3 ms·
> For the same purpose that all standards have--to formally define it in writing. This is tautological. It's equivalent to saying "it needs a standard to be wr
by faitswulff 3y ago
> For the same purpose that all standards have--to formally define it in writing.
This is tautological. It's equivalent to saying "it needs a standard to be written because it needs a written standard."
I mean what use case is there for Rust language users that isn't already met by the Ferrocene project? And the Ferrocene project is not a standard as in "other implementations will be found lacking," but a description of the 1.68 compiler as-is. That is a specification, not a standard. Ferrous Systems did not need Rust to have a standard in order to qualify the compiler for ISO 26262 and IEC 61508.
- thesuperbigfrog 3y ago>> "it needs a standard to be written because it needs a written standard." Yes. And if the law in your country requires it to be standardized for specific use cases, then a language standard is needed. >> what use case is there for Rust language users that isn't already met by the Ferrocene project? Can you legally use Rust for the control software in aircraft? (https://en.wikipedia.org/wiki/DO-178C https://en.wikipedia.org/wiki/DO-178C) What about the safety systems for railroads? (https://ldra.com/ldra-blog/software-safety-and-security-standards-for-gts-and-rail-applications/ https://ldra.com/ldra-blog/software-safety-and-security-stan...) What about the control systems for nuclear reactors? (https://www.nrc.gov/docs/ML1300/ML13007A173.pdf https://www.nrc.gov/docs/ML1300/ML13007A173.pdf)
- faitswulff 3y agoAnd if you need a ISO 26262 qualified Rust compiler, one exists. Hurrah. Since you edited your post…simply having a standard won’t immediately qualify the language for those industries. There is only a tenuous link between having a standard and qualifying the language for industrial use.
- thesuperbigfrog 3y ago>> simply having a standard won’t immediately qualify the language for those industries. There is only a tenuous link between having a standard and qualifying the language for industrial use. Not having a language standard disqualifies Rust. Administrators say that it shows that Rust is "not serious" and "not ready" for critical work.
- faitswulff 3y ago> Not having a language standard disqualifies Rust. Then explain how Ferrous Systems qualified a stock Rust compiler.
- thesuperbigfrog 3y agoFerrocene is not a "stock Rust compiler". The "stock Rust compiler" is not qualified for safety critical work. If Ferrocene did not add value above what is offered by the stock Rust compiler, why would anyone buy Ferrocene? Ferrocene is qualified for some safety critical work and plans to have more qualifications soon. Ferrous Systems wrote a blog post about the process: https://ferrous-systems.com/blog/qualifying-rust-without-forking/ https://ferrous-systems.com/blog/qualifying-rust-without-for...
- faitswulff 3y agoThe blog post you link to says it's an unmodified fork. Here's a Ferrous Systems employee saying as much: > Ferrocene is upstream rustc but with some extra targets, long term support, and qualifications so you can use them in safety critical contexts. This is what was stopping things like automotive companies from moving to Rust for things like engine control units, etc. > It basically costs some money for the support and the qualification documents, but they will be all you need to prove qualification to any pertinent regulatory body so that your software can be certified for use in a real vehicle or whatever. > ...Ferrocene is just unmodified rustc https://old.reddit.com/r/rust/comments/17qi9v0/its_official_ferrocene_is_iso_26262_and_iec_61508/k8ccct4/?context=3 https://old.reddit.com/r/rust/comments/17qi9v0/its_official_... Basically the value add was to expand the support and documentation, which was required for qualification. Again...no "standard" needed. I think you are conflating standards and specifications. Ferrous fleshed out the specification, the description of the 1.68 compiler as-is. That means Rust 1.68 as-is was good enough for ISO qualification. Without a standard. A standard is a minimum bar for languages to meet in order to be considered compliant. That's not a problem right now because there is, for all intents and purposes, a single canonical compiler and that is not likely to change.