11 ms·
Officially Qualified – Ferrocene
- weinzierl 3y agoThis is big news in my opinion. "We’ve qualified Ferrocene for use in systems up to ASIL D" Where D is the highest existing level used for systems that can potentially cause fatal injuries. From my understanding that means that now Rust can be used for the development of security critical software in automotive. I used to work in automotive and where I worked software development was dominated by ancient and archaic compilers and toolchains. Even if it wasn't for the advantages that Rust brings to the table the possibility to use a modern toolchain would be revolutionary. At the same time this is the biggest risk for adoption because these legacy systems are deeply ingrained and intertwined with existing processes that often span multiple tiers of suppliers and will be hard to change.
- pjmlp 3y agoWhile it is great that Rust is now also an option, some of those places still stuck in C89 and C++98, are hardly to going upgrade to anything else. Some times not even the tooling is an excuse, as most chip vendors do at least support C11 and C++14 in most cases.
- Xylakant 3y agoDisclaimer: I'm one of the founders of Ferrous Systems To some extend I agree, but from our conversations with OEMs, Tier 1 and Tier 2 suppliers we do see a significant interest in moving to rust, much more than moving to a new C/C++ version. The reasoning is that moving to a new C/C++ version is an incremental change, but moving to rust signifies a jump to a different tech level (let's set aside whether that's true on a technical level or not, I'm talking about perception). One of the signifiers is that we were able to qualify the rust language as it exists, with no such restrictions such as Misra C etc. So no "reduce use of pointers" etc. The other things that's helping is regulatory pressure. The CISA, DARPA etc are all advocating strongly in favor of moving to memory safe languages, and for the chunk of the market that used C/C++ before, rust is a pretty good offering there: It binds to C both ways, that means not only can you call C code from rust, but also the other way round - you can build a component in rust and integrate it in your existing firmware. That's a rare capability. Chipset and ecosystem support are IMO the biggest hurdles at the moment, but with Ferrocene as a qualified compiler, at least that one bar is removed. It's still a long way to go and a lot of work ahead of us :).
- pjmlp 3y agoI see human behavior a more problematic issue to overcome than the toolchains, hence why I mentioned the toolings being more modern than what many are willing to adopt. Looking forward to regulatory pressure to help improving the situation, not only regarding the adoption of modern safer languages, but also to "just" adopt modern practices and tools while coding in C and C++. Already changing the mentality from unsafe at any speed, to quality matters, would be a big improvement. A plus from safer languages that aren't copy-paste compatible with C, is that C style programming is already taken out, so we don't need to spend time creating SonarQube rules and forcing them into teams. Good luck with the Ferrocene effort.
- Xylakant 3y ago> I see human behavior a more problematic issue to overcome than the toolchains, hence why I mentioned the toolings being more modern than what many are willing to adopt. I absolutely agree. I agree that this is what's holding back adoption of new tooling the most. However, the impression that I get from our conversations is that a new C/C++ is seen as "more of the old thing" while rust is considered a break with the old thing, something new with substantial risk, but also substantial upsides. This perception helps when it comes to considering an adoption.
- cryptonector 3y agoWe need an industry-wide break with the old thing. There have been enough problems caused by crappy unmaintainable spaghetti code full of UB. Now, a new thing (Rust) doesn't mean you'll get better code in every way, but at least in some ways.
- rdsubhas 3y agoTo be frank, this seems to be a general comment on rust as a language itself, than ferrocene. One would instead start from an observation that rust has been filling a real need/gap in the market which can't be explained merely by human behavior alone, and looks like it's been quite successful at doing that.
- zozbot234 3y ago> From my understanding that means that now Rust can be used for the development of security critical software in automotive. What about other safety critical domains such as aerospace, medical, railways, machinery, process control etc? It seems like each of these has its own bespoke standards, so Ferrous will need to seek certification for these separately?
- twic 3y agoAs the article says: > Beyond the automotive, Ferrocene can also be used in electronic programmable systems in the industrial sector. Here the focus is on developing products or applications that carry out safety functions. Like the automotive certification, we’ve also gone for the highest level of risk reduction and qualified it at SIL4. Apparently [1] the SIL standard is used in at least the process control, nuclear, mechanical, and railway industries. Not sure about medical or aerospace. [1] https://en.wikipedia.org/wiki/Safety_integrity_level#Standards https://en.wikipedia.org/wiki/Safety_integrity_level#Standar...
- Xylakant 3y agoAerospace would be DO-178, which is on the roadmap, but will take some effort (a year or two, give or take). Medical is closer: While there are dedicated certifications for medical, they are relatively close to the IEC 61508 industrial standards and so IEC certifications are often used as a stand-in for the equivalent medical certification.
- kejaed 3y agoKeeping an eye on this in the aero, uh, space. Very interesting progress, keep up the good work.
- twoWhlsGud 3y agoIsn't AdaCore handling the DO-178 side? Or does Ferrocene intend to have an offering here, also?
- tialaramex 3y ago> From my understanding that means that now Rust can be used for the development of security critical software in automotive. It has always been possible to do whatever you wanted in this respect, Ferrocene means that you don't have to go to more trouble than a competitor who does their software development in a similarly qualified C++ software suite. Rather than pay some number of people to explain why it's OK that you didn't do the boring normal thing, you can pay Ferrocene for their paperwork which says actually Rust is just one of the boring normal things. Is "Boring normal thing" good enough? Well, on its own I'd argue it's not even close, but pragmatism rules the day, people writing firmware which is in pretty old cars were knocking it together in C with no rules, and most people didn't die, so, that's our baseline, that was apparently OK, logically a bit of that won't be a disaster... right? It reminds me of GRAS rules. On the one hand, there's no particular reason to just assume parsnips are OK food while this random thing my chemists just invented is not - after all parsnips may be "natural" but so are all nightshades and some of them are straight up poison (and indeed the rest of Apiaceae, the family parsnips are in, are sometimes poisonous) - however on the other hand a lot of people have eaten parsnips already and they seemed fine, so, maybe that's enough reason to require tests for my chemical but not parsnips ? Or at least, lets not require the tests before continuing to eat parsnips.
- weinzierl 3y ago"It has always been possible to do whatever you wanted [..]" That is not quite what I meant. You can always do what you want if you are prepared to accept the consequences. German law requires the manufacturer of a technical product to take all measures objectively necessary and reasonable in order to avoid danger and harm. In automotive safety critical systems ISO26262 is a legally well established, necessary (but not necessarily sufficient) prerequisite for that. Car manufacturers spend a ton of money on certified compilers and toolchains for good reasons. One of them is legal compliance. "From my understanding that means that now Rust can be used for the development of security critical software in automotive." What I meant here is that I'm not sure if what exists today (including Ferrocene's certified toolchain) is enough to make Rust happen in safety critical automotive applications. I simply do not know enough to make that claim.
- DoingIsLearning 3y ago> Rust can be used for the development of security critical software in automotive. Perhaps you are native of a latin language? In the context of ISO26262, ASIL levels relate to the criticality of _safety_ not security. My house's security will determine how easily someone can break in. My house's safety will determine how well it will survive a hurricane.
- weinzierl 3y agoOh yes, you are right, in my mother tongue safety and security are the same word. It is still embarrassing, I should have been more careful.
- lbschenkel 3y agoPortuguese doesn't distinguish between those either: both are "segurança".
- chromatin 3y agoWait -- I find this fascinating. They are also kind-of the same word(s) in German (Sicherheit / Sicherung). Do native German speakers draw much distinction between Sicherheit and Sicherung, and to the same degree that we do in English? If no, I am curious how the differentiation in concepts developed in English developed and whether it is also present in other Germanic languages.
- Megranium 3y agoHmm in German you could also say "Betriebssicherheit" (safety) vs. "Angriffssicherheit" (security), or at least that always was the translation that made most sense to me personally. I'd say native speakers of German distinguish it but it depends on the context ... talking about computers, it's typically more about security, while when talking about construction sites, it's typically more about safety.
- M3t0r 3y ago
- tecleandor 3y agoFor somebody not familiar with compilers, rust or ASIL... What's the difference between the regular rust compiler and Ferrocene that makes it adequate for critical systems?
- ijustlovemath 3y agoIn a word: documentation and testing. They're not making major modifications to upstream, but they are crossing the Ts and dotting the Is to satisfy the that their compiler meets all the safety requirements set forth in those standards. As far as why use their compiler vs upstream? It's similar to why you might use a managed database vs deploying your own in a $5 droplet; in a big corporate environment, you have no trouble paying for things that would be hard to do yourself, and satisfying regulators is one of those things. All at a very reasonable price point, too!
- tecleandor 3y agoI mean, I was thinking more like: What's the merits that allow the certification? Is it technical? Is it bureaucracy and "just" certifications? I've been on the healthcare business so I've seen how that works when doing FDA or CE certifications.
- Xylakant 3y agoDisclaimer: I'm one of the founders of Ferrous Systems. Ferrocene as a compiler is not inherently more suitable for safety critical applications than stock rustc as distributed by the rust project. It is for all intents and purposes the rust projects compiler, with all the certification paperwork - that's quite a stack of paper if you include all of it, but it doesn't change any of the functionality. However, on a support/organizational level, there are quite a few differences. We run our own CI for all of our supported targets which allows us to provide different QA levels than the rust project does or even could support. We do provide higher levels of assurance on some targets compared to upstream. For example, the aarch64-unknown-none target is treated as "tier 2" by the Rust project, meaning they don't run any tests for it. Instead, Ferrocene treats it as fully supported, and we ensure all tests pass on it when we merge any change (contributing back fixes when something breaks). We can also provide support for targets that are not in the rust projects tree, or even require legal paperwork for access to test hardware etc., to the point that we can provide binary only targets that cannot be made available via the rust project. On a support level, we also provide support for existing rust version, to the point of long term support for certified versions (2 years by default, more or less infinite with a separate support contract). There's also minor things that are interesting to organizations: Notification of known issues, signed installers, ... All of these things do not change the compilers behavior, but can be quite essential for organizations with long term, safety critical projects.
- londons_explore 3y agoWhat impact does certification have on the safety of the resulting systems? Is this one of those standards which involve a lot of questionnaires and box-ticking, but has negligible effect on the bug-free-ness of the resulting software?
- dgacmu 3y agoThe biggest practical impact is probably from having the CI tests running on the certified platforms that were not already tier one for rust.
- Argorak 3y ago(disclaimer: also a co-founder of Ferrous Systems) The ISO 26262 is certainly an effective standard. The boxes to tick are of the kind "do you have your requirements written down?" ("will someone later know what this thing does?"). So, we do have to tick boxes, but we're free to pick on how to tick boxes :). What TÜV now certified is that our box-ticking process is fine. I have absolutely no problem with framing this as box-ticking in some way, but that box-ticking has _meaning_. However, on an existing tool, that means you write the spec (spec.ferrocene.dev) and check if everything has a test implemented. Yep, that's an amount of pretty dumb and repetitive work. And pretty often, on widely-used software, for the happy path, you'll find that it's rather bug-free. So, yes, you tick the box, but you now know that this is in order. In other cases and on less popular platforms, we frequently find issues like e.g. changes in code size between versions (which could hint to a bug). And it's not just super-niche targets, the last version had a size regression on certain arm targets. Details on some of the fixes over the last years can be found here: https://ferrous-systems.com/blog/how-ferrocene-improves-rust/ https://ferrous-systems.com/blog/how-ferrocene-improves-rust.... We find a lot of things in corners and better ways to improve the Rust compiler. As we're a downstream to Rust, we're actually incentivised to push changes upstream with preference, so yes, we contribute to the general quality of the Rust compiler (also of older versions) and with that to bug-free-ness of the resulting software. So, we're over here, ticking boxes, informing parties when one box doesn't tick.
- lucasyvas 3y agoIt seems like it would be cool to have a "rustup" variant that used this so it was a smooth setup to get a certified tool chain. That said, I don't code for such environments so I don't know if they prefer to piece their tools together or if there are other reasons to not bother.
- pietroalbini 3y agoWe're working on that! Expect more news around it in the coming months.
- Game_Ender 3y agoThis is very exciting, the interop with C really opens the ability to fold this into an existing OS and drivers. Any existing examples of operating system integration, for example working with SafeRTOS [0]. 0 - https://www.highintegritysystems.com/safertos/ https://www.highintegritysystems.com/safertos/
- Argorak 3y agoYes, we built bindings for LynxOS 178 a while ago and demonstrated Rust on QNX at embedded world. https://www.lynx.com/press-releases/rust-compiler-support https://www.lynx.com/press-releases/rust-compiler-support https://ferrous-systems.com/blog/how-we-built-our-embedded-world-demo-on-rust-for-qnx/ https://ferrous-systems.com/blog/how-we-built-our-embedded-w... Porting Rust to RTOSes is reasonably easy.
- dwroberts 3y agoI was expecting it to be locked to quite an old rust, just because of how difficult/slow it is to get this kind of accreditation, but it's 1.68 which is not bad at all (latest stable is 1.73)
- deleted 3y ago[deleted]
- faitswulff 3y agoCan any of the Ferrocene folks here can talk about what the release cadence for officially qualified Rust toolchains might be?
- Xylakant 3y agoA lot of the timeline depends on the partner we're working with to achieve qualification. Initial qualification definitely takes longer, but we're having discussions on how we can cut down on the manual part of the certification. We do for example pull in all releases of the compiler, including nightly, and build them using our CI and test sytems. The versions that pass are made available to our customers, so they can follow the release cycle - though these are obviously not qualified and nightly comes with the usual nightly (lack of) stability guarantees. I obviously can't make any promises here, but we aim to pick two of those rust versions per year and then certify them - how long that takes depends on the feedback we get from the auditor and on their availability. The exact cadence will need a little shakedown - no one has experience in qualifying rust compilers continously :)
- the_duke 3y agoSide question: Is your pricing in line with the norms in this sector? It seems really cheap to me.
- AlotOfReading 3y agoFrom past experience, other companies in this space typically charge 1-2 orders of magnitude more per seat. Their products are also usually worse than the free/OSS options that don't come with certification paperwork.
- linuxlizard 3y agoI'm very excited about this. Having a vendor supported toolchain means I might be able to bring Rust into where I work. Embedded companies are very conservative and risk adverse. Have a commercial package with LTS and certifications addresses some of the concerns.
- thatxliner 3y ago“Rust was designed specifically to handle concurrent and parallel programming”
- BD103 3y agoCongrats! Ferrocene has been building towards this accomplishment for a while. I definitely appreciate the amount of hard work that went into this. (And as a fellow Rust user, all the improvements and changes that get merged upstream.)
- juliangmp 3y agoI've met some people from ferrous before (during one of their rust courses) and I have to say I was quite impressed with their work. They went through the qualification without a fork of the compiler. The changes they made are upstream, and all open source.
- littlestymaar 3y agoThat's a vert smart move actually: the value their customers are paying for is the certification/paperwork, so upstreaming doesn't cost them anything and it reduces their costs a lot since they don't have yo maintain their fork, which can be an extremely costly endeavor in the long run.
- WiSaGaN 3y agoAny example PR? I am curious about what they look like.
- steveklabnik 3y agoHere is one I know of: https://github.com/rust-lang/rust/pull/90346 https://github.com/rust-lang/rust/pull/90346 I believe this is one as well: https://github.com/rust-lang/rust/pull/113535 https://github.com/rust-lang/rust/pull/113535
- Xylakant 3y agoThe second one was for a demo at an ESA symposium about rust in space, so it‘s not directly related to the certification.
- steveklabnik 3y agoAh ha! Thanks :)
- Xylakant 3y agoI mean, it’s definitely indirectly related to the entire certification thingy. After all, we do want to see rust code in space. That what kicked off that whole idea :)
- Sytten 3y agoWill you guys provide certified libraries as well? Like an async executor, http client, bluetooth, etc? That would be something even companies outside the target for certification would probably be interested in.
- Argorak 3y agoWe're being asked about these regularly, but e.g. bluetooth certification is still too prohibitive to just do without a customer. However, I'm also frustrated with "everything is customer funded", so we're looking at ways to make this things happen. Sorry to be vague.
- stefanoco 3y agoOn this topic (certified libraries) I suspect an interesting evolution might happen: by observing how you guys at Ferrous achieved this milestone while keeping a consistent openness, other actors (companies, consultancies and academic institutions) start seriously thinking about the possibility of contributing with high quality and certified libraries for a lot of scenarios. In other words I’d look at this as a milestone that opens to new and disrupting ideas
- Argorak 3y agoYes, and this does indeed happen. Turns out publishing such a thing makes people get in touch.
- 1-KB-OK 3y agoHuge! Congrats to the team.
- KwanEsq 3y agoIf someone from Ferrous sees this, I'd advise putting the price in English punctuation when writing the article in English. It's a needless stumbling block having the comma and period in the wrong place.
- Argorak 3y agoHe, thanks! Weird how that happened though, as the post _was_ edited by an English speaking person living in Germany :).
- stefanoco 3y agoThis is a milestone and a landmark achievement. And the reasons for this are not limited to the availability of a qualified and vendor supported toolchain for the use of Rust in Functional Safety concerned embedded designs. The goal has been reached while maintaining openness and shared results, which is an industry first.
- ruuda 3y agoAside from having gone through the certification, what are the differences between Ferrocene and upstream rustc?
- steveklabnik 3y ago"Measured in literally tens of lines" https://news.ycombinator.com/item?id=37771664 https://news.ycombinator.com/item?id=37771664 for more: https://ferrous-systems.com/blog/qualifying-rust-without-forking/ https://ferrous-systems.com/blog/qualifying-rust-without-for...
- LelouBil 3y agoAs someone that doesn't know anything about safety certifications of software, what do they actually do to make rust certifiable ? Like what are the requirements and how to they make rust follow them ?
- 0xfedbee 3y agoIf I ever see Rust code running in a car, I’m never going to buy it.
- LargoLasskhyfv 3y agoUnimpressed because of https://en.wikipedia.org/wiki/Technischer_%C3%9Cberwachungsverein#Brazilian_dam_disaster https://en.wikipedia.org/wiki/Technischer_%C3%9Cberwachungsv...
- TheDesolate0 3y agoWoo-hoo!