3 ms·
>> Will this really make coreutils more secure? In the long run yes. Sure, many logic bugs happen in Rust programs as well, but memory safety bugs are another
by senfiaj 16d ago
>> Will this really make coreutils more secure?
In the long run yes. Sure, many logic bugs happen in Rust programs as well, but memory safety bugs are another level of hell. At least many classes of exploits will mostly be impossible. Also, Rust program failures tend to be more predictable. For example, in C/C++, if you do out of bound writes in an array or writes in a freed memory block, the behavior is undefined. The program might crash, the memory might be silently corrupted, or nothing might happen at all. In a normal (non unsafe) Rust code these kinds of issues are either prevented by static checks or become explicit runtime panics.
While the migration could be done more gradually, 26.10 is not an LTS release and is not considered stabe enough. The next LTS is 28.04, so I hope there is 1.5+ years for things to stabilize.
- aliceFish 16d agonew C++ STL standard makes it no more undefined.
- senfiaj 16d agoIn theory yes, but it requires enough discipline and knowledge. A language that makes it harder to write bad code still has an advantage over a language that doesn't care about bad code.
- rshackleford1 16d agoCan you point to any outstanding, unfixable, memory safety bugs in the coreutils that justify such a rewrite? This is a cynical license issue, not a safety issue. I think there are much more severe security risks which come from behavior divergence of replacement tooling than memory safety bugs from 40 year old widely used/tested software.
- erminpour 16d agoRusty Shackelford :D
- DeathMetal3000 14d agoThe software world is littered with memory vulnerabilities and you’re here still asking for proof? You may not like Rust and that’s fine. But don’t continue propagating the attitude that got us here in the first place.
- rshackleford1 10d agoI am talking about the coreutils, not the software world... Yes, memory saftey bugs exist, but they are not the end of the world or that difficult to fix in most cases. The coreutils have been battle tested for decades. Surely it is easier to fix new bugs that are found, memory issues or otherwise, than it is to rewrite from scratch because they "might" have memory safety bugs. It is a waste of resources to rewrite the coreutils based on some ideological allergy to this specific kind of bug. Or you can accept that it is purely a licensing issue being dressed up as a security concern.