Static Analyzer Rudra Found over 200 Memory Safety Issues in Rust Crates
infoq.com
infoq.com
I am still impressed by the (IMO) small amount of issues uncovered. We're talking 43k+ packages and the Rust's stdlib and compiler. Only 76 CVEs! That might sound like a lot but it's definitely, what, 0.0018% compared to the number of packages. That means that for each CVE [that has been resolved and patched] you'll get ~566 packages fixed in one fell swoop.
Super rough estimations, of course, but I am glad that such work exists. I'd love to see even more of it! Rust is a modern fan object (including by myself) but we need less fandom and more facts. Let's have them.
Anybody knows links to other similar works like Rudra?
But we also know that things to do stdlib to die, right? Python is a famous example; almost every Python dev I know never uses the builtin HTTP client APIs.
So eh, I am okay with having de facto standards in the form of widely accepted libraries.
On a separate note, I had really high hopes for Rust 2021 edition. They had a chance to introduce new syntaxes and address error handling at least but they opted not to do so. Disappointing.
When I have Python installed, I can be 100% sure of what works, regardless how uncool the library might happen to be, so those builtin http client libraries will be used.
First, the issues surfaced are all in unsafe blocks, which is the desired state of things.
Second, it’s a testament to how powerful unsafe is in making code safer: I don’t think this sort of static analysis would ever go through the whole of crates.io in 6.5 hours if it had to analyse the complete code base for each package.