There have been a dozen CVEs reported against all of coreutils in the past twenty years. The most recent audit of uutils-coreutils turned up forty-four CVEs.
By all appearances they’re replacing battle-tested and fundamental tooling which hasn’t been a problem with extremely amateurish Rust. The threading highlighted in the linked post above seems pretty egregious.
I would appreciate Go much more otherwise.
Also for Rust based rewrites, they could start by bootstraping Rust compiler itself, dependent on C++ to start it.
They don't do it, because even though LLVM and GCC are written in C++, a pure Rust compiler would not scale to the same level of contributions, and existing capabilities.
YOU have proclaimed the language to be as fast as C while being safe. YOU need to prove it. Think of this as an OPPORTUNITY to PROVE that Rust can walk the walk, and you can make Rust coreutils as fast as the C one. Think hard about how you can model low level Linux constructs safely. Fix your libs. Fix the compiler. This is the yardstick you need to meet. You are making free software, and the thing about it is users are free to choose otherwise. YOU need to prove that Rust is just as fast and lightweight as C, and once you do, we'll be happy to adopt.
Right now, dear Rust devs, what you are doing is the same as AI companies are doing - you're trying to usurp power based on extremely nebulous conjured threats. Nobody likes being threatened.
which ideology? Are people saying that there's an ideology of pushing rust for things without concern for quality? Sincere question, because I'm seeing that on this thread and I wasn't aware that that was a thing beyond the "re-write it in Rust" meme.
Yes, there is. There are people who genuinely think quality does not matter as log as it is written in Rust as Rust is memory safe.
Is this hyperbolic? Such people are in leadership places?
Many people have decided that this decision supposedly specifically about licensing ideology.
You can make up your mind about which of the two you believe.
See also, for Ubuntu's take on this: https://news.ycombinator.com/item?id=49707948
Let's not mention other aspects of security, such as the recent supply chain issue, or the old story of the serde maintainer shipping a binary blob just because...
This is literally an /r/pcj meme.
You weren't kidding: it was exactly 4 years ago ("September 13, 2022").
Mirrored the way I implemented status=progress in FreeBSD dd, though there the flag was set by a SIGALRM timer: https://freshbsd.org/freebsd/src/commit/4767c42c1146459eb751...
It would appear GNU dd 9.9 still does a call for every block. Low-hanging fruit if anyone fancies it:
dd if=/dev/zero of=/dev/null count=100000000 status=progress
51200000000 bytes transferred in 18.644004 secs (2746191200 bytes/sec)
target/release/dd if=/dev/zero of=/dev/null count=100000000 status=progress
51200000000 bytes (51 GB, 48 GiB) copied, 20.8772 s, 2.5 GB/s
gdd if=/dev/zero of=/dev/null count=100000000 status=progress
51200000000 bytes (51 GB, 48 GiB) copied, 23.6744 s, 2.2 GB/s