I.e. the Rust this, Rust that spam is a little naive to the task at hand, even though it would be a step up from C
I.e. the Rust this, Rust that spam is a little naive to the task at hand, even though it would be a step up from C
I know I've seen an older document that specifically prohibited use of malloc that the risk was too great. Is that still the case?
I'm not related to this project or aerospace, so I can't divine more knowledge than anyone else, although I have seen many coding standards that forbid malloc after some critical time (e.g. no dynamic memory allocation after the plane is off the ground)
Parts of the STL were formally verified. cprover (with satabs and cbmc) can handle C, C++ or Java. F' uses autogenerated classes, which helps a lot avoiding mistakes.
Advocacy should always be tempered with a bit of hard reality check, otherwise one just ends up scaring possible adopters away.