People seem to think that rewriting in rust just magically fixes all issues, but that's not how it works (See recent uutils CVEs). Rewrites tend to have more bugs because the code is new and hasn't been reviewed as much.
People seem to think that rewriting in rust just magically fixes all issues, but that's not how it works (See recent uutils CVEs). Rewrites tend to have more bugs because the code is new and hasn't been reviewed as much.
Given a comprehensive test suite for the original, probably, yes. if the test suite isn't great, you are still going to spend a lot of time/tokens chasing edge cases.
> that's 100% security bug for security bug compatible with the original
You can do this part without AI. c2rust will give you a translation that retains all the security bugs (and all the memory unsafety). The hope is that the AI in the loop will let you convert it to idiomatic rust (and hence avoid the memory unsafely, and in doing so, also resolve some of the security issues).
> If it was so easy to rewrite everything in rust, I don't know why the response to this incidents isn't a rock solid replacement in rust, the next day.
Meaning that AI/Rust enthusiasts are supposed to supply solutions. Of course they won't.
Citations and links, please.
Though I wonder why.
"bigiain" comment, in the same discussion is an example: https://news.ycombinator.com/item?id=48120707
There is comment like this everywhere, if you don't see them it's just that you don't want to see them. There are a little less frequent than 5 years ago but still frequent enough in each c, c++ or rust discussions.
I'd disagree with that poster that you can write 100% security bug free code just like that.
> There is comment like this everywhere, if you don't see them it's just that you don't want to see them.
Can you discuss productively without attacks? Mine was, and still is, a question of genuine curiosity. And the only "fanatic" thing in your linked comment is a bogus 100% claim. I'm not seeing fanaticism.
I didn't use the word 'fanatic' neither the previous comment you were responded too.
> Can you discuss productively without attacks?
So you thing someone telling you "look a little harder" is a "personal attack" ? After I took some time to give you a link you ask for ?
> I'm not seeing fanaticism.
You are the only one using this word in this discussion.
If you are taking the time to find a link then understand that your effort can be for naught if you could not resist to insert "if you don't see them it's just that you don't want to see them". What's your imagined ideal outcome when you comment... this, exactly?
Advice: just put the link and skip snarky commentary. Trying to emotionally load your message does not move discussions forward. It puts them in a corner.
> You are the only one using this word in this discussion.
OK, fair -- then I want to hear what words you'd use. Apart from the guy claiming an imaginary "all security bugs will be fixed" which I already said I disagree with, are there other criticisms?
That you take more time to search yourself before asking other to do it.
> Advice: just put the link and skip snarky commentary
As usual, the one requesting compliance to other is often the worst offender.
> Apart from the guy claiming an imaginary "all security bugs will be fixed" which I already said I disagree
That was exactly the point of the 'bluedragon1221' initial comment you were responded to. So finally you agree ?