3 ms·
Author’s paper also doesn’t solve the problem, because I wager most C++ programmers wouldn’t touch this rustified C++, which manages to look even worse than the
by blub 2y ago
Author’s paper also doesn’t solve the problem, because I wager most C++ programmers wouldn’t touch this rustified C++, which manages to look even worse than the already not light on the eyes original.
- pjmlp 2y agoProbably, but then they will need to decide how much they feel like if C++ joins the computing equivalent of hazardous goods, where products written on it only have clearance for specific use cases. See "Product Security Bad Practices" from CISA and FBI, published last week. https://www.cisa.gov/resources-tools/resources/product-security-bad-practices https://www.cisa.gov/resources-tools/resources/product-secur... => "Software manufacturers should build products in a manner that systematically prevents the introduction of memory safety vulnerabilities, such as by using a memory safe language or hardware capabilities that prevent memory safety vulnerabilities. Additionally, software manufacturers should publish a memory safety roadmap by January 1, 2026."
- rfoo 2y ago> such as by using a memory safe language or hardware capabilities that prevent memory safety vulnerabilities Heh, now I do believe that my partially-memory-corruption-based side job may be in danger. If it was just "by using a memory safe language" I do not care, but if they want to boost hardware assisted mitigations (better and ubiquitous memory tagging etc) it's going to have significant impact.
- steveklabnik 2y agoThey are advocating for a holistic approach for safety. But of course, when talking about a specific part of that, they’ll talk about the specifics. With regards to programming languages, memory safety is the next big thing to tackle.
- pjmlp 2y agoIronically some Turing Awards could already see this coming in 1980, but it was needed some money to be tied to CVE's, to make this actually matter. "A consequence of this principle is that every occurrence of every subscript of every subscripted variable was on every occasion checked at run time against both the upper and the lower declared bounds of the array. Many years later we asked our customers whether they wished us to provide an option to switch off these checks in the interests of efficiency on production runs. Unanimously, they urged us not to--they already knew how frequently subscript errors occur on production runs where failure to detect them could be disastrous. I note with fear and horror that even in 1980 language designers and users have not learned this lesson. In any respectable branch of engineering, failure to observe such elementary precautions would have long been against the law." -- C.A.R Hoare's "The 1980 ACM Turing Award Lecture" It is only taking a couple of decades to get there. By the way I know you already are aware of this, more for those that don't.
- gpderetta 2y ago> It is only taking a couple of decades to get there. I don't know how to break it to you, but the Eighties were 40 years ago :( In any case I was wondering if Hoare, in addition to bound checkings, felt as strongly about the so called temporal safety, but his words are unambiguous: he is not just rejecting any form of Undefined Behaviour, he wants anything that passes static checking to have useful valid semantics, reminiscent of the "well typed programs can't go wrong" maxim.
- pjmlp 2y agoA side effect of native language, where a couple doesn't translate to 2, rather some. That maximum is usually the approach to UB in sane systems languages, literally meaning undefined and that is it, possibly having traps or similar enabled by default. It isn't the wildcard for any kind of optimisations are allowed, aka "please go wild dear optimiser".
- blub 2y agoWe don’t know if this is a case of the government watchdogs barking while the caravan moves on.
- pjmlp 2y agoYeah I know, too many folks at WG21 think is this going to be just like Ada so they are on the clear. Except that back then, it mostly failed due to the prices of compilers adjusted to goverment level contracts, the few UNIX vendors like Sun that sold such compilers it was extra not part of the regular UNIX SDK, the cost of hardware to run modern Ada compilers (Rational started as a Ada Machine company), so it was dropped as requirement, and thus stuff like JPL, MISRA, AUTOSAR, F-35 C++ (what a success this one),... that allowed cheaper development with guiderails. Now that exploits have money placed on them, in fixing CVEs, pushing fixes into devices, insurances paying for downtime,.... goverments and companies burning that money, have reached the conclusion that software is now critical infrastructure, and must be dealt accordingly like everything else that is criticial in modern societies. This is not going to be Ada again, as much some folks wish for.
- account42 2y agoLooking forward for all the government sanctioned "safe" software that continues to send real time telemetetry while it tries to manipulate me into spending money on things I don't need. But at least only the good guys will be able to do that, yay.