Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Gankro
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
Gankro
10y ago
I always mess this up, but here's something from memory: I believe there's ABI things that motivate stage 2. The compiler built in stage 0 has historically had special ifdefs to deal with "features that don't exist in th
32.
▲
by
Gankro
10y ago
I have no regrets. Everyone should get to know the fear and joy of this Makefile.
33.
▲
by
Gankro
10y ago
Ah good, now the whole world gets to enjoy the greatest Makefile ever. For other curiosities of Rust's history and bootstrapping process, I recommend brson's annotated stdlib: https://github.com/brson/annotate
34.
▲
by
Gankro
10y ago
ASLR is only relevant if you're exploiting a memory-safety bug. It is therefore "useless" in a safe Rust program (just as it's "useless" in Python, Java, JS, etc), but this is assuming: * all the underlying uns
35.
▲
by
Gankro
10y ago
fwiw this appears to be a goal of people working on speccing out Unsafe Rust stuff. You also don't need to worry about interpreting any english specs today, because there just aren't any specs at all yet!
36.
▲
by
Gankro
10y ago
Yes. However Rust's precise mitigation only works because it doesn't use hashcoding (Swift does). A possible mitigation that's similar to Rust's would be for each Dictionary to post-process hashes with some per-Dictionar
37.
▲
by
Gankro
10y ago
There's a load factor in Swift's Dictionary but it's hardcoded. Same for Rust. (I've maintained both implementations) I assure you the bug is as described. I wrote it up the initial bug report and what needed to be done
38.
▲
by
Gankro
10y ago
Agreed on this, but this is ignoring the much more subtle effect of unwinding: it introduces optimization barriers around every function that "might" throw. As a basic example: x = 1 something_that_can_fail() x = 2
39.
▲
by
Gankro
10y ago
It's worth noting that Haskell has "shared xor mutable" via the ST Monad. It effectively providing mutable memory cells that aren't allowed to "escape" a scope in much the same way as `&mut`. Also having ac
40.
▲
by
Gankro
10y ago
Admittedly there's still a syntactic difference between move and copy -- with Swift and C++'s definition of copy. Rust calls that Clone, though. :)
41.
▲
by
Gankro
10y ago
Can confirm, used null all the time in Rust. The raw pointers are important native Rust constructs, although they do skew to supporting C idioms as much as possible (e.g. `* const T` and `* mut T` is basically a worthless distinction within
42.
▲
by
Gankro
10y ago
Using typenum in production isn't a fireable offence?!
43.
▲
by
Gankro
10y ago
Swift uses them in the standard library to do cute things like a space efficient `Int63?`, but doesn't currently expose them as a general user facility.
44.
▲
by
Gankro
10y ago
Rust isn't hashcode based. You don't define how to hash a type in that way. You define hashing algorithms which operate on arrays of bytes. All a type has to do to implement hashing is specify how to feed its bytes into a hasher.
45.
▲
by
Gankro
10y ago
If you can't already hash/compare an array of bytes, something terrible has happened with your language design.
46.
▲
by
Gankro
10y ago
You can turn the Twitch HTML5 player off. I had to do this on my laptop (chrome on macos) a few months ago because the HTML5 player was too unstable. Like, I didn't even know they had made the change, I was just losing my mind because
47.
▲
by
Gankro
10y ago
About this many: https://github.com/rust-lang/rust/blob/235d77457d80b549dad3a... (This file is no longer in master because the compiler bootstraps from the previous stable release; too lazy to accurately isol
48.
▲
by
Gankro
10y ago
The more impressive part is: that manages to self-preserve across hundreds of Rust language/compiler versions with wildly varying designs and semantics all the way up to today's version.
49.
▲
by
Gankro
10y ago
I still believe in the dream of the mythical Graydon Backdoor in OCaml. No one could even be mad, it would be so good.
50.
▲
by
Gankro
10y ago
This particular attack is done entirely in the rustc frontend, so adding another way to build the backend shouldn't matter? One requires a new implementation of the frontend to apply diversity mitigations.
51.
▲
by
Gankro
10y ago
Swift's long term goals are to handle the exact same space as Rust, and that means the exact same performance/control goals. We're just starting higher up, and working our way down. Rust is a lot more mature! RIP libgreen.
52.
▲
by
Gankro
10y ago
Yeah this is clearly someone who's into FP. If you rewrite this code to replace the map/sum with a for loop it's basically identical in length, while being completely idiomatic.
53.
▲
by
Gankro
10y ago
Yeah, it just wasn't clear to me (or anyone else I asked) that GEP wasn't "allowed" to strictly interpret signedness and inboundness. LLVM docs, amirite?
54.
▲
by
Gankro
10y ago
If you trigger this fallback (e.g. someone is colliding all your hashes), your entire collection is probably stuffed into one bucket. Degrading only individual buckets is of course a nice middle ground that avoids harsh discontinuities in p
55.
▲
by
Gankro
10y ago
Hmm, a quick checklist-style thing is a pretty good idea!
56.
▲
by
Gankro
10y ago
> I would say that this is from a time when the invariants were not understood. Yeah, but it's not like "oh this is an obvious thing to consider trusting the caller about". It's an exceptionally niche problem that you
57.
▲
by
Gankro
10y ago
> I have yet to see any of this. mem::forget-pocalypse was this. (Rc/Arc, Vec::drain, thread::scoped) Any UB bug that results from an overflow is kind've implicitly this. BTreeMap::range still has an UB bug from trusting the
58.
▲
by
Gankro
10y ago
Type punning is a mess in C because you have to jump through hoops to make it legal. The language subsequently failed to provide ergonomic solutions to the very real problems type punning solves in a systems language. Type punning is perfec
59.
▲
by
Gankro
10y ago
I actually talked to Lattner about the isize thing a few months back -- according to him it's fine to overflow while doing GEP because llvm shouldn't care if you pass in negative offsets to represent really big positive ones.
60.
▲
by
Gankro
10y ago
When SipHash was presented at CCC, it was alongside the proof of concept attacks against MurmurHash and CityHash. See the "Attacks" section of [0]. Murmur was notable at the time for its use in Java and Ruby. Ruby has since moved
More ›