It would then be actually really hard to successfully run a C program (in the debugger) with any problems. Under these conditions it'd be easy to imagine most C programs running with fewer bugs (, leaks, etc.) than Rust programs.
It would then be actually really hard to successfully run a C program (in the debugger) with any problems. Under these conditions it'd be easy to imagine most C programs running with fewer bugs (, leaks, etc.) than Rust programs.
You can't even do anything in C without some asm (syscall wrappers) because C was meant to boil down and streamline PDP-11 assembly (Your computer is not a fast PDP-11) to a set of consistent principles. The consequence of this is that the core of the language is pointers and pointer arithmetic, and raw unabstracted pointers are fundamentally unsafe to work with.
Using the rust type system I can essentially confirm code is bug and edge-case free with exhaustive matching and unit testing (C's lack of tooling blessed the world with autoconf and cmake btw). Not to mention rusts ability to abstract away necessary boilerplate gives me more time to think about my code instead of pointer arithmetic and allocation heuristics.
The "cure" for C is a language that abstracts away raw pointers and memory allocation.
Which language can do anything without some asm and support as many platforms as C?
I wouldn't be surprised if someone figured out how to do the interrupts and register control necessary to invoke syscalls with pure LISP/Scheme/CL :P
P.S. anything that compiles with LLVM and has an ingrained way to do print() that doesn't invoke libc, although there's a blurry line here between "pure asm"/"compiles to asm" that involves trusting-trust-style bootstrapping of features into the compiler
> I wouldn't be surprised if someone figured out how to do the interrupts and register control necessary to invoke syscalls with pure LISP/Scheme/CL :P
Haha
> P.S. anything that compiles with LLVM and has an ingrained way to do print() that doesn't invoke libc, although there's a blurry line here between "pure asm"/"compiles to asm" that involves trusting-trust-style bootstrapping of features into the compiler
Actually LLVM IR has no concept of syscalls, you have to use inline assembly inside your IR to issue syscalls.
Here is what assembly code looks like in (ccl) Clozure Common Lisp:
https://github.com/Clozure/ccl/blob/master/level-0/X86/x86-h...
ARM version of same file:
https://github.com/Clozure/ccl/blob/master/level-0/ARM/arm-h...
If you mean that a dereference of a memory location involves the compiler emitting pointer arithmetic instructions -- that's true of all languages.
If you want your language to completely disguise the machine from you, and "abstract away" memory allocation, you're going to pay a high complexity cost to do so.
If you have never run C in a debugger, with the massive amount of highly sophisticated tooling available to C debuggers, then you're operating from a profoundly mistaken starting point for evaluating the viability of C for modern safe sofware development.
C debuggers and tooling are vastly more powerful than Rust's static type system, and catch a much wider array of memory problems (, and bugs) than the Rust compiler can catch. Static verification is far more limited than the dynamic verification a sophisticated debugger can perform.
People's undergrad C course is a terrible basis on which to evaluate what C is today. The reason C is associated with a lack of security is that almost all software is written in C, written in a time when either the internet didnt exist or didnt imply an adversarial local environment.
Running a network cable through every facet of our O/S and software breaks many assumptions about the entire history of programming -- which C predominated in. This is a very poor basis on which to generalize the capabilities of a well-specified C programming environment (which today, is much more powerful than Rust's compiler).
The problem is - undergrad C is about the lowest common denominator that all tooling understands and that all people understand. Of course you're probably not going to have to go as low as C89 like sqlite or, until 2022, the Linux kernel [1], but still, the long support cycles of many distributions make it challenging to move standards upgrades forward.
[1] https://www.zdnet.com/article/linus-torvalds-prepares-to-mov...
Is there any dynamic verifier that fully validates all acesses w.r.t. the object trees specified by the C standard? Tools like ASan and UBSan won't detect a write to one field running into another field, only a write overrunning the complete object. (Compiler-level hardening might catch that to some extent, but it's limited to TU boundaries.) Not to mention things like 'misuse of restrict pointers' that I've never seen any verifiers for, except for special cases like overlapping memcpy() buffers.
Meanwhile, Rust does have its own dynamic verifier, called Miri [0], which checks just about every language-level rule at runtime. The main drawbacks are that it's slow and doesn't support calling arbitrary C functions, but it would be hard to get that to work short of the Valgrind route of emulating the whole process on an instruction level.
There's also nothing stopping debuggers reifying the C at debug-time into this metadata.
My claim is 95% can be fixed by just normalizing what is current practice at the stdlib level and compiler level. By extending constexpr, i think you could get to 100%. Given that this is the case, why even both with the nightmare of Rust.
When people propagandize about C, they're universally unaware that the normal process of development basically addresses most of the problems Rust is supposed to be solving, and more than the rust compiler alone solves. The remainder are 95% to do with libc, which should just be thrown out.
A smidge more compile-time eval with constexpr, and the use case for Rust could disappear. It's a great shame that C is run by a standards process that's determined to relegate it to electric motors and digital watches from the 80s.
As someone who's worked on C debuggers and tooling... I really have no idea what you're talking about. C's core semantics are just so weak that it's not really possible to express a lot of the things you can express in the type system, and that's before we get to the necessary lossiness that debuggers and tooling have to work with (e.g., you can't just ascribe types to memory in C because C--in practice--is way too loose with types for that to be meaningful).
For an example from something I've worked on, Linux manages to have two different arrays for the GPRs for a thread register context, one that's used for ptrace and one that's used for signal contexts. Helpfully, the header files give you macros to map register names to numbers so that you can say regs[RAX] instead of regs[0]. But the offsets are different, so you have to remember that you need to use regs[REG_RAX] instead of regs[RAX], and there is absolutely no tooling in the world that can tell you when you get it wrong because there is no expressible difference between the two scenarios in C. Meanwhile, in Rust, I can wrap the accessors in newtypes so that I can only use the correct set of constants to index into the array, which makes the error state literally impossible to construct.
That's the real value of a static type system--you can use it to make errors literally impossible to specify in an API.
If your point is that historical C APIs have overused an untyped operation, that's part of my point about a new std lib. Rust APIs can still provide an untyped indexer, it's just bad API design.
What I'm imagining a new std lib would be doing is having debug allocators, metadata against types, etc. Ie., a std library designed for the debugger along with a release version.
In Rust, I can express an API which can't be used incorrectly. In C, I can't. Sometimes, in C, you can sometimes get to the point where you use conventions that means maybe static or dynamic analysis tools might be able to flag the misuse of the API, but very often, such tools have extremely poor tradeoffs between precision and accuracy, far worse than exists in Rust with just the vanilla compiler.
My point isn't that you exhaust all the features of Rust with a better stdlib and "debugger-oriented programming" -- my point is that you can get 95% of the way there with trivial complexity costs.
Rust imposes significant program design costs which can be very detrimental to otherwise trivial performant memory management, to faster iteration of software design, and so on. These aren't free lang. features.
Neither ISO nor OpenGroup would care about it.
Remember that since 1989, no actions were taken to improve its security.
Even the few functions that have been added still use pointer/length pairs without any means to validate they are the correct pair.
Not much, but not nothing, either. gets was deprecated in C99 and removed in C11 (https://en.wikipedia.org/wiki/C_file_input/output#gets)
Technically, gets() was removed from the standard library in C11[0]. However, that is far from a semantically meaningful overhaul of the standard library. I nonetheless felt the need to point out that there was a very specific effort for the sake of completeness.
Would it be easy enough to port important C code to it, given that most of the libc-supplied functions, and functions transitively depending on these, would have to be rewritten? Would it be worthwhile, compared to rewriting such code it in Zig, Rust, or Ada?
Only bothering to list two examples, there are many others, even Cyclone is partially C compatible, guess what came out of Cyclone.
import statements are a deal breaker
>C3
shit syntax
>Cyclone
vaporware
There's a Safe C++ extension proposed for Clang [0].
But those are C++, not C. A little different kettle of fish.
Gnome's Vala [1] aims to be the "smoothest C off-ramp". It does compile to C, but with GObject taking control of everything.
There's CheckedC [2], which adds optional bounds checking to C, and was backed by Microsoft until recently.
There's the Linux kernel's nolibc [3], which I've enjoyed the heck out of using, but it is rather constrained.
There's C's own Annex K [4], that almost nobody has implemented, and every compiler developer hates and can poke holes in. GCC and LLVM have both repeatedly said they won't support it. (So much as easy to get them to support things...)
GCC already has a number of memory safe languages, though. Most of which, because they're part of the same compiler suite, can interact with other languages that GCC has. Like the D or Go frontends.
[0] https://discourse.llvm.org/t/rfc-a-clangir-based-safe-c/8324...
[3] https://lwn.net/Articles/920158/
[4] https://www.open-std.org/jtc1/sc22/wg14/www/docs/n1106.txt
i mean, if the committee members can make it happen or not, i don't know. but it's still a worthy thing to explore, I think. there's going to be a lot of C code that will need a very gradual migration path to safer apis for a very very long time.
But this?
> Under these conditions it'd be easy to imagine most C programs running with fewer bugs (, leaks, etc.) than Rust programs.
This is a crazy goal. You will never out-rust rust by adding a few runtime checks to C, while in debug mode. Fewer bugs than rust code is a wild goal.
I don’t think you understand just how much rust’s design prevents you from shipping bugs. It’s due to a combination of so, so many things. Like: references instead of pointers, unsafe blocks, sum types & match instead of unions, no implicit nullability, unwrapping optional values is explicit, the result type and #[must_use], bounds checks, the borrow checker preventing use after free, ownership semantics, Send & Sync for thread safety, and I’m sure plenty more.
It’s common to write very complex, threaded rust code and have it work first time. Well, the first time it compiles. Coming from C, it’s wild. Or, really, just about any other language.
To get the same result in C wouldn’t just need a “strict mode”. You would need to ban raw pointers - which would make it no longer C. And you’d need to make functions return more than an (easily ignored) status code. Ie, you want a result type. For bounds checking, you’d need a language level data structure for slices / arrays (pointer + length). You’d have to do away with void pointers for “generic” parameters. And probably 100 other tiny, breaking changes that the C community will never accept.
And for all that, you would essentially get zig. Zig does all these things.
But that would still get you worse bug density than rust because you don’t have a borrow checker. It’ll get you close - Runtime checks in debug mode will detect your use after frees - if you have a good test suite. But they won’t prevent aliasing. Or (I think) help with thread safety. For that, you need a borrow checker. You need rust.
I don't think we have a good evidential basis for comparing the total class of programming bugs in Rust vs. comparable langs -- since there isn't that much Rust code.
One "empirically ambitious" claim here is that the very high complexity of rust isn't design-bug-free, and "getting to 95%" with a modern C toolchain retains a very low-complexity get-it-done-and-iterate style of programming which has many "bug free'ing" advantages. Esp. if supported by a "debugger-oriented std lib"
Speaking of things that don't have "good evidential basis"... I love how you apply an incredibly high standard of scrutiny to claims made by others but you neglect to do the same for your own claims.
The idea that memory leaks in Rust are easier than in C, even in this C with this fantasy standard library, is just absolutely ludicrous. We are living in two different planes of existence.
The C you're talking about doesn't exist and you're way way way over-stating the prevalence of bugs in Rust because of its iteration times/complexity/"design constraints." Which is another claim that doesn't have "good evidential basis." It's funny how the claims suggesting that Rust reduces bugs require a high standard of evidence, but the claims suggesting that Rust introduces new bugs that are more easily addressed by C are passed on without any scrutiny at all.
And where did you get this 95% figure from? Did you just pull out of thin air? Where is your "good evidential basis"?
Look, it's fine to theorize about things and have opinions and guesses. I get that. But when you don't let others have that same grace, your inconsistent application of evidentiary standards becomes plain.
You have also identified, as I have in my own comments, that some of my claims are as empirically difficult to verify.
> 95% of the supposed issues with C could be solved by a new standard library
But now you're saying this does actually exist, and the answer is actually "no standard library" and not a "new standard library."
Is this the same code responsible for all the memory safety CVEs we see?
And great job at plucking one pittance out of my comment and responding to it, while completely ignoring the more substantive critique of your inconsistent application of evidentiary standards in your commentary.
> You have also identified, as I have in my own comments, that some of my claims are as empirically difficult to verify.
The circumspection you describe here does not at all come across in your commentary. Your commentary does not read like it has appropriate circumspection. Instead, you just state things as if they are facts:
> 95% of the supposed issues with C could be solved by a new standard library, integrating the debugger into the compiler as the default build/run environment (with auto address sanitisation, frame protection, etc. etc.), and a default strict mode error checking.
There is no circumspection there. There is no expression of uncertainty. There is no admission that you lack "good evidential basis."
There's no concrete examples from you. No specific pointers to anything. Just made up statistics.
Yes, people write their own stdlib for C, and the better ones are written effectively "for the debugger". This is code that runs spaceships, nuclear power plants, xray machines, and the like.
Rust fanatics exist in this parallel universe in which it was, necessarily, the language which was the original sin -- so that Rust can be sold upon a cross as the redemption for C.
There's plenty of existence-proof systems that are written in C with the goal of saftey and reliability. No libc, and historical programming in general did not have that goal. This has vastly more to do with the history of programming, and its assumptions of non-adversarial low-risk host systems -- than to do with what contemporary C development necessarily looks like. As-if C developers are actually unable to detect use-after-free or double-free etc. std memory saftey issues; it's absurd.
> Rust fanatics
Oh okay, so if we're going to go there, then I just get to call you a C fanatic. And yes, indeed, we live on two different planes of existence, as I said. That's for damn sure.
> but I can nevertheless point to its absence in official sales pitches
Which "official sales pitches"? I don't see any in this HN thread. Yet again applying inconsistent evidentiary standards.
> There's plenty of existence-proof systems that are written in C with the goal of saftey and reliability. No libc, and historical programming in general did not have that goal. This has vastly more to do with the history of programming, and its assumptions of non-adversarial low-risk host systems -- than to do with what contemporary C development necessarily looks like.
You might be saying something significant in that paragraph of word salad, but I can't spot it. I'm not confused as to why C is the way it is. That isn't the interesting bit.
> As-if C developers are actually unable to detect use-after-free or double-free etc. std memory saftey issues; it's absurd.
Odd that they keep making that mistake then!
Huh? Memory leaks? Poor iteration time? "Different kinds of bugs"? What are you talking about?
How do you leak memory in rust by accident? I've worked fulltime in rust for ~3-4 years and I don't think I've ever leaked memory in my code. I did it once on purpose in a script - but that was by explicitly calling Box.leak().
Poor iteration time? What? In my experience, iteration time in rust is significantly faster than that of C. Sure - the first program you write is hard, because learning rust is horrible. But once you know it, the ergonomics of the language make it a dream to work in. People make a big deal of the borrow checker, but its all the little things that the language does right that makes it productive to work in. Sum types. Match expressions. Iterators. Cargo. Editions. #[test]. References. Option and Result. Documentation. A standard library that works the same on every platform. And so on. Turns out we got better at inventing programming languages in the 50 years since C was invented. This isn't a rust thing - Swift, Zig and - in many ways - typescript and C# all support the same great feature set.
If you want to complain about rust, get in line. I'm no fanboy, and there's a laundry list of legitimate complaints you can make about the language. I've written thousands of words on the subject and annoyed a lot of people right here on HN in the process.
But you have to use it if you want to understand its flaws. It sounds like you're just inventing problems with rust from nowhere. How dull.