Guess I should start my 5th attempt at finally getting good at Rust.
Guess I should start my 5th attempt at finally getting good at Rust.
Probably this one:
- Rust has the clear goal of memory safety, which is an active issue in the kernel (see: Kees Cook's Kernel Self Protection Project), even more so when it comes to drivers which are a lot more variable in quality and have very variable levels of oversight, which is why those are the primary use case.
- Rust has a much more expressive type system, especially without the need to go into template weeds.
- Rust has a lot less implicit behaviours.
- Rust features tend to be more orthogonal and mis-interact less with one another.
- While Rust has a fairly steep learning curve, short of unsafe it doesn't kneecap you, if it doesn't like what you're doing (right or wrong) it tells you, it doesn't go off into the weeds doing the wrong thing.
https://rust-for-linux.github.io/docs/kernel/
Out of that, core is basically just what you get from Rust's core itself, alloc is similar to Rust's provided alloc but is fairly heavily customised to meet the requirements of the kernel and of Linus. But kernel is custom code for the kernel specifically. Overall that's a lot of effort.
We didn't see a similar effort for C++. Would that have overcome Linus' reluctance? Well, it can't if it doesn't exist.
Do you remember the Paul Graham essay on the Blub programming language? (http://www.paulgraham.com/avg.html)
C++ is kind of like the Blub language. If you know C++ well enough, you can do anything you need to do, so something like Rust just seems too esoteric and weird and pretentious.
Fortunately, I spent many years using Rust recently (coming from primarily a C background) and when I'm on a project using C++, it just feels too weird and rudimentary and horribly over-complicated.
To end with a quote from the PG article:
_But when our hypothetical Blub programmer looks in the other direction, up the power continuum, he doesn't realize he's looking up. What he sees are merely weird languages. He probably considers them about equivalent in power to Blub, but with all this other hairy stuff thrown in as well. Blub is good enough for him, because he thinks in Blub._
C++ is full of footguns and it is easy to make mistakes, but it is also one of the most powerful and expressive languages out there.
Not to mention that it is blazingly fast.
C++ templates are hard to learn and understand, but they are one of the most powerful constructs we have in any programming language, I miss them when I work in other languages.
Though as far as compile time templates go I think Nim templates generally meets or exceeds C++ templates in most areas. But I've become addicted to compile time type ducking, which is antithetical to Rust's vision of programming.
You can argue that what you give up in exchange for this freedom is more valuable, but don't twist the definitions of words.
It depends on which "common definition" you're working from. To make an analogy, both GPL advocates and MIT/BSD license advocates argue that their conception of freedom is "more free."
Rust is closer to the GPL here. By limiting certain things that you can do, you are free to do things that would be harder if you're allowed to do anything. The canonical example here is Stylo; the project was attempted with C++ multiple times, but was too buggy. But Rust's restrictions allowed the Rust version to succeed. You can argue it both ways: Rust limits certain kinds of code patterns (outside of unsafe, of course...) but that may enable you to do things that were too hard to do when there were no safeguards.
(A more generalized version of this debate is the distinction between "positive liberty" and "negative liberty," this debate transcends software.)
The restrictions merely apply to provably correct code.
I'm not sure how telling the compiler to disable the safety features so you can do your thing is unbearably limiting.
I would have said C is firmly a Blub, though.
I love Rust; I’d do any new project in Rust instead of C++.
It’s worth the effort to learn.
- Have hidden costs
- Have sneaky failure-modes
C just... doesn't add any abstractions. And then Rust adds abstractions, but makes a concerted effort to avoid ones that have these two problems
Rust though? That could make the kernel more secure in the long-term and rule out a whole class of bugs. This makes sense.
The thing that finally made Rust click for me was doing a usb HID project. Suddenly all the machinery around ownership and multi-threading made sense and I was able to get things done, and I could suddenly also do all the things I previously attempted to do in Rust.
I guess i should do the same too but I have really and man the language is not easy to grok. These days it also feels like if you don't know Rust, you are somewhat "old school".
You say that like there’s some scalar measure of “better”.