5 ms·
Genuine question: Would you mind explaining to a dev that doesn’t know much (anything) about Rust, how does this settle any debate?
by calebpeterson 2y ago
Genuine question:
Would you mind explaining to a dev that doesn’t know much (anything) about Rust, how does this settle any debate?
- jerf 2y agoI believe it goes something like, "I have constructed a strawman that Rust claims that all code written in it is automatically safe by all conceivable definitions of safe, but look, ha ha, here's something that detects unsafe code in Rust!", and I don't mean "code marked in unsafe blocks". It's a concatenation of several logical fallacies in a row; equivocation, straw manning, binary thinking about safety, several others. It's hard to pick the main one, but I'd go with the dominant problem being a serious case of binary thinking about what "safety" is. Of course, if the commentor is using anything other than Idris for all their programming, they're probably not actually acting on their own accusations.
- PreInternet01 2y ago[flagged]
- commodoreboxer 2y ago> This repository demonstrates that, when using 'safe' Rust, there are still double-digits cases where you may still encounter dread-pirate-UB. No it doesn't. Miri is for unsafe code. There's no UB in safe Rust by design. Any UB caused without unsafe is considered a bug to be fixed.
- PreInternet01 2y ago[flagged]
- nequo 2y ago> ... in generally safe Rust. Just to find agreement about the terminology, wouldn't we call all code that is not inside an unsafe block "safe?" If so, then adding "generally" is superfluous, right? If not, then how is "generally safe" different from "not inside an unsafe block?"
- jerf 2y agoI didn't expect you to outright confirm that you are using the "solve all programming problems ever" strawman, but, err, thanks for the proof I guess. I thought maybe I went a bit overboard in the reading between the lines but I guess I nailed it.
- marcosdumay 2y ago> Of course, if the commentor is using anything other than Idris I'm sure the Idris compiler has bugs somewhere too. If the OP actually programs, they are violating their rationale (I'm quite sure assembly or assembled binary aren't ok either).
- mrweiden 2y agoFrom the original post > It’s not enough to rely on bug-finding tools From the Miri github: > Miri is an Undefined Behavior detection tool for Rust.
- keybored 2y agoDarpa is already ahead of you all with the hedging: > The preferred approach is to use “safe” programming languages “Safe”. Terms and conditions may apply.
- Sharlin 2y agoThere is no contradiction. The fact that UB-finding tools alone are not sufficient doesn't mean they aren't useful even with a safe(r) language. In other words, from "safer languages are necessary" it does not follow that "safer languages are sufficient".
- PreInternet01 2y agoWell, the general 'Rewrite All in Rust' consensus is that it solves all general programming problems, ever. Yet, the linked repository shows a huge list of cases in which simple, documented use of Rust can cause Undefined Behavior (a.k.a. 'UB') Pretty much every argument of Rust advocates against C/C++ boils down to either 'but memory safety' or 'but UB'. Yet there are many convincing counter-arguments that boil down to 'but CompCert' or similar, and, as the linked repository shows, there might be at least some truth in there?
- steveklabnik 2y agoNo serious person claims that Rust solves every problem ever. Also, many people cite things like Cargo as a reason to prefer Rust over C and C++, as well as other things. UB is a big part of it, of course, but it isn’t the only thing.
- galangalalgol 2y agoI selected it for performance reasons myself, the UB protection was a nice benefit that was expected, cargo wasn't expected and is extremely nice coming from the cmake,conan,vcpkg and duct tape world I came from.
- PreInternet01 2y ago> No serious person claims that Rust solves every problem ever No, but there are a lot of people claiming that Rust cannot ever have any problems. Just look at this thread. I merely linked to MIRI, and am currently at, like, -10 just for that. Lots of people claiming that it just applies to 'unsafe Rust': is that true or not? Regardless of anything else: can you, as a Rust community leader, please state clearly: is UB in generally safe Rust possible or not?
- steveklabnik 2y agoNo, people are not claiming Rust cannot have any problems. UB is not possible in safe Rust, by design. The root cause of UB is always in unsafe code. Miri is useless if your code is 100% safe Rust. The only exception to this is bugs in the compiler, of which there are a few. They’ll be fixed.
- leftyspook 2y agoIt is a tool for checking that your unsafe code doesn't cause UB. It doesn't really settle anything, but the commenter uses it as a gotcha to say "rust is no better than C, because you still can compile code that contains UB".
- spease 2y agoThey are claiming that because code in ‘unsafe’ blocks in Rust can have undefined behavior, that the language is no safer than C. This does not settle the debate because unsafe is rarely needed for a typical Rust program. In addition, the presence of an unsafe block also alerts the reader that the set of possible errors is greatly increased for that part of the code and more careful auditing is needed. It’s a little like saying traffic lights are useless because emergency responders need to drive through them sometimes, so we should just leave intersections completely unsignaled and expect drivers to do better. Rust is by default restrictive and requires you to explicitly make it unsafe, C/++ are by default unsafe and require you to explicitly make them restrictive.