9 ms·
Ada is a criminally underrated tool that is unfortunately probably doomed to perpetually take the backseat to Rust despite Rust not solving all the problems Ada
by seabird 2y ago
Ada is a criminally underrated tool that is unfortunately probably doomed to perpetually take the backseat to Rust despite Rust not solving all the problems Ada does. It's really sad that so many people's idea of safe programming is pretty strictly limited to memory safety, and that because Ada's baseline memory safety (SPARK is a different story) isn't as robust as Rust's borrow checker (in the sense that it doesn't have a borrow checker in favor of just avoiding dynamic allocations whenever possible), that it's a relic of the past.
Ada's type system, SPARK, general clarity on behavior, etc. allows you to structure programs in a manner that makes it hard to Hold It Wrong, especially when dealing with embedded firmware that has all sorts of hardware gotchas. I haven't gotten the chance to use the Tasking primitives in anger yet, but I have a strong suspicion that they're going to bail my ass out of a lot of problems just like the rest of the language has.
My team started at a new employer and made the jump from C to Ada for MCU firmware. We control things that spin real fast and our previous experiences with C definitely resulted in some screwups that left you weak in the knees for a bit. There was some initial hesitation but nobody has any interest in going back now. Rust was floated but we're all glad we didn't opt for it -- memory safety on a system that never allocates memory doesn't hold a candle to Ada's bitfield mapping/representation clauses, ranged types, decimal types, reference manual, formal verification options, concern from the powers that be about providing a stable and trustworthy environment for doing shit that you really don't want to get wrong, etc.
- LiamPowell 2y agoI'm a bit disappointed that we've ended up with Rust in the kernel but not Ada. The kernel relies on GCC and there's already an Ada compiler in GCC, so it wouldn't require adding another compiler as a build requirement like Rust does. There's a couple of major advantages that Ada could have in the Linux over Rust for safe drivers: 1. Having the option to use SPARK for fully verified code provides a superset of the correctness guarantees provided by Rust. As mentioned in the parent comment, Rust focuses purely on memory safety whereas SPARK can provide partial or complete verification of functional correctness. Even without writing any contracts, just preventing things like arithmetic overflows is incredibly useful. 2. Representation clauses almost entirely eliminate the need for the error-prone manual (de-)serialisation that's littered all over Linux driver code: https://www.adaic.org/resources/add_content/standards/22rm/html/RM-13-5-1.html https://www.adaic.org/resources/add_content/standards/22rm/h...
- ksec 2y ago>ended up with Rust in the kernel but not Ada Linus hated Ada. I suspect he doesn't exactly like Rust either but the Tribe is just too strong within Linux.
- Jtsummers 2y agoDo you have a source for that? I've found his remarks on Pascal and C++ but not Ada.
- ksec 2y agoLinus' opinion on Ada (vs Rust): > We've had the system people who used Modula-2 or Ada, and I have to say Rust looks a lot better than either of those two disasters. https://www.infoworld.com/article/2247741/linux-at-25-linus-torvalds-on-the-evolution-and-future-of-linux-2.html https://www.infoworld.com/article/2247741/linux-at-25-linus-...
- LtWorf 2y agorust is in the kernel to attract the young developers, which ada does not.
- Ygg2 2y ago> I'm a bit disappointed that we've ended up with Rust in the kernel but not Ada. Why? Do you program in Ada or Coq? People can't be bothered to track lifetimes, what makes you think they are ready to track pre/post-conditions, invariants and do it efficiently and thoroughly.
- docandrew 2y agoSteve Klabnik (of Rust fame) wrote a (very generous IMO) article about Ada, interesting comparison: https://steveklabnik.com/writing/learning-ada/ https://steveklabnik.com/writing/learning-ada/
- zerr 2y agoThe literally verbose syntax contributes to its unpopularity as well. It is extremely hard to skim/read and comprehend prose-like Ada code.
- shakna 2y agoWouldn't Rust's symbol heavy syntax contribute the same?
- swiftcoder 2y agoI think that since a significant portion of Rust developers come from a C++ background, and C++ uses basically the same set of symbols, it's not a huge barrier to adoption
- shakna 2y agoRust actually has a bunch of oddities, to the point they test them [0]. [0] https://github.com/rust-lang/rust/blob/master/tests/ui/weird-exprs.rs https://github.com/rust-lang/rust/blob/master/tests/ui/weird...
- swiftcoder 2y agoThere's really only one sigil in there that isn't in C++ (the ' single-quote to name lifetimes and labels). And it's missing several ambiguities that plague older C++ grammars (i.e. is >> a greater than, or closing two template expressions?)
- CRConrad 2y ago> (i.e. is >> a greater than, or closing two template expressions?) I thought it was a pointer-dereference signifier(, or maybe an object-string-stream thingy)? If you mean C++, that is.
- crabbone 2y agoI like Ada, but I tend to agree. "End Something_Somethig_Something" is really a mouthful (compared to "}"). And programmers are superficial like that. Ada wouldn't be the first decent language being dismissed for inconsequential aspects like this one.
- Yoric 2y agoFor what it's worth, many Rust developers (including myself) are also Ada fans. Note that ranged types, decimal types, etc. can fairly easily be emulated in Rust, with what I find is a clearer error mechanism. SPARK is, of course, extremely cool :) There are several ways to work with theorem provers and/or model checkers in Rust, but nothing as nicely integrated as SPARK so far.
- zozbot234 2y agoI would quibble with the "fairly easily" part. It will likely become possible to make them as ergonomic as the Ada variety if Rust's const generic and constant evaluation facilities are extended far enough, but this would also open up the can of worms of essentially giving Rust the full capabilities of a dependently-typed language (at least in its compile-time subset), which Rust's dev community may not necessarily be OK with.
- Yoric 2y agoI'll grant you that Rust is not nearly as ergonomic as Ada in this domain, but doing it manually is fairly easy. Turning it into a library is a bit more complicated - these days, I'd do it with macros. Of course, making sure that the compiler knows about it for optimization purposes would require lots of const generic.
- kevlar700 2y agoThe real benefit of Adas typing is that it is so easy to utilise often preventing logic errors.
- Yoric 2y agoAnd this is definitely a strong benefit. The benefit of Rust's typing is that (in the absence of `unsafe` or bugs in the compiler or stdlib), it's a simple theorem prover. Much less powerful than the theorem provers you can use with SPARK, but it's a start :)
- mentalgear 2y agoIdeally, Rust would start adopting excellent features like Ada's SPARK, and vice-versa Ada get inspired by Rust's good parts as well.
- typ 2y agoThe popularity of a programming language is not always about what the language offers. I would say a comprehensive, well-documented, mature set of standard libraries for its target audience is far more important (notable examples like R, Python, and Go). Last time I checked, Ada doesn’t even have a de facto, high quality TLS/crypto library, let alone various essential protocol/format codecs, yet the core team (AdaCore I assume) puts a lot of resources into offering a few sophisticated flagship IDEs that potential hobbyists would never use (they already have vim, emacs or vscode). I understand that as a business they have to sell something for revenue and they cannot sell standard libraries. So, that’s probably a dilemma that we cannot have the nice things for Ada to take off.
- rendaw 2y agoAlso a package manager - Rust's is excellent and a huge reason to use it over C/C++. I see Ada has Alire but that seems like a fairly recent development and I don't know how it compares.
- LiamPowell 2y agoThere's some thick bindings to libtls that coincidentally happen to be written by the author of the article. There's also some OpenSSL bindings in Dmitry Kazakov's Simple Components and some in Ada Web Server by AdaCore, although they're pretty minimal. I think most applications of Ada are in embedded systems where you don't often want anything not in the standard library.
- uticus 2y ago> I think most applications of Ada are in embedded systems... Ada is heavily used and carries a historical influence not only with embedded software space, but also with hardware space: VHDL is one of the two major hardware description languages used in ASIC design and FPGA implementations. (The other language is Verilog, based on - you guessed it - C, because of its popularity.) "Due to the Department of Defense requiring as much of the syntax as possible to be based on Ada, in order to avoid re-inventing concepts that had already been thoroughly tested in the development of Ada, VHDL borrows heavily from the Ada programming language in both concept and syntax." - https://en.wikipedia.org/wiki/VHDL#History https://en.wikipedia.org/wiki/VHDL#History
- Keyframe 2y agoAda is a lot of fun and a great thing which is ruined (and blessed) by the fact there's de facto only one implementation and company behind it out in the open, and that is semi-closed / license PITA. There were improvements over the years by AdaCore, but I think this altogether hurt the adoption of such a great language in general - no other wide open implementation (like Rust has). If you want to see an extreme example of such a hurt, take a look at Allegro CL and Franz; Imagine having that out in the open and what it'd do for CL, but at least CL has great alternatives in the open like SBCL, whereas Ada doesn't.
- CRConrad 2y ago> no other wide open implementation (like Rust has) So (at least according to pjmlp in https://news.ycombinator.com/item?id=42548360 https://news.ycombinator.com/item?id=42548360) Rust also only has a single "wide open" implementation. Which means Rust doesn't have any "other" open implementation either, right? Honestly, it's hard to know what of all the pro-Rust stuff one sees (here and elsewhere on-line) to take seriously, when its advocates constantly -- consciously or not -- exaggerate its virtues like this.
- LiamPowell 2y agoAs far as I'm aware, the compiler AdaCore sells is just GCC. You can install GCC built with Ada support from your distros package manager and it will just work. You can also download builds from here: https://github.com/alire-project/GNAT-FSF-builds https://github.com/alire-project/GNAT-FSF-builds
- debugnik 2y ago> As far as I'm aware, the compiler AdaCore sells is just GCC. The compiler yes, but I'm convinced FOSS gnatprove must be outdated in some way: Last time I tried following AdaCore's SPARK manuals, certain basic aspects and pragmas didn't work correctly on the latest version. Not to mention when SPARK aspects sometimes broke the LSP and formatter.
- Keyframe 2y agoIf something hasn't changed, FSF builds are a year behind libre version (by design), and libre version is GPL3 cancer which is not suitable for commercial development. You're then stuck either with a year old version or buy into AdaCore Pro version of it. Not great, not terrible.. but that's kind of the only game out in the open, which is what makes it different from most of other languages out there.
- pjmlp 2y agoIt suffered from high prices in compilers when it had an opportunity, plus Modula-2 and Object Pascal being good enough for those that cared about safety on 16 bit home computers. It also didn't help that the UNIX vendors that had Ada compilers like Sun, it was an additional purchase on top of the development SKU that already had C and C++ included.
- jjnoakes 2y agoMemory safety and the borrow checker are useful even in the absence of dynamic memory allocation. This still doesn't bring rust and ada to the same place, but it is important to clarify that piece.
- kevlar700 2y agoSpark supports borrowing which is easier to use than Rusts now. It also prevents memory leaks.
- lenkite 2y agoI never even knew that this "Ancient Language" had dependent types. Always thought it was a "modern" invention of snazzy newer academic languages like Idris, etc. But, its easy to figure out why it didn't become popular. C/C++/any other top10 language all had free compilers available to everyone. Ada didn't during the explosive era of computing expansion. Also, not a problem nowadays with IDE auto-complete/snippets but the language was too verbose for older generation of programmers.
- Lucretia9 2y agoYou talk about C and C++ yet call Ada "ancient," C from 1969 and C++ from 1979. Whereas Ada's first version is from 1980 and first standardised version (different to 1980) in 1983. Yeah, "ancient."
- samatman 2y agoVerbosity was genuinely expensive at the time. Two ways: until the mid-80s, 5 1/4" floppies held between 100 and 250kB depending on format, so a program which used up three times as many bytes (I think that's a good multiplier from C to Ada) is making a meaningful difference for transfer, backups, storage. What's probably more important is that 80 columns was far and away the likely maximum for a screen, and 40 columns wasn't unheard of. The word PROCEDURE took up 11 to 22% of the column width! This wasn't a show-stopper, Pascal uses a similar syntax (both of them derived from Algol of course) and was pretty popular, but plenty of people complained about Pascal's verbosity as well, and Ada is definitely more verbose than even Pascal. The lack of autocomplete (even things like snippets were relatively uncommon) didn't help, but mainly, verbosity imposed real costs which are mitigated or irrelevant now.
- rad_gruchalski 2y agoI really wanted to use Ada, at least learn it. Concepts are nice but I gave up when started looking into unicode support. It was wild, a bit discouraging. Or has the situation changed? What’s the unicode status in Ada?
- docandrew 2y agoYou can embed and work with UTF-8 strings with no issue (I have source with emoji string literals), but if you need complex manipulation of code points vs glyphs etc. I’m not sure how robust the libraries are for what you are trying to do. https://ada-lang.io/docs/learn/how-tos/gnat_and_utf_8/ https://ada-lang.io/docs/learn/how-tos/gnat_and_utf_8/
- rad_gruchalski 2y agoThank you, this is very useful information.
- cenamus 2y ago> We control things that spin real fast and our previous experiences with C definitely resulted in some screwups that left you weak in the knees for a bit. Ha, you could almost read this as a stuxnet joke