Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ralfj
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
61.
▲
by
ralfj
4y ago
If Rust leads to more languages for more domains adopting Rust-style enums and pattern matching (algebraic data types / sum types -- this idea predates Rust by decades, so "modern" is an interesting term to use), I'd ca
62.
▲
by
ralfj
4y ago
It might still be tricky or even impossible to do that, that sounds very specific. If it is truly impossible we in the UCG would love to hear that. :) We don't want to rule out any legitimate use-case without reasonable alternatives (a
63.
▲
by
ralfj
4y ago
To be clear, MiniRust doesn't change any of the rules Rust has, it makes them precise . 64bit tagged pointers are possible in Rust, you just have to do it right, and ideally one day MiniRust will spell out precisely what "right
64.
▲
by
ralfj
4y ago
I compare MiniRust and Ferrocene at https://github.com/RalfJung/minirust#what-about-the-ferrocen... . :) TL;DR they re quite different in style, precision, and scope.
65.
▲
by
ralfj
4y ago
Yeah, I am aware it's far from a main language at these companies, but having any use at all is a strong sign. I am in contact with some people in the Android team at Google that are also using Rust (and that want to use Miri :D ).
66.
▲
by
ralfj
4y ago
> Rust screams UB much quicker when it comes to memory semantics than any other language that I know. If you only use raw pointers, Rust has significantly less UB that C does. But if you use references, then yeah we have those aliasing
67.
▲
by
ralfj
4y ago
Yeah okay, traits are super complicated and C doesn't have anything like that, I admit. It's not really part of how to map instructions to the machine, it's more part of how to figure out which function is even being called
68.
▲
by
ralfj
4y ago
> Are there any formal (or formal-ish) grounds for saying that only authors of unsafe code need to be aware of Undefined Behaviour in Rust? Yes. It's called type safety / type soundness: you cannot cause UB in safe code. I lite
69.
▲
by
ralfj
4y ago
Microsoft, Amazon, Facebook/Meta, and Google are all using Rust in production. It's not just web3 nonsense.
70.
▲
by
ralfj
4y ago
The early web with every browser doing something else was terrible for website authors. A lot of the innovation in the web started when there finally was standardization so that these fancy features could actually be used reliably acros
71.
▲
by
ralfj
4y ago
Rust has that mapping in the same sense that C does: there exists a fairly simple way to implement every language construct (except maybe for dynamic method invocations) in assembly. However, Rust and C alike have another whole dimension
72.
▲
by
ralfj
4y ago
> "cool, a way to get the binaries small enough for embedded" lol, I didn't even realize the wrong associations I would create here. Glad you liked it anyway. :) I guess my choice of name was not great. I also considered p
73.
▲
by
ralfj
4y ago
Yes, MiniRust is basically a slightly extended MIR. But MIR is designed for borrow checking and MiniRust is designed for exploring semantics. And MIR doesn't have a precise operational semantics so it's not like this is duplicatin
74.
▲
by
ralfj
4y ago
Hi Amos, thanks a ton. :)
75.
▲
by
ralfj
4y ago
If you are writing unsafe Rust code and want to be sure that your code is following the rules of the language, then this is an important steps towards giving you a sufficiently precise description of those rules that you can use for this pu
76.
▲
by
ralfj
4y ago
It's certainly not official, so please don't take all the choices MiniRust makes as being anyone's opinion but mine -- but we're working towards having something official like it. :)
77.
▲
by
ralfj
4y ago
You just fully agreed with what I said in the post. :) Explaining that one of the optimizations is wrong is my entire point. Then I go on saying which optimization is wrong (in my view) and propose a structural explanation for why it is
78.
▲
by
ralfj
4y ago
Indeed int2ptr is the "evil" operation. If we banned it, we could get rid of all this "exposed" stuff and ptr2int would be fine. However, in order to make int2ptr work, we have to also make ptr2int a bit more complicated
79.
▲
by
ralfj
4y ago
The standard defines "based on" by talking about hypothetical alternative executions where the original value has a different value. In those executions, the access in question does not even happen in my program. What this goes
80.
▲
by
ralfj
4y ago
Looks like you ended up agreeing with my post then. :) (FWIW I fully agree re: appealing to authority. I'd rather people engage with my arguments than take them on face value.)
81.
▲
by
ralfj
6y ago
Note that all of the optimizations I used in the main part (not the warm-up) of my post are still performed even with "-fwrapv -fno-strict-aliasing". So this does not avoid the issues I am talking about.
82.
▲
by
ralfj
6y ago
Seeing how long the story of poison/undef is dragging out for LLVM, I'd say it's more of a years-long process than an hours-long one. ;) But still, the most important part is that there's a discussion at all, and the de
83.
▲
by
ralfj
6y ago
Yeah, there were some bugs in the frontend and I think one in the backend. But there were zero bugs in the optimization pipeline, which is where typically the most subtle bucks lurk. For more details, see https://www.cs.utah.edu&
84.
▲
by
ralfj
6y ago
One could imagine a specific primitive operation in the language that lets you adjust the low bits of a pointer without casting it to an integer and back.
85.
▲
by
ralfj
6y ago
> if this snippet is legal C code, then LLVM can't treat it as if it were UB? It can in principle for the purpose of this example, since this is not the C code that the programmer originally wrote. This just means that if the snippe
86.
▲
by
ralfj
6y ago
Thank you so much for the feedback :) . I spent more time on this than on my usual post, so it is great to hear that that has paid off.
87.
▲
by
ralfj
6y ago
Oh, there was a repost in 2020, that explains the sudden spike in page hits that I saw earlier this year and couldn't trace back. ;)
88.
▲
by
ralfj
6y ago
So the gist of the post is, if you want to "count" for Firefox developers, you better share your usage data with them? That attitude is... not great. The point of making telemetry optional is to respect the users choice, not to sa
89.
▲
by
ralfj
11y ago
> There are a lot of crates that use unsafe code in one form or another; and it troubles me (although no one else cares) that they are probably more dangerous than I realized. Be careful here, module != crate. Most crates consist of many
90.
▲
by
ralfj
11y ago
No, it doesn't break the promises in any way. If all your code does potentially dangerous memory manipulation, then there's very little hope that there will ever be an automatic checker for the safety of your program. The promis
More ›