I'm funding Ladybird because I can't fund Firefox
jackkelly.name
jackkelly.name
Mozilla is an online advertising advocacy project. Just try suggesting to anyone from Mozilla the idea of web without ads. They will be 100% opposed, unwilling to even consider alternatives, as if they are being paid to defend this pro-advertising position. They are indeed being paid indirectly from the coffers of an advertising company.
"Free and open web" apparently means web open for advertising. The presence/absence of advertising on the web is a non-negotiable. Mozilla insists advertising is a must-have.
Why was the original internet free of ads before it went public. Are there more important uses for a computer network. ISPs privatised the financing for the network. We pay for internet. It is not free. Funding from advertising has never been a necessity.
But Mozilla argues advertising is 100% essential.
Citation needed. I realize they get a ton of money (probably most of their funding in fact) from Google, but still have they actually made such a statement? For now at least, they support ad-blockers a lot better than Chrome (because of Manifest v2).
> Anonym was founded with two core beliefs: First, that people have a fundamental right to privacy in online interactions and second, that digital advertising is critical for the sustainability of free content, services and experiences. Mozilla and Anonym share the belief that advanced technologies can enable relevant and measurable advertising while still preserving user privacy.
Which completely ignores non-profit uses of the web, which is interesting since they're a non-profit and all.
They've made similar statements in the past[1]:
> Advertisements pay for all those “free” services you love, as well as many of the products you use on a daily basis — including Firefox. There’s nothing inherently wrong with advertising
Which is of course true because they don't accept donations to fund Firefox despite people complaining that they want to be able to make such donations for years.
[0] https://blog.mozilla.org/en/mozilla/mozilla-anonym-raising-t...
[1] https://blog.mozilla.org/en/mozilla/the-future-of-ads-and-pr...
There's no way they would manage to exist like a business with a multi million dollar a year CEO without all that sweet Google money. So they are totally beholden to advertising straight from the top down. It doesn't even matter who is at the top, the whole step setup guarantees it'll be one of the big business players.
Basically when they moved Firefox from a foundation to a corporation, this was pretty much inevitable. They don't even want our petty donations anymore. We can donate to the foundation's pet side projects but not too Firefox.
I shit on Firefox every damn day, but that's because I'm a tech-brain(rot) weirdo. Truth is I absolutely love it. Firefox, or one of its derivatives, is the main (often times only) browser on every device I own. I literally wouldn't buy a device if I knew I couldn't install Firefox.
Right now, our options are a world without Firefox or a world where Firefox is supported by the dominant market player. Maybe that changes in the future? Maybe it doesn't. But a chance for a future that isn't just the children of KHTML can't happen if Firefox doesn't exist.
The obvious Apple in the 90s comparison comes to mind.
TFA is about one such chance (and why it might be more donation-worthy), no?
I hope for a future where I've got even more options, but right now, it's a baby project. Getting standards-compliant rendering working is step zero. Things like site isolation, hardware video acceleration, and extensions that have enough access but aren't running wild with permission are really where a browser in the modern world shows its metal. Not to mention multiplatform support.
An OS isn't just a kernel, and a browser isn't a just rendering engine.
With that context, I'm on board with not giving money to Mozilla Corp. Late last year I cancelled my subscriptions to Pocket, the VPN, and recurring donations.
That said, I recommend that you support Servo instead of Ladybird.
Reason #1) C++ is just dumb in 2024 and choosing it is a big red blinking sign that the devs make bad decisions. Now they're considering a rewrite in a better language? So, starting again from scratch... No thanks!
Reason #2) Given the track record of the main author of being an ass to people who aren't willing to be marginalized, I don't have high hopes that he can lead anything as complex as a competitive browser. No, Serenity OS is nowhere near the same level of complexity thanks to el GOOGs insistence that the modern web includes every API found in OSes. Serial port access, really?
Anyway, please don't just jump on a hype train. Fund Servo.
> Give capital to another project because C++ is "dumb" and Rust is not.
I applaud you for disclosing your biases at the top but I was so hoping the disclosure wouldn't be a spoiler for the rest.
That’s a quite strong accusation without any evidence.
Because modern C++ (e.g., using std::unique_ptr with std::make_unique() and RAII wherever possible) is safe enough, is getting safer with each iteration, is easier to learn for someone who already knows C or older (pre-11) variants of C++, and offers greater compatibility with the billions of lines of code already written in C and C++.
> Reason #2) Given the track record of the main author of being an ass to people who aren't willing to be marginalized
I was hesitant to even mention this, but not having to deal with demanding, danger-haired political agitators wielding their CoCs is enough of a reason for me to avoid Rust completely.
Apple’s App Store Connect yesterday just won’t login anymore, tried Chrome and it works.
So many broken headers, weird fonts, overlapping elements, etc.
It’s a simple js file, and I now have a couple dozen subscribers. A nice project.
If the problem persists, use this form to report it to Mozilla: https://webcompat.com/issues/new
If, as some claim, there isn't ever enough money to really fund development, fine, they've now proven that. But not even allowing it as a possibility is completely insane!
I'm left in a position where I'm assured repeatedly that the best way to fund Firefox development is to pay for a side project I have no use for like Pocket or their VPN and then hope that that payment doesn't get consumed paying for said side project or future side projects.
OP's thoughts were mine the day that the LBI was announced: finally there's a non-profit that is actually committed to maintaining browser diversity. It's just a pity that it's one that's starting from behind and not the existing non-profit whose browser at one point enjoyed a majority market share.
Oh sorry, she's chairwoman of the board now, completely different.
In India, an entire telecommunications company was forced to use a fork - KaiOS for Reliance Jio phones because FirefoxOS was abandoned.
FirefoxOS was a terrific idea, but the baby needed time to grow up to teenage level, but was murdered soon after birth
And don't forget, these things are not just cosmetic. Not being able to get married could lead to some serious consequences when having kids (e.g. a lesbian couple) and one partner dying.
Personally I would not have pushed to fire him, no, and I'm very pro-LGBTQ+. It was only a small donation compared to how much he makes and the legislation was easily defeated. But I don't work at Mozilla.
That is not true. California had domestic partnerships with identical rights and responsibilities as marriage starting in 1999. Eich opposed applying a term that, in his view, carried religious import. That's all.
What a great vision.
Edit: okay from what I understand in the blog, one of the reasons for abandoning it was that it was hard to keep up with the electron API changes and keep it compatible. That just goes to show that they were completely outplayed early on, otherwise they wouldn't have had to play catch up by merely being an electron shell around Spider monkey...
>But Tofino is dead (long live the Browser Futures Group!), and Electron compatibility isn’t essential for a viable Gecko runtime. It’s also hard, since Electron has a large API surface area, is a moving target, requires Node.js integration (itself a moving target), and is designed for Chromium’s process architecture, which is substantially different from Firefox’s.
Every monetization attempt failed (even with stuff centered around "privacy", a niche where Firefox is well known). I've seen numbers that indicated that the Mozilla foundation donations are almost equal to what they profit from their commercial products.
Again, though: they have yet to try the obvious, which is allowing people to donate to Firefox.
I have zero interest in supporting all the random distractions that Mozilla engages in, but if they gave me a donation box for Firefox specifically I'd set up a recurring payment today.
They can't in good faith claim to have tried every monetization method when they have never let users earmark funds for Firefox.
How do you measure impact? If it's income created for Mozilla Corp then I agree it's impactful too, and the CEO's pay does seem justified.
> How successful are they with their side projects, anyways?
Honestly I don't know, I haven't looked at their latest annual report. I do pay for Mozilla VPN, although I'm not a Firefox user.
https://news.ycombinator.com/item?id=40901664
So in other words: the side projects aren't successful enough to justify not accepting donations.
> [Mozilla] in 2018's cash flow was negative ~1 million dollars while in 2022 it actually profited ~167 million.
A reply to that comment‡ states the following:
> Also important is that if you look at their annual reports, while it's still the most significant revenue source, the percentage of revenue coming from search engine royalties (i.e. Google) has been steadily going downwards. Instead revenues from their other services (VPN, Pocket, etc) had been increasing steadily.
And indeed we can verify those numbers on Wikipediaᵃ, where we see "Revenue derived from Google" trending downward every year.
So it seems she's been A) successful with continuing the search engine deal with Google; and B) increasing revenue from their other services (VPN, Pocket, etc.) so that Google's contribution to the revenue pie chart slowly shrinks over time.
† https://www.reddit.com/r/dataisbeautiful/comments/1dg7ejv/co...
‡ https://www.reddit.com/r/dataisbeautiful/comments/1dg7ejv/co...
ᵃ https://en.wikipedia.org/wiki/Mozilla_Corporation#Finances
It’s a fantasy land. I was there for awhile.
The C-level execs getting their salaries off that Google money can!
However with falling marketshare there comes a point that when that won't fool regulators anymore. And then there's no point for Google to keep paying.
Yes, better give it to Google and golden-parachuting C-level execs
It's hard to imagine that it's for a reason other than "Google wants it that way".
If you can provide a citation for this claim I'd get a subscription today. I don't pay for their side projects because I don't want them to take it as a signal of demand for VPNs, but if it's truly 100% profit I'd be willing to risk it.
> Also, if we are realistic, the total money in donation that Mozilla could get would probably represent a drop in the ocean compared to their annual budget and the amount of money you need to develop a (complete) browser.
People keep saying this, but given that it's never been tried you have no proof. And even if it were, what harm is there in opening up one more option for those of us who want to be really clear about what we're paying for?
Fair enough. They publish their annual financial report but it isn't splitted per project so it's hard to know for a fact with the public information we have access to. However, it isn't unreasonable to think that at the very least a percentage of the smaller products revenues are reinjected elsewhere in the organization (e.g Firefox) since the goal seems to be to diversify their income sources.
> People keep saying this, but given that it's never been tried you have no proof. And even if it were, what harm is there in opening up one more option for those of us who want to be really clear about what we're paying for?
It's been tried over and over in the FOSS community. Few projects are able to get decent money with donations (e.g. Thunderbird). However, it's nowhere near the complexity of a web browser.
For example, Thunderbird made almost $7M (USD) in 2023 for an average of $20 per donation which is 350k users out of 20M monthly active users [1]. Firefox has 10 times that number of users so we could estimate that they'd make $70M/year. That's far from $500M/year they're doing right now.
[1]: https://blog.thunderbird.net/2023/05/thunderbird-is-thriving...
Hello friend! Thank you so much for donating to support Ladybird!
We believe the world needs a truly independent web browser.
That's why we are funded entirely by voluntary donations, and we intend to keep
it this way forever.
Make sure you sign up for our newsletter below if you'd like to receive
monthly updates on our progress!
https://github.com/LadybirdBrowser/ladybird.org/blob/336f892...I guess I should also add that it is just the rendering engine, not a full browser
> However, now that Ladybird has forked and become its own independent project, all constraints previously imposed by SerenityOS are no longer in effect. We are actively evaluating a number of alternatives and will be adding a mature successor language to the project in the near future. This process is already quite far along, and prototypes exist in multiple languages.
So it looks like there's a plan to refactor away from C++ as it spreads its wings. I'm in favour of people funding any browser engine with a realistic shot at viability.
https://servo.org/blog/2024/06/28/input-text-emoji-devtools/
Rust was literally invented to solve the security and concurrency issues inherent in using C/C++ for a browser engine. You could argue that's the one use-case where it is objectively the best language to use. It's so valuable for that purpose that every large company has rewritten at least some crucial components in Rust.
I also think Rust will be one of the only languages strict enough to enable the use of AI-generated code without compromising security. I certainly don't want AI-generated code for high-security applications, but there's nothing we can do to stop it at this point.
"We are actively evaluating a number of alternatives and will be adding a mature successor language to the project in the near future. This process is already quite far along, and prototypes exist in multiple languages."
I assume it's either Rust or Jakt (the latter a language in development by the Ladybird lead dev), though I suppose Swift might be on the table.
C/C++ is arguably the safer choice in terms of actually completing and maintaining a project of this magnitude.
It very much has.
I do like Rust, but I've only come across a few "higher profile ish" projects. None were really that important or useful that I actually bothered to remember them.
Windows 11 kernel will soon be booting with Rust inside (https://news.ycombinator.com/item?id=35738829)
Microsoft seeks Rust developers to rewrite core C# code (https://news.ycombinator.com/item?id=39240205)
Note that it's likely that some of the biggest applications aren't public and so even if identified you couldn't actually count the lines yourself.
Some of the open source projects you can find are AWS Firecracker https://github.com/firecracker-microvm/firecracker and Cloudflare Pingora https://github.com/cloudflare/pingora
Of course, your mind is biased towards things that have existed for years before Rust gained traction. Those codebases aren't necessarily going to be rewritten overnight (if at all) in Rust. Others have mentioned it, but tech companies are writing foundational software with Rust, check out Cloudflares repository list for example:
https://github.com/orgs/cloudflare/repositories?q=language%3...
Mozilla doesn't control Rust, and why would it matter? What is your disaster scenario here? What would Mozilla do to sabotage Ladybird?
At this point, Ladybird has no competitors because it is not much more than a hobby project. It isn't usable yet.
>At this point, Ladybird has no competitors because it is not much more than a hobby project. It isn't usable yet.
Whether or not it is usable is a temporary technical issue. It absolutely is a contender for mindshare. Lots of people want a browser that isn't controlled by a nefarious advertising megacorp, and Firefox is about the only game in town. That is hopefully going to change.
Like who?
Anyway, it would be a good thing anyway because "friends of Mozilla" are likely some of the most dedicated FOSS people working in software.
> it is not outside the realm of possibility for Rust to switch to an awful license
It is absolutely outside the realm of possibility. It is as impossible as Python or any other major language doing it. Millions of lines of Rust are in production at for-profit and non-profit orgs, as well as in FOSS projects.
Even if they did it, Rust would be immediately forked and continue as it was before under a different name.
> Whether or not it is usable is a temporary technical issue.
I disagree. It is a long-term technical issue, because every viable browser engine so far has had many millions of person-hours put into it. Ladybird isn't close and likely never will be.
Are most browser vulnerabilities not still found in engines like V8? Rust can help with something like last year's buffer overflow in libwebp (although that's overkill when a project like https://github.com/google/wuffs exists), but I'm unclear on how it gets you a better JIT.
Hopefully someone who knows more will explain this better
It's (much) more involved than using C++, but that's a worthwhile tradeoff for something as important as a browser engine.
More info: https://eli.thegreenplace.net/2021/rust-data-structures-with...
good link you shared. i personally always went with option 2 he presents.
You can always go through and systematically remove unnecessary `unsafe` later if needed, but there's no need to do so upfront if that would prevent adoption.
refactoring those unsafe will never happen in the kind of place that put them in place to begin with.
Giving me a donation box to pay for Firefox means that I can be very confident that they are getting the right message from my dollars. But for some reason they are very reluctant to do that.
and let the market work.
browsers are a common utility, like water, internet etc - n should be treated the same.
Chrome is a punch in the face by the invisible fist of the market.
https://github.com/ungoogled-software/ungoogled-chromium
Without signing in to a Google Account, Chromium does pretty well in terms of security and privacy. However, Chromium still has some dependency on Google web services and binaries. In addition, Google designed Chromium to be easy and intuitive for users, which means they compromise on transparency and control of internal operations.
ungoogled-chromium addresses these issues in the following ways:
- Remove all remaining background requests to any web services while building and running the browser
- Remove all code specific to Google web services
- Remove all uses of pre-made binaries from the source code, and replace them with user-provided alternatives when possible.
- Disable features that inhibit control and transparency, and add or modify features that promote them (these changes will almost always require manual activation or enabling).
The parent comment (and this whole post) is mostly about the funding of browsers.
If you were to fund, say chrome, you might waste your money.
Might be similar to funding firefox, which has lots of telemetry baked in. Unless you could fund a "no-telemetry firefox", or a version of firefox with easy to implement self-hosted firefox sync and auth.
I understand the project started as a hobby, and anyone who wishes to be involved has their own prerogative, but I'd have a hard time getting behind it myself.
How can you have a real memory safe application when the memory itself is managed by a shit ton of code written in an unsafe language?
It turns out actually pretty effectively? There are going to be more bugs and boundary issues of the OS, but memory unsafety isn't some goop that oozes into your runtime.
My point is, people act like anything built with non memory safe languages is shit ever since Rust became the Jesus. We have the actual operating systems written in C, working ok. It is fine.
Yeah maybe Rust would be better but it is not a magic bullet and memory safety comes with many caveats in design of the code and possible performance issues when you are building something low level like a browser.
In addition to that, the browser is executing third-party code all the time while making it a good point of entry.
I mean, the most memory safe language will invoke syscalls. It will ask for memory pages and stuff. If we assume the app is running on a pile of shit because the OS is written in C, how can we be sure that the language is memory safe?
I understand the value of memory safe languages but people bashing on C/C++ code does not make sense to me when everything is essentially running on C. That’s all.
> In addition to that, the browser is executing third-party code all the time while making it a good point of entry.
This made me curious about something. Has there been many exploits stemming from JavaScript engines? I honestly do not know but as far as I can tell, most of the issues originate from faulty image decoders screwing up memory and tls implementations etc.
You may be right if you're talking about a GC'ed language, which gives memory safety and at the same time frees up the developer's mind. But if you're talking about constructs like borrow checkers then they do add cognitive load that is perhaps better spent elsewhere.
https://www.zdnet.com/article/chrome-70-of-all-security-bugs...
https://msrc.microsoft.com/blog/2019/07/a-proactive-approach...
> ~70% of the vulnerabilities Microsoft assigns a CVE each year continue to be memory safety issues
Why build a new browser in C++ when safer and more modern languages are available?
Ladybird started as a component of the SerenityOS hobby project, which only allows C++. The choice of language was not so much a technical decision, but more one of personal convenience. Andreas was most comfortable with C++ when creating SerenityOS, and now we have almost half a million lines of modern C++ to maintain.
However, now that Ladybird has forked and become its own independent project, all constraints previously imposed by SerenityOS are no longer in effect. We are actively evaluating a number of alternatives and will be adding a mature successor language to the project in the near future. This process is already quite far along, and prototypes exist in multiple languages.
The languages that are memory safe either impose too much of a straightjacket to be productive (Rust), don’t give you a GC or a memory safe way of writing one (Swift, Rust), or give you a GC with the wrong semantics (Java, Go, etc). Yes, the browser needs to have a GC. No, there’s no way around that.
I’m not saying it can’t be done - but there are good reasons to stick with C++ to get this job done. Not an ideal situation but it’s where the world is at.
The JS engine - about 1/3 of the browser engine, ish - is tightly coupled to the GC through-and-through. Let's even assume you have a JS engine that doesn't JIT. (If it did JIT then rewriting it in a memory safe language isn't going to do much for you at all.) The interpreter, the runtime, and the libraries are going to have to be making decisions on behalf of the GC (for stuff like weak maps, at least) and is going to have to play along with the GC's tracing (every class in the JS engine participates in the JS GC and so must tell the GC how to mark - or worse, move - outgoing references).
The rest of the browser has to play along as well, just not as much. The DOM is basically JS's "standard library" within the browser and it also needs to have its objects play along with the GC's semantics.
So, maybe there is code out there where the GC can be an island. The browser is not that.
And yes, you can make that happen. Marking references for a GC is in the same ballpark as a custom allocator. It doesn't have to fill the code using it with unsafe.
You're going to have to add GC awareness to objects so it can trace through them, but the code that makes and manipulates those objects can have all the necessary rules enforced by types.
GC != RC.
A type system can let you say things like “make sure someone finds out when I assign this pointer”. But that’s not what GC wants, unless (as I said before) you’re happy with your non-GC heap pinning objects (the browser isn’t, but some GC clients are, sometimes). GC wants a guarantee like: you cannot have a pointer in any data structure unless that data structure can be found by GC, and when it is found, make sure to respond to the GC’s request to scan it. That ends up being hard to do with any type system, unless that type system only allows objects to be allocated by that GC and the abstraction sits in the compiler/runtime below the type system (like in Java, Go, and Fil-C).
I am aware.
> But that’s not what GC wants, unless (as I said before) you’re happy with your non-GC heap pinning objects (the browser isn’t, but some GC clients are, sometimes).
I can't figure out exactly what you mean here. Temporary pins on the stack should be fine, and I don't see why anything else would be necessary.
> GC wants a guarantee like: you cannot have a pointer in any data structure unless that data structure can be found by GC, and when it is found, make sure to respond to the GC’s request to scan it. That ends up being hard to do with any type system, unless that type system only allows objects to be allocated by that GC and the abstraction sits in the compiler/runtime below the type system (like in Java, Go, and Fil-C).
Doing heap allocations through the GC doesn't sound very hard. And why does it need to be below the type system?
Maybe instead I should ask you what the already existing GC libraries for Rust get wrong? Do they require users to be unsafe or do something to break safety? Are they unusable to implement javascript?
The browser has a whole native heap (i.e. C++ objects, in current impls) that participates in the JS GC heap as follows:
- If the C++ object is referenced from C++ or from JS, it must be kept alive.
- If the C++ object references a JS object, then the JS object must be kept alive, so long as the C++ object would have been alive per the previous rule.
- It's possible for an object reference chain like JSobject->C++object->C++object->JSobject, and let's assume there are no other pointers to the C++ objects, in which case the last JS object should kept alive by GC only if the first JS object is alive.
- It's possible for dead reference cycles to exist like JSobject<->C++object, in which case both should die.
This requires that C++ has the ability to place references to JS objects in C++ fields.
This is where pinning comes in. It would be quite simple (and memory safe) but also totally incorrect (i.e. massive memory leak) to say that if a C++ field points to a JS object, then the GC just sees that field as a root. This is what I mean by pinning. (Note that "pinning" has many meanings in GC jargon; I'm using the Hermes version of the jargon. I guess I could have said "strong root" or something, but that's weirder to say.) This would be wrong, since it would not allow us to collect the dead cycle at all. Dead cycles are a common case in the browser. It would also cause other subtle breakage.
So, what the browser does instead is to have the C++ heap participate in GC: every C++ object that could possibly store a reference to JS objects anywhere can respond to GC callbacks asking it to account for all of those references. And, every C++ object needs to have a story for being referenced exclusively from JS, exclusively from C++, or a combo of the two. And the C++ code needs to be able to participate in whatever barrier discipline is necessary to get generations or incrementality or concurrency that the JS heap wants.
There are different ways to do this. Blink's Oilpan is probably the most principled, and that's basically a whole GC-for-C++ framework - very complex stuff. So, tons of inherently not-memory-safe code on the browser side just so it can do business with the JS heap.
The hard part of using a data structure like that is giving it ownership of the data and control over destroying it, but Rc does that too, doesn't it? That kind of thing is why I mentioned Rc. The difference between Rc and GC is much more in the behind-the-scenes tracking than in the API it gives.
If this code was all written in Rust, I could imagine there being almost no uses of `unsafe`, except for one: the thing where the GC decides to delete an object.
But this means that all of that code that isn't marked `unsafe`, but instructs the GC about what objects to mark or not, is really super unsafe because if it makes a logic error in telling the GC what to mark then the GC will delete an object that it should not have deleted.
So, the problem here isn't that you can't wrap the unsafe stuff in a safe API. The problem is that even if you do that, all of your seemingly-safe code is really super unsafe.
> The hard part of using a data structure like that is giving it ownership of the data and control over destroying it, but Rc does that too, doesn't it? That kind of thing is why I mentioned Rc. The difference between Rc and GC is much more in the behind-the-scenes tracking than in the API it gives.
The difference between RC and GC is exactly in the fact that the API they give is radically different. And that the behind-the-scenes tracking is different, too.
It's totally valid to tell RC "I want to point at this object so keep it alive".
But that's not the API that the GC will give you, unless it's a pinning API. The API where you tell the GC "keep this alive" will prevent the deletion of the garbage cycles I mentioned earlier.
So, the GC (in the case of something like a browser) gives a different API: one where user code either marks something, or not, at its discretion. There's no easy way to make that safe.
By putting it in a GC structure, it would be giving ownership to the GC, and would borrow it back to use. So whenever it's not borrowed, it's safe for the GC to delete it. And the GC won't delete anything outside of its control.
If you have a logic error and prematurely delete, then attempting to borrow the object will return None, which is still safe.
> It's totally valid to tell RC "I want to point at this object so keep it alive".
> But that's not the API that the GC will give you, unless it's a pinning API. The API where you tell the GC "keep this alive" will prevent the deletion of the garbage cycles I mentioned earlier.
The idea is that any pointing/pinning you do while manipulating an object would be a borrow on the stack. As soon as the function returns, there's no pinning.
So there's a few things that exist in this system:
* A GC-object references another GC-object, keeping the target alive while it is alive. A GC-object can be created by either Rust or JS. The loop you describe would be made up of GC-objects, so it would be straightforward to collect.
* A non-GC object has a permanent pinning reference to a GC-object. These are rare and purposeful.
* (Optional) A non-GC object has a weak reference to a GC-object, which can be collected at any time.
* Rust code has a temporary pinning reference to a GC-object on the stack, while traversing/manipulating it, and it goes away as soon as the function exits. It won't pin too long because the release is automatic. It won't free prematurely because the GC code knows the borrow is happening.
At Mozilla, our mission is to keep the Internet healthy, open, and accessible for all. The Mozilla Foundation programs are supported by grassroots donations and grants. Our grassroots donations, from supporters like you, are our most flexible source of funding. These funds directly support advocacy campaigns (i.e. asking big tech companies to protect your privacy), research and publications like the *Privacy Not Included buyer's guide and Internet Health Report, and covers a portion of our annual MozFest gathering.
Be realistic. For all bad mozilla foundation/corporation/toppahs did, the code is still open source and relatively free. If even something called IceWeasel almost had a shot at forking, the bar is pretty low.
Having a fully new codebase implementing the web is a great thing.
IceWeasel was a completely different thing mainly based around mozilla trademarks for logos/names that clashed with the FOSS policies of linux distros when shipping non-upstream binaries.
Sorry if I don't understand what you meant to ask.
We're talking decades of features they have to support - unless they're planning on strategically dropping support for older unused/deprecated parts of the standard? Even in 2008 Google made the decision to use Webkit for their browser because they understood what an enormous undertaking it would be to write their own rendering engine. That was 16 years ago.
Th selling point is to have multiple implementations of browser engines. Currently we have three (gecko, webkit and blink, where blink is based on webkit and webkit is based on khtml). If you consider how much of the modern world is based on browsing standards it seems pretty self-evident to not have it depend on a few corporations.
Bun is a wrapper around JavaScriptCore (the JS engine used for webkit just like v8 is used for blink or node), so not at all an independent JS runtime and is not at all a browser.
> We're talking decades of features they have to support
If this is proven not to work because the standard has grow too big as you imply then we should absolutely look into either dropping old standards or slowing the pace we introduce new standards. This project is a litmus test for the web.