5 ms·
The Fil-C Manifesto: Garbage In, Memory Safety Out
- philosopher1234 3y agoIt can run CURL!!! And OpenSSL! This seems possibly like a big deal.
- hollerith 3y ago>Fil-C is currently about 200x slower than legacy C according to my tests
- pizlonator 3y agoIt sure is! :-) But it can run real code, and that's what matters most in early bringup.
- rubymamis 3y agoHow much faster do you think it can get? BTW, awesome work!
- pizlonator 3y agoIf enough effort goes into it? Pretty much as fast as C.
- rubymamis 3y agoDamn, I hope that day will come!
- jitl 3y agoIt’s interesting to see a very pragmatic approach towards “better C”. There’s so many “better C” languages out there gaining popular interest like Zig, Hare, Odin, Jai; but none (I don’t consider Rust a better c) try to tackle memory safety, even when stating from a clean slate. Then there’s this thing, which is still mostly normal C, so it’s very easy to apply to existing code, and it does solve memory safety head on. It’s not clear from reading but it seems like most checks happen at run time, and not at compile time. How much feedback goes the compiler give to the user about mistakes?
- pizlonator 3y agoBasically all feedback is at runtime.
- sixthDot 3y agoCommits messages are the shit.
- nickpsecurity 3y agoI’m curious if you’ve looked at the prior attempts at memory safe variants of C or compiler-assisted safety for legacy C? They are really safe with better performance than Fil-C is. More important, you might find some of their ideas useful in your own work. Here’s a few I remember: CCured https://people.eecs.berkeley.edu/~necula/Papers/ccured_toplas.pdf https://people.eecs.berkeley.edu/~necula/Papers/ccured_topla... Softbound + CETS https://people.cs.rutgers.edu/~sn349/softbound/ https://people.cs.rutgers.edu/~sn349/softbound/ Clay Systems Language https://www.eg.bucknell.edu/~lwittie/research.html https://www.eg.bucknell.edu/~lwittie/research.html Cyclone Language (Rust drew on it) https://en.m.wikipedia.org/wiki/Cyclone_(programming_language) https://en.m.wikipedia.org/wiki/Cyclone_(programming_languag... Fail-Safe C https://staff.aist.go.jp/y.oiwa/FailSafeC/index-en.html https://staff.aist.go.jp/y.oiwa/FailSafeC/index-en.html CheckedC https://github.com/microsoft/checkedc https://github.com/microsoft/checkedc Also, one can combine subsets of C with FOSS, static analyzers that can handle those subsets. Then, compose only in ways that the tools can handle. Then, combinatorial and fuzz testing of the interface composition. I know you’re doing the project for fun while exploring specific ways to achieve your goals. So, these are just some links and concepts that might help on your journey. Lots of folks don’t know about prior work in this area. So, I keep passing it on.
- pizlonator 3y agoI know about all of them. CCured, Softbound, and Cyclone are abandonware. Cyclone and CheckedC require lots more changes to your code than Fil-C. CheckedC isn't even memory-safe since all it handles are bounds. Thanks for the super sweet attempt to teach me about this field, but I'm an expert on this stuff already. The fact that I'm starting from a "no premature opts" mindset and just being full-on pragmatic is because I know better than any of those folks. :-)
- nickpsecurity 3y agoThe performance loss was many times higher than experts usually hit even when optimizing for correctness. You also assume it will be later be close to C’s performance which most people who are experts wouldn’t claim. I’m glad you are aware of their work, though. “Know better than any of those folks” The Word of God says pride comes before the fall and the proud get humbled. If you have the knowledge, then wisdom might be the next thing to add to the project. You will be living pleasing to God and might draw in others with exactly the ideas you need.