Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Gankro
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
151.
▲
by
Gankro
11y ago
Doing lots of automated analysis on a patch is definitely great. However I'm talking about the kind of analysis that really requires humans who understand the larger ecosystem. A bot can't understand that some interface design is
152.
▲
by
Gankro
11y ago
So basically, anything that looks like a real patch should be merged? This is a terrifying idea. Human review is necessary to determine if a change is semantically sound and technically/politically desirable. No amount of automation co
153.
▲
by
Gankro
11y ago
Is this not a ridiculous thing for an application to check for? That the library it's using detected that it contains a bug?
154.
▲
by
Gankro
11y ago
What have I diluted the meaning of errors to? Rust doesn't remove bounds checks in --release. It's wrapping that gets turned on in release. I'm not sure why you're distinguishing overflow as truly exceptional, as oppos
155.
▲
by
Gankro
11y ago
We specifically recommend against providing panicing and non-panicking. This causes horrible combinatoric explosions. There's very few exceptions to this (array indexing being the major exception). We do of course recommend non-panicki
156.
▲
by
Gankro
11y ago
This seems a bit too unpragmatic. Would you also require the user to explicitly handle: * Index out of bounds on every array op * Integer overflow on every arithmetic op * OOM on every allocating op Maybe if you're writing an ironclad
157.
▲
by
Gankro
11y ago
Just to clarify since `unsafe` is a special term in Rust: `unwrap` still checks for None and panics, it doesn't blindly assume it's valid. That said, I think you're too dismissive of "can never fail" assumptions. Th
158.
▲
by
Gankro
11y ago
Not 100% sure but this precise optimization for LLVM is probably part of ScalarEvolution, which tries to figure out how values in a loop evolve: http://llvm.org/devmtg/2009-10/ScalarEvolutionAndLoopOptimiz... LLVM
159.
▲
by
Gankro
11y ago
Isn't this more or less [SemVer]( http://semver.org/ )? A bit more streamlined from the official SemVer spec, but it's basically a guideline anyway.
160.
▲
by
Gankro
11y ago
Huh. I tested it out on serde-toml; does it have a bug, then?
161.
▲
by
Gankro
11y ago
I'm pretty sure this is the only way that Serde works? If you tell it do deserialize to a `Point { x: u32, y: u32 }`, it will ignore any additional fields.
162.
▲
by
Gankro
11y ago
Or if T contains a NonZero (Vec, VecDeque, HashMap) ;)
163.
▲
by
Gankro
11y ago
Yeah both are examples of the designer being a bit "cute". The piston thing is however totally idiomatic and recommended by the piston devs, while I've never seen anyone actually loop over an Option in real code. Though it wo
164.
▲
by
Gankro
11y ago
Piston is pretty quirky, honestly. The window builder is pretty vanilla, but the event-processing-for-loop stuff is super quirky. The `e` that is yielded by iterating the window is the window itself WHAT Especially because the examples us
165.
▲
by
Gankro
11y ago
PwdHash has serious usability issues: http://people.scs.carleton.ca/~paulv/papers/usenix06.pdf In particular, the fact that you type your password into the password field means that failing to invoke PwdHash means
166.
▲
by
Gankro
11y ago
What makes you think there's a reliable way to zero memory in Rust?
167.
▲
by
Gankro
11y ago
Depends on the precise details, but generally speaking the nastiest problem would probably be the fact that `region analysis + type erasure = sadness`. For instance, you can't just have all your objects be some opaque thing, you need
168.
▲
by
Gankro
11y ago
No the bash script doesn't verify itself. The only real verification step is using https (and writing the script so that it's not vulnerable to truncation attacks).
169.
▲
by
Gankro
11y ago
I would personally arguing that a deep copy necessitating an explicit function call is a good thing, though. It makes potentially expensive operations obvious, and improves your ability to reason about program behaviour.
170.
▲
by
Gankro
11y ago
You have completely ignored the actually interesting point of my argument, and focused on pointless details. In particular, my statement on affine types. Or, in C++ terms, move semantics by default, instead of copy semantics by default. Raw
171.
▲
by
Gankro
11y ago
Yes, backwards compatability with C makes this a hard problem, but this is exactly what affine typing fixes: assignment is a shallow copy, but the old copy becomes inaccessible.
172.
▲
by
Gankro
11y ago
My answer to that is "you shouldn't want to deep copy on assignment". It's a performance trap and makes the code harder to understand. Without pervasive copy/assignment/move ctors you would be surprised to see
173.
▲
by
Gankro
11y ago
There's a difference between overloading `+`, `-`, `<<`, (which must obviously run custom code when applied to custom types), and overloading `,`, copying, assignment, moving, and tons of other "already works on everything&q
174.
▲
by
Gankro
11y ago
Sadly Rust does little to deal with these higher-level bugs. We give you tools to deal with them (tracking taint with PhantomData), but it's not clear to me that anyone's bothering to actually do that. e.g. crates.io does no such
175.
▲
by
Gankro
11y ago
It's still a bit of a draft document (still missing the last chapter, for one). Happy to change stuff based on proof. That's one of the more dubious ones for sure.
176.
▲
by
Gankro
11y ago
Primary author here. AMA how Rust is unsound.
177.
▲
by
Gankro
11y ago
Not my thesis by verdict of my supervisors -- I am now on my third attempt at a thesis. (attempt 2 was http://cglab.ca/~abeinges/blah/too-many-lists/book/ )
178.
▲
by
Gankro
11y ago
Minorish point: a true OOM won't panic, it'll abort the program completely. Some APIs may identify that the requested amount of memory is impossible (would overflow) and panic instead, though. Aborting once the allocator has actua
179.
▲
by
Gankro
11y ago
A simple example of this would be two threads with two channels to each-other. A is in channel A, B is in channel B. While blocked on channel A, thread 1 can't handle messages in channel B. Certainly a bit more contrived then deadlock
180.
▲
by
Gankro
11y ago
Note that rust has bit literals, so you can explicitly write bit masks out: let mask = if blah { 0b11111110000000001001001100000101u64 } else { 0 } and you can include optional underscores wherever for clarity let mask = if b
More ›