5 ms·
Safe rust is harder than C.
by maxk42 2y ago
Safe rust is harder than C.
- Cyph0n 2y agoSafe C is harder than safe Rust.
- Quothling 2y agoZig is easier than Rust.
- jsheard 2y agoSafe Zig is harder than safe Rust, but easier than safe C. In conclusion, programming is a land of contrasts.
- eikenberry 2y agoI've never heard the opinion that safe Zig is harder than safe Rust. Pretty much always the opposite, that Zig is easier than Rust all around.
- binary132 2y agoI think the claim here is that it’s hard to write really safe zig
- kelnos 2y ago> but easier than safe C Well, everything is easier than something that doesn't exist.
- tonetegeatinst 2y agoDosnt GCC have flags that enforce memory safety? Also don't fuzzers handle this issue?
- kstrauser 2y agoIt cannot possibly. You can catch some low hanging fruit, but asking a compiler to evaluate whether a specific chunk of code is memory safe is basically solving the halting problem.
- jmkr 2y agoCan you explain what that low hanging fruit is (or refer me to docs), and also explain it being a decision problem a bit more thoroughly. I will accept that if you have to run a program to decide if it's memory safe then that fits the criteria, but from my understanding static analysis doesn't run the program, and a compiler is parsing and lexing anyway so it should be able to catch at least some things (the low hanging fruit)? Since I have actually started using C I realized how easy it is to be lazy and not handle memory right so it makes Rust and maybe C++ seem more appealing, but trying to figure out random segfaults it seems like address sanitizer and valgrind catches more than I would have assumed is a low hanging fruit. I guess I should look more into how Rust manages that safety or understand what memory safety is trying to accomplish more formally. I've taken GC for granted for years until I needed to care about memory.
- steveklabnik 2y ago(Not your parent) An example of low hanging fruit is -fwrapv. This flag takes a behavior that is undefined, signed overflow, and converts it to defined behavior, two's compliment wrapping. That improves safety, but it does not prevent all errors. There are many flags like this, but they all tackle individual aspects of the problem, and even if you turn them all on, there are situations which aren't caught.
- jmkr 2y agoThanks. Yeah that makes sense for low hanging fruit. Going through the gcc flags it does seem like a lot of tradeoffs have to be made so you can't cover everything. A quick look through compiling Rust it seems it does at least some of this checking at MIR. I'll have to read more about it.
- nanolith 2y agoThat used to be true, but now we have reasonable model checking tools for C. It's possible to write safer C without the cognitive load of Rust. https://www.cprover.org/cbmc/ https://www.cprover.org/cbmc/
- OtomotO 2y agoGreat now give me tooling of this millenium (no, I am not going back to vendor everything manually and I am not reinventing every basic data structure I wrote in University in ever project I work on) and we have a deal! Oh, also get rid of header files, they are archaic. And I want fearless concurrency... And sum types!
- nanolith 2y agoIf you want those things, you don't want C. Pick a reasonable higher level language you like that makes those decisions for you. My comment was not to imply that somehow C is superior to X, Y, or Z, but rather to point out that the safety problem with C does have a practical solution.
- OtomotO 2y agoFair point, sorry (non native speaker here, for what it's worth) have a wonderful day!
- Cyph0n 2y agoI am sure it is “possible”, but we are talking about practicality here. Why doesn’t the Linux kernel embrace model checking instead of experimenting with Rust?
- nanolith 2y agoIt is quite practical. I'm actually planning a book on the subject. The reason why some Rust enthusiasts have been experimenting with Rust in the Linux kernel is because they are passionate about Rust, and kernel maintainers are looking to find younger people. It's neither an endorsement of Rust nor an argument against model checking in C. The reality is that this tooling isn't yet well known about. As it becomes better known, it will be adopted.
- lomase 2y agoAny kind of Rust is harder than safe C#.
- rowanG077 2y agoIs that really the case? I would say writing bug ridden C is easier then Rust in some cases. Writing working C is much harder then writing safe Rust.
- _bin_ 2y agoMaybe this depends on the application type. I've written a lot of each, and maintaining anything involving concurrency is worlds easier in Rust, since those tend to be the most painful and time-consuming bugs to fix. It's got a learning curve, isn't a particularly easy language, and a big chunk of the "community" sucks, but most of the places I've applied it have been a net hassle savings.