← Back to context

Comment by gabrielhidasy

5 years ago

For each piece of software, there just be a version in Rust, and that version must advertise it's rustiness

After looking at the source I find this one to be much easier to read than equivalent C, because Rust is a more expressive language. So looking at what an all-rust kernel would look like seems quite worthwhile. You can't reach anything new if you're not willing to experiment.

The type of software makes the difference - does it process untrusted input, maybe even over the network? This here is a kernel including a memory-safe TCP/IP stack (https://github.com/smoltcp-rs/smoltcp/), and not having it crash or be full of security vulnerabilities due to preventable memory corruption is a quality beyond personal language preferences.

  • It is possible to overstate a valid case until it becomes meaningless... are modern OS IP stacks written in C really 'crash'ing or 'full of security vulnerabilities'? No.

    • There has actually been a few crashes in the core TCP/IP stack of both Linux and Windows in the last 5 years, though I'm not sure any of them were due to memory safety (most were logic bugs as far as I can tell). That said, rust's approach to error handling could help avoid crashes here as well.

      However, we have seen *many* memory-safety crashes in the drivers to talk to network interfaces. Those really are full of security vulnerabilities. The most prominent recent one was broadcom's wifi driver having heap buffer overflows allowing remote code execution by anyone within wifi range in 2019[0].

      [0]: https://www.bleepingcomputer.com/news/security/broadcom-wifi...

    • The fact is that it is overwhelmingly more difficult to write and guarantee that your C code is "safe" to the same extent that a naively-written Rust program which accomplishes the same thing would be, especially as your software's complexity increases.

      Is it possible to write C code that has the safety properties of Rust code which provides the same functionality? Absolutely, in theory. But will you be able to accomplish this and then guarantee this safety and have the confidence that future code changes won't break those guarantees? That becomes exceedingly more difficult to do, nevermind the extra time and effort it would take. In most cases this would be prohibitively expensive, and you'd just get on with life hoping for the best and mitigating what you can.

      In my view, one of the killer features of Rust is its ability to be easily ABI-compatible with C as needed, which I see as a pragmatic feature of Rust that acknowledges the messy software reality of our world and the fact that C (or any other language) isn't just going to be "replaced" by rewriting stuff everywhere, neither anytime soon nor probably ever in totality. This lets us more readily combine the great capabilities of Rust with the enormous volumes of useful code that already exist today without resorting to dogmatic approaches of always thinking we need to rewrite the latter. The "rewrite everything in Rust" idea is fun in an academic kind of way, but in the real world economics will prevent that from happening everywhere, in a similar way that economics usually prevents you from validating and providing certain safety guarantees about your C code.

    • The TCP/IP stacks of the few popular OSes is not full of security issues, but that took a lot of effort that a small team can't do. Also, it's a matter of updating: after reviewing the CVE database, would you be comfortable running a 5 year old kernel without updates?

For each rust submission, there shall be a comment at top lamenting the gradual rusting of hackernews.

  • Not lamenting in this case, the project is awesome and rust is made for this. I just find amusing that almost all popular rust projects I see have "in Rust" front and center

    Must be an awesome language to work on.

I mean honestly who cares? its their time. I use rust over c/c++ these days for practical reasons.

1. the toolchain is better. (cargo ala)

2. maintenance of the software is better. (static linked binaries, easier deploys)

3. memory safety.

4. resource consumption (cpu/ram)

when I don't need 4 I use golang (most cases) because of 1, 2, and 3.

and I choose tools (all other things being equal) written in rust for the same reasons.

Now ask yourself why.

Mozilla decided to create Rust after years of using C/C++. Why?

Because they spent a fortune fixing the same problems over and over again, and they realized that no matter how clever their developers were, those problems were always going to arise as long as they kept using C/C++.

Not because C/C++ is inherently bad, but because is more flexible than strictly needed in some ways.

Rust was designed to prevent many classes of problems.

  • I'm ok with things rewritten in Rust, really looks awesome as a language. And the fact every rust project advertises rust front and center compounds that image.