4 ms·
C is not X-safe because you can’t declare conformity in the type system. In Rust, if I understand the article, you can create a “trait” that marks a type as co
by sitharus 2y ago
C is not X-safe because you can’t declare conformity in the type system.
In Rust, if I understand the article, you can create a “trait” that marks a type as conforming to an invariant, so in the article they marked thread-safe structures as Send and the thread functions as requiring types that implement Send.
Send isn’t an API to implement or type definition, it’s a sentinel saying “I declare that this type conforms to the documented expectations” even though the expectations can’t be checked by a compiler.
- dzaima 2y agoMore generally, with C you can't restrict what can (accidentally or not) interact with the internal unsafe bits (without the cost of forcing the data to always live in the heap at least; or perhaps annoying field names that are automatically searched-for by your build system, though then you're essentially making a DSL), or even force using the "safe" parts properly (not enforced at compile-time, at least) outside of, again, a rather limited subset of cases. As a very general example, you can repeat basically any statement in C twice and it'll still compile. If you get lucky, the compiler might tell you you've ended up with a double-free or something, but that's a very limited set of cases, and won't help if the second copy is invoked down a couple function calls. There may be some ways to still get additional true guarantees in C, but they'll be rather more restrictive than ones you can write in Rust, and you'll likely end up with overhead, which tempts skimping out on doing things properly in the name of performance.
- uecker 2y agoIndeed, the double consumption you can not express in C. But invariants of data structures are not a practical problem in C. Looking at the Rust code of this project though, I trust my C code a lot more though... ;-)
- dzaima 2y ago> invariants of data structures are not a practical problem in C. Is that not the cause of like all memory safety vulnerabilities, which are like 30%-or-whatever of linux ones? I've certainly written my fair share of mistakes around invariants in C code. Of course, if you're a perfect developer, indeed the choice of language won't end up mattering.
- uecker 2y agoStraw man fallacy. .
- 0xDEAFBEAD 2y ago>it’s a sentinel saying “I declare that this type conforms to the documented expectations” even though the expectations can’t be checked by a compiler. Interesting. So perhaps the next step is to sprinkle asserts in randomly at runtime to help with catching bugs.