Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Gankro
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
121.
▲
by
Gankro
11y ago
There isn't any definition of memory safe, nor any published version of C++, for which this is a true claim.
122.
▲
by
Gankro
11y ago
The problem with Ranges is you can't trust anything they tell you about bounds, and they can't trust you about bounds, so every access has to be checked. This hurts in algorithms like binary search and sorting (which are some
123.
▲
by
Gankro
11y ago
Well, except for literally all the developers that use Unity, Flash, Java, and GameMaker (but I guess they aren't True Professionals?) In the space of core engine stuff, I agree.
124.
▲
by
Gankro
11y ago
There's never been a C-based compiler. Rust started out as OCaml. A true bootstrap would take weeks of non-stop compiling. You'd end up compiling rustc itself about 900 times, ignoring all the different LLVM builds, I think. Rust
125.
▲
by
Gankro
11y ago
Don't. This would be a terrible lint. It's perfectly reasonable to expect an index to be in bounds for various reasons.
126.
▲
by
Gankro
11y ago
We use panics for logic errors. This is an important distinction. We will never throw if a file couldn't open, or if a string couldn't parse, because these are expected errors that you should explicitly handle. Catching panics sho
127.
▲
by
Gankro
11y ago
The guarantee I prefer is "If there's a segfault and you didn't write `unsafe`, it's not your fault". This is not necessarily referring to a single change, but rather the application as a whole. Dependencies like li
128.
▲
by
Gankro
11y ago
If 16 bits is enough, use an explicitly 16-bit integer. If you want something architecture-sized (e.g. because it's dealing with pointers/addresses), use things like `size_t` which makes the intent much more clear, and which are b
129.
▲
by
Gankro
11y ago
Yes, they trigger a panic. No, there's no ASan. There isn't as strong a need for ASan in Rust because so little code is unsafe. Most of the time, the only reason you drop down to unsafe code is because you're trying to do som
130.
▲
by
Gankro
11y ago
I almost pinged Niko to be like "you know Java has closures right?" and then I saw him mention `ret` and was like "oh this is ancient, ok".
131.
▲
by
Gankro
11y ago
"everything is floats" is also technically a solution, but with a curious fail-state.
132.
▲
by
Gankro
11y ago
The existence of a densely populated area doesn't imply that most people live there. The majority of a population can be sparsely distributed just fine. In Canada it only became true ~80 years ago that most lived in urban areas accordi
133.
▲
by
Gankro
11y ago
Admittedly, a lot of us still giggle whenever Coq comes up. :)
134.
▲
by
Gankro
11y ago
As far as I've seen, the text interface is radically more unstable. Like when they recently striped types from pointers, I was like "oh no that sounds like it'll be a lot of work to upgrade to", and all the backend pee
135.
▲
by
Gankro
11y ago
Rust is trying to improve the quality of core infrastructure, not random CRUD apps. It takes time for large companies to rewrite and migrate these systems, but it is indeed happening behind closed doors (source: private conversations with s
136.
▲
by
Gankro
11y ago
Multi-process to isolate tasks, and whitelists for system apis to minimize the priviledge of each task. Servo has no back-compat concerns. It will be using browser.html -- no legacy XUL addons at all.
137.
▲
by
Gankro
11y ago
Except if it's really random, after enough trials you'll have some clearly random distribution, with some distortion related to the actual cost. Figuring out the cost is just some statistical analysis away. See e.g. https:/&
138.
▲
by
Gankro
11y ago
Awesome, cool! The repo's a bit of a commented-out mess (I was trying to get a bunch of broken impls working before I had to get back to real work), so let me know if you have any trouble. Always happy to help people learn the language
139.
▲
by
Gankro
11y ago
Rust's solution is to provide the hash function as a generic parameter so you can just Fnv/Xx/Sip based on your workload, with Sip as the default if you don't pick. Unfortunately this is mostly incompatible with the adap
140.
▲
by
Gankro
11y ago
I've literally never heard of Vhash, and I see no references to it outside of the 2007 paper. As far as I know, the state of the art for "fast and secure" is still SipHash 2-4 or 2-3. While SipHash perf is generally quite goo
141.
▲
by
Gankro
11y ago
As long as your usecase isn't worried about hash-flooding [0]. Unfortunately too few people know this is even an attack, so it may be reasonable for languages to default to a stronger hash algorithm for safety, but this isn't the
142.
▲
by
Gankro
11y ago
Rust automatically chooses the "best" strategy based on how you're building the source, per https://github.com/rust-lang/rfcs/blob/master/text/1183-swap... If you're building a d
143.
▲
by
Gankro
11y ago
Yeah I was really surprised to see a significant post on this with no mention of the hilarious dangers of variance, sharing, and overwrite-ability. In Rust it ends up actually being pretty clean because mutability is inherited. Generic valu
144.
▲
by
Gankro
11y ago
To be clear, this is applying the classic observation that if you keep the first and last letter correct, humans are really good at unjumbling the center.
145.
▲
by
Gankro
11y ago
Do you want to proceed forward one byte, "character", grapheme, or codepoint?
146.
▲
by
Gankro
11y ago
There's two aspects of complexity with strings: 1) 40 years of crazy encodings and languages. 2) human languages are wildly diverse and basically any assumption you wish to apply is broken. For 1, any system that wants to deal with the
147.
▲
by
Gankro
11y ago
std provides String (utf8), OsString (bytes/wtf8), PathBuf (bytes/wtf8), CString (null-terminated). Each has their own unsized view: str, OsStr, Path, and CStr. We also provide AsciiExt for those times where you really truly belie
148.
▲
by
Gankro
11y ago
It's also funny because memory leaks literally aren't a memory safety issue. If they were, every garbage collected language would be memory-unsafe.
149.
▲
by
Gankro
11y ago
Technically Rust doesn't have proper linear typing, only affine typing. Destructors give you "basically" linear typing, but there's ways to bypass destructors both explicitly and accidentally (though if memory safety isn
150.
▲
by
Gankro
11y ago
Weirdly the i586 is the problematic one. 3, 4, 6, 7, and 8 all apparently work fine. https://users.rust-lang.org/t/i586-support-illegal-hardware-...
More ›