter on the CPU. Native compilation helps mainly with startup time and memory consumption. It's not exactly great for runtime performance as it takes away some key optimizations. Another benefit of rust assuming you are distributing binaries is you'll be able to use the latest version of Rust rather than being pinned to older versions of the SDK with partial support based on the whims of google.
- shopvaccer 3y ago>mainly because android is multiplatform and rust, by it's nature, is only available for what it's built for Android is one platform: android. I thought rust worked across multiple operating systems. >Rust doesn't have a GC so it'd (likely) have a lower memory consumption and could possibly be lighter on the CPU. So what? I have never used G.C. >Native compilation helps mainly with startup time and memory consumption. It's not exactly great for runtime performance as it takes away some key optimizations. That is fair I suppose I think the main benefit of rust/c++/ndk on android is that I can just port desktop programs and I don't have to learn android's java/kotlin and sdk.
- theusus 3y agoI found adoption of Rust being slow, but it has started to grow.
- outworlder 3y agoIt's incredibly fast compared to most programming languages.
- trealira 3y agoI wasn't around for it, but didn't C grow fast during the 70s and 80s? And didn't Java and JavaScript also spread pretty fast? Of course, Java was explicitly promoted and advertised by Sun, and JavaScript played off of Java's popularity and later became a web standard.
- kibwen 3y agoC was definitely a player in the 70s and 80s (when it (and Unix) still had a lot of healthy competition), but it didn't attain its current veneer of ubiquity until approximately the early 90s (after being standardized in 1989). Javascript was derided as a joke until 2009 brought ECMAScript 5 and Node.js. Java's rise was relatively fast, but Java also had the benefit of the most concerted corporate ad campaign in the history of programming languages (how many programming languages have you seen advertised on TV? https://www.youtube.com/watch?v=FpirOZe1Cgk https://www.youtube.com/watch?v=FpirOZe1Cgk )
- pjmlp 3y agoRegarding Java, it also helped that big Smalltalk players like IBM, decided to fully pivot into Java, and many Oracle haters might not realise that alongside IBM, they were the first ones to have alternative JVMs and were together with Sun in the Network Computer effort. Smalltalk had a .NET like role in OS/2, one of the reasons SOM even supported metaclasses, just imagine the alternative universe.
- p4ul 3y ago
- 1f60c 3y agoIdeally, Android wouldn’t have any security vulnerabilities, but that’s not realistic. Rust won’t prevent every bug (and it’s even possible to cause segmentation faults in an ostensibly safe language like Python), but “better” is still a huge leap forward.
- kupopuffs 3y agojust.... no more buffers overflown
- vitiral 3y agoOr dead pointers used, or race conditions
- tialaramex 3y agoNope. Race conditions are an ordinary fact about our universe, Rust has those. (Safe) Rust doesn't have data races which are much stranger. Race conditions are just an ordinary effect where several actors are doing things and you need to be careful to ensure that they're co-ordinated properly if that's important. If Alice and Bob both conclude there's no milk, both then go to the store and buy milk, now there is too much milk. Data races are because it's not possible to deliver what you intuitively expect from a computer which is capable of multiple notionally simultaneous operations. They have no analogue in our real world experience, which is why they're baffling for real programmers on non-trivial software. The world stops making sense. Most programming languages which allow parallel computation have data races. In C and C++ they're just Undefined Behaviour. Game over. In Go they're sometimes not Undefined Behaviour if your race only touches very simple things like integers. In Java, interestingly, they're always defined behaviour but it doesn't help very much because the behaviour is extremely hard to reason about. Still, your program does do at least something sane even if your head hurts when you think about it. In safe Rust this never happens.
- jon_richards 3y agoSpeaking of race conditions, I recently looked into the current state of “make sure something is in the db and then retrieve it”. Absolutely bonkers that “on conflict do select” still doesn’t exist.
- SuaveSteve 3y agoThe Doom of programming languages? Rust must be run everywhere with no irony.
- deleted 3y ago[deleted]
- asrael_io 3y agoYeah but does Doom run on rust-analyzer?
- gpm 3y agoRust analzyer type checks rust and type checking is turing complete... it's only a matter of time.
- outworlder 3y agoPeople want to replace C, which runs anywhere. Rust must also be able to.
- az09mugen 3y agoI may have wrong assumptions, but I find it funny they didn't use Golang. Is it not capable of doing the same thing ? Anyway, happy to see rust being adopted for that usage.
- izacus 3y agoNo, Go isn't appropriate for these things. Use the best tool for the job
- digdugdirk 3y agoCan you please explain why Go isn't appropriate here?
- pix128 3y agoGo is garage collected
- sangnoir 3y agoBinary size, for one. The blog mentions a binary file grew from 220kb (C) to over 400kb (Rust). I also doubt a garbage-collected language work very well for drivers that require precise timing (MMIO) and/or control over memory allocation.
- pjmlp 3y agoIt worked rather well for Xerox PARC, TI, Genera and others, had they not mismanaged their products, or fighting against workstations being built with a free beer OS.
- samus 3y agoThe blog immediately put that statement into context, stating that the binary file actually ended up replacing most of their stack. At the end of the day, they ended up with about the same size binary size. Also, they were not even really trying to optimize for size.
- 3y ago
- kajaktum 3y agoI don't get mailing lists. See this https://lists.denx.de/pipermail/u-boot/2022-March/478466.html https://lists.denx.de/pipermail/u-boot/2022-March/478466.htm... So where is the patch?
- 5- 3y agothe git-send-email format for a patch series is the cover letter (the one you are looking at) and then one message per commit (subsequent emails in the thread). mailman is not the best interface for reading these; people would normally use their mail client, or specialised tools like patchwork. e.g. this series on patchwork: https://patchwork.ozlabs.org/project/uboot/cover/20220320114118.2237795-1-ascull@google.com/ https://patchwork.ozlabs.org/project/uboot/cover/20220320114... (click 'expand' in the 'series' line)
- hackernudes 3y ago00/12 is the description. The rest of them are 01, 02, etc... It all works great if you are actually subscribed to the mailing list. The kernel "lore" site has a better interface to the mailing lists and can download stuff as mbox files - https://lore.kernel.org/all/20220329165900.1139885-1-ascull@google.com/ https://lore.kernel.org/all/20220329165900.1139885-1-ascull@... There is also a service called "patchwork" that collects these patches in a web page format
- deleted 3y ago[deleted]