4 ms·
Rustler catches panics before they crash the VM and raises them on the elixir side as an exception. So your process might crash but the vm wont
by el_oni 2y ago
Rustler catches panics before they crash the VM and raises them on the elixir side as an exception. So your process might crash but the vm wont
- kristoff_it 2y agoThat's a neat way to get corrupted state in your application, especially when users of said language don't realize that their language has exceptions. I wrote this recently about Go, but it equally applies to any Rust application that tries to recover from a panic. https://kristoff.it/blog/go-exceptions-unconvinced/ https://kristoff.it/blog/go-exceptions-unconvinced/
- ellroy 2y agoI don't think this is right. The process will crash, and the Supervision strategy you are using will determine what happens from there. This is what the BEAM is all about. The thing with NIFs is that they can crash the entire VM if they error.
- MarcusE1W 2y agoErlang's (Elixirs) error management approach is actually "Let it crash" This is based on the acknowledgment that if you have a large number of longer running processes at some point something will crash anyway, so you may quite as well be good at managing crashes ;-) https://dev.to/adolfont/the-let-it-crash-error-handling-strategy-of-erlang-by-joe-armstrong-25hf https://dev.to/adolfont/the-let-it-crash-error-handling-stra...
- foldr 2y agoYes, but that's not Rust's error management strategy. Most Rust code isn't written with recovery from panics in mind, so it can have unintended consequences if you catch panics and then retry.
- throwawaymaths 2y agoThis is terrible, actually. And I've run into it, causing a memory leak.
- filmor 2y agoHow so? The whole point of unwinding is to gracefully clear up on panics, how did it peak for you? It's also not like there is much of a choice here. Unwinding across FFI boundaries (e.g. out of the NIF call) is undefined behaviour, so the only other option is aborting on panics.
- throwawaymaths 2y agoYes. Abort early in unit tests, core dump so it never makes it to prod
- filmor 2y agoThe panic is converted to an Erlang error exception. You have to explicitly ignore it to make unit tests pass in spite of it. I am still interested in the situation you observed.