3 ms·
This is covered in the fuzzing project's FAQ https://fuzzing-project.org/faq.html https://fuzzing-project.org/faq.html "if you start a new software project it
by rquirk 12y ago
This is covered in the fuzzing project's FAQ https://fuzzing-project.org/faq.html https://fuzzing-project.org/faq.html
"if you start a new software project it is a good idea to avoid C right from the start. however ... most major software components we use today [are] written in C. Rewriting things from scratch is hard, compared to that finding bugs with fuzzing is the low hanging fruit."
While something like Go has good performance, writing low-level tools in interpreted languages (Python, Ruby, etc) means you would always have the performance overhead of firing up the interpreter for everything. A hypothetical non-C system would feel sluggish compared to what we have now.
- pjmlp 12y agoWho said anything about interpreted languages? Modula-2, Modula-3, Go, D, Haskell, OCaml, Oberon, Ada, Extended Pascal, Object Pascal, C#, Java, ... The list of languages with native code compilers is quite big, no need for interpreters. The problem with fuzzing is that, like the use of safer languages, it just won't get adopted unless forced down the throat of developers. This is why, Google, Microsoft and now Apple are adopting a "our way or the high way" in memory safe languages for their platforms. After all, proprietary APIs would already be enough for platform lockin. I do agree no one is going to re-write the huge amount of code out there. However it is already good enough if new code get written into something else.
- femngi 12y agoIt's not just about native vs interpreted though. Most of those languages use garbage collection for memory allocation which is still going to be an unacceptable performance hit for most of the domains where C and C++ are still in use.
- pjmlp 12y agoUnless one is writting device drivers, kernel modules, signal processing algorithms or anything else that needs to fit in 16ms, there is hardly any reason to use C or C++. Languages like Object Pascal, Modula-2 and Ada that don't use garbage collection and many that do, like Modula-3 provide much more control about value types and GC behavior than what Java and C# are known for. Finally many of the garbage collection jitter issues are caused by developers clueless about writing GC friendly algorithms or simply how to use a profiler.
- rmc 12y agoWhat about Rust from Mozilla?