9 ms·
Facebook puts bounties on bugs in the D programming language implementation
- thepumpkin1979 13y agoGoogle supports Go. Mozilla supports Rust. Facebook should actively support D.
- simendsjo 13y agoWould be great, but the situation is a bit different. Google creates Go. Mozilla creates Rust. Facebook employs one of the designers of D.
- smegel 13y agoAnd Go/Rust represent new paradigms whereas D aims to be a less sucky C++...would be interesting to know why Facebook took this approach.
- simendsjo 13y ago"New" paradigms? Care to elaborate?
- keeperofdakeys 13y agoIn brief, all three of Go, Rust and D are designed to replace C++. Go is built around concurrency, so applications you write are almost instantly parallelisable. It uses a simple garbage collector, to make it easier to program. It was developed at Google, with none other than Rob Pike being involved. http://golang.org/doc/faq http://golang.org/doc/faq. Rust is designed to help prevent memory leaks, while still enabling manual memory management. https://github.com/mozilla/rust/wiki/Doc-language-FAQ https://github.com/mozilla/rust/wiki/Doc-language-FAQ. It was written by mozilla, because using C++ for a web browser leaves quite a few memory leaks. Mozilla are also building a prototype browser engine in Rust, called Servo, http://www.mozilla.org/en-US/research/projects/#servo http://www.mozilla.org/en-US/research/projects/#servo. Although its future is still quite uncertain at this point. I haven't had too much contact with D, but from what I understand, it's designed to be C++ done right, while keeping compatibility with many parts of C. http://dlang.org/overview.html http://dlang.org/overview.html
- steveklabnik 13y agoGoogle has been steadily moving away from "Go is a C++ replacement" (because it's not) and toward "Go is a Python/Ruby replacement." (which fits it _much_ better) Also, you're descriptions of Go and D are great, but I'd say that Rust is more "Concurrency of Erlang, speed of C++, type safety of ML/Haskell".
- tptacek 13y agoI'm not sure that this is a distinction (C++ vs. Python replacement) that means all that much.
- steveklabnik 13y agoFor me, it helped me get less mad about Go. ;) A Python replacement accepts that GC is mandatory, while a C++ replacement needs to not have a GC, as the most prominent example of this distinction.
- mjn 13y agoFor some use cases that would matter, but for a lot of C++ use-cases, no GC isn't really fundamental. Large codebases increasingly use the "C++ GC", aka RAII with std::shared_ptr, as the de-facto-standard way of managing memory. For those kinds of applications, how D's GC compares then just becomes a matter of performance tradeoffs between different GC implementations, not a matter of GC vs. no-GC.
- steveklabnik 13y agoAbsolutely. GCs have been improving a lot over recent years, and there's lots of software that's written in C++ that doesn't have to be. You can write D without any GC at all, though: you lose a lot of the standard library at present, but I've done it. It's not possible, in my understanding, to turn the GC off in Go.
- 13y ago
- jnbiche 13y agoLooking back over the D forums, D implementers have been promising to support shared libraries since at least 2006, and as far as I can tell, none of the major D compilers support it yet. D is a very nice language, but without shared libary support in Linux or Windows, its use to me as a low-level alternative to Python or Lua is limited. Go clearly is interested in static-only compilation, and they've said as much. Rust is still too alpha to use for serious projects, and to be frank I find it carries much of the complexity that turns me off from C++ (I really wanted to like Rust). Meanwhile, I've found Nimrod can happily handle shared library support, meaning I can easily make nice extensions for Python and Lua. Nimrod is just as fast as D, and probably a bit faster than Go and Rust. Syntax is very nice for Pythonistas, and it has a very full standard library. I've also noticed that Nimrod is getting some very good exposure here on HN, and people smarter than I am are starting to play around with it (in addition to the people smarter than I am who invented it and brought it to this level). In the end, the only new low-level language without big company support may turn out to be the winner here.
- simendsjo 13y agoShared libraries work on gnu/linux (since 2.063..?), they just haven't been announced (the devs want some "beta" testing first I seem to remember). EDIT: Ok, since 2.064
- WalterBright 13y agoShared libraries are now supported on Linux as of 2.064. Other platforms to follow.
- zanny 13y agoAnd in many ways Microsoft is now supporting C++. Though that language sees a lot more cross pollination between companies because of its ubiquity and age. I find it interesting as a programmer who loves to operate in the space that uses useful abstractions but still is running on raw hardware, as C++ improves rapidly with the new release model since C++11, my interest in D wanes. I hope that most of what D is eventually seeps into C++, but nowadays I don't mind my C++ syntax and don't feel like I'm fighting with it as much.
- cldr 13y agoSame here; I used to be a huge fan of D but then C++11 came along and solved most of my problems (and some that I didn't know D had).
- pjmlp 13y agoThe problem is that when you work on big teams and are forced to work in C++98 with lots of style guide restrictions. Or when management will ever allow for updating the compilers on the build infrastructure. Also compiling C++ code in C++11 mode won't make many developers use Modern C++, instead of C compiled with a C++ compiler, as many still do. Maybe it works for your context, but in a global context we need to have safer languages for systems programming. Which were already available when C didn't had any meaning outside UNIX.
- cldr 13y agoThat's true, but you can write C code in D as well, so switching to D won't make people write idiomatic code either. If they won't learn how to use one correctly then they won't care enough to use another correctly. And if your company won't let you upgrade compilers, then it certainly won't let you switch languages altogether.
- pjmlp 13y ago> That's true, but you can write C code in D as well, so switching to D won't make people write idiomatic code either With a Pascal like type safety. You need to be explicitly mark your code as @system to be allowed to do C like tricks. This alone is a very big advantage.
- jekdoce 13y agoIsn't it better for the community if everyone support the same language and add a lot of solid standard libraries?
- _random_ 13y agoFacebook is the only one smart enough not to invent a new wheel. Not a fan of D though.
- mixmastamyk 13y agoGood for them. I was a bit surprised by the amounts though. Is it enough to motivate? Also, I notice the BountySource site is blank without javascript on. I'm not one who demands that every site work w/o it. But, they should at least show their banner and message that it needs to be turned on. The noscript tag is twenty years old, no?
- simendsjo 13y agoI noticed this too. But I wouldn't single them out. A lot of sites I visit has problems without js. It's even worse when the site isn't blank - _some_ things just doesn't work or show as they should...
- sampk 13y agohttp://forum.dlang.org/thread/l65mvq$du0$1@digitalmars.com#post-l66f6u:241doe:241:40digitalmars.com http://forum.dlang.org/thread/l65mvq$du0$1@digitalmars.com#p... > The D Programming Language? $80? Ha... Fail. How do you mean that? The budget is of course much larger than that. I'd just started assigning it. Andrei
- mkramlich 13y agosurface interpretation: they want them fixed sneaky possible reason: recruitment strategy that's more likely to suss out the more "elite" devs likely: my bet, a mix of both
- simendsjo 13y agoThe sneaky possibility has already begun. You just have to follow the depths of the newsgroup :) http://forum.dlang.org/post/l54orn$tn3$1@digitalmars.com http://forum.dlang.org/post/l54orn$tn3$1@digitalmars.com
- yeldarb 13y agoAnd when can we put bounties on Facebook bugs?
- lacker 13y agoGood question. What Facebook bug would you put a bounty on? (ps I work on Facebook platform so this is not an idle question)
- yeldarb 13y agoWish I would have seen this earlier. I run a game on Facebook platform and we oftentimes have bugs that you guys likely consider corner cases because they only affect a very small subset of your users. These tend to happen to our heaviest users who account for a large portion of our revenue. These power users either use obscure edges of the platform or act in unique ways to other users. For instance, many of our top players have been completely unable to access their friends list for the past 2 weeks now. Playing with friends is a hugely vital component of our game and this bug makes it completely unusable for these players (many of whom have been active, paying users of our game for several years now). See Bug 1420634571501183 (recently marked as a duplicate of 681781621832581 which I have no way of verifying since that user didn't post an error message and was using FQL rather than the graph api.. I'm hoping this bug doesn't just get lost now that it's been marked as a duplicate). This isn't the first time we've had a bug like this happen. Allowing developers to put a bounty out would be a strong signal that it's an important bug to fix. It's not necessarily about the bonus revenue to Facebook, it's about giving developers a way to get truly important bugs prioritized. Or heck, being able to buy 5 minutes of a real Facebook engineer's time would be valuable as well. See also: Bug 1394861264086269 which is a bug marked as Invalid but has to do with the (relatively obscure) "Game Groups" Graph API not matching what's actually shown on the web interface. Bugs 177435992460351 and 242967435851521 which will probably be closed in 5 months because "We are prioritizing bugs based on impact to the developer community. As this bug report has not received much attention from other developers, we are closing it so as to better focus on the top issues." even though they've been confirmed by FB just like countless other bugs I have reported over the years.
- 0x0 13y agoThe author of the post also had a Reddit AMA recently, related to Facebook's usage of D: http://www.reddit.com/r/IAmA/comments/1nl9at/i_am_a_member_of_facebooks_hhvm_team_a_c_and_d/ http://www.reddit.com/r/IAmA/comments/1nl9at/i_am_a_member_o... Among other things, he wrote the book "The D Programming Language".
- pera 13y agooh another of those bounties programs... but maybe this one is different from the rest? If you ever find any security issue don't expect to obtain a bounty from the big corps easily, and not even a "thanks". Once, the co-founder of one of the most important security companies told me "do not expect to receive a bounty without sending a minimum of 10 emails explaining the same thing in 10 different ways... average 20". It's a sad truth, and I think this means that usually legit critical security issues reports will not be properly rewarded because most people get tired quickly. One year ago I discovered a session hijacking vulnerability on Facebook, the guy who respond my messages didn't even know what secure flag is. After asking me how to solve the bug (the solution was actually pretty simple) they never replied to me again. With Google was the same thing: last year I found leakage of sensitive user information because of bad cookies configuration, 0 bounties 0 thanks. Another bad experience I had with Google, but maybe a bit of topic (sorry): almost two years ago the gmail's cert changed for apparent no reason using a new CA, and it seemed that nobody else was having this issue (ie no mentions of this new cert on the web, googling the fingerprint returned 0 results) except me. I accepted this new cert on my laptop in my home; but then the "funniest" thing happened: when I connected to gmail from my university the previous cert appeared again, "it's ok.. nothing strange is happening here", but then when I went back to my home the new cert showed up again! my paranoid level went to over 9000 and immediately I connected through Tor to gmail (yup, the old nice cert was there again) and sent an encrypted mail to google's security team explaining everything, with the fingerprints and certs info, _including_ at the end of my message my pgp pubkey. One week and a half latter.. I received an email from the "security team": they replied my message in plain text, my message was quoted unencrypted (!) and they asked me how I discovered this, I told them that my browser checks for every new cert. I also told them if it would be possible to not quote in plain text encrypted mails. Then, after two days I got a new email from them, again plain taxt, and it was pretty minimalistic "We checked out and the new certificate is ok" EOF no digital signature no nothing, wtf! oh well... at least on the next day I connected to gmail in my home and the old good cert was there again :) (and the strange new cert never appeared again). A late Halloween story.
- CJefferson 13y agoDid you even read the article? Did anyone who update you read the article? This has nothing to do with security issues. It is to do with fixing specific bugs in the D compiler and libraries.
- hawkharris 13y agoMaybe they'll put a bounty on getting 13-year-olds to make wall posts instead of sending self-destructing photographs.
- deleted 13y ago[deleted]