Erlang/OTP 18.0 has been released
erlang.org
erlang.org
In addition, I wrote a full QuickCheck model for the new maps. That is, we randomly generate unit test cases for the maps and verify them. We have generated several millions of those test cases, including variants which heavily collides on the hash. This weeded out at least 10 grave bugs from the implementation, which in turn means this release is probably very stable with respect to maps.
1: https://medium.com/@jlouis666/breaking-erlang-maps-1-31952b8...
2: https://medium.com/@jlouis666/breaking-erlang-maps-2-362730a...
Out of curiosity: QuickCheck is a property based test library? I know of test.check in Clojure and they mention QuickCheck as the inspiration, so I guess they re similar in this regard.
Since you are searching randomly, you need good heuristics that skews the distribution toward where "errors often occurs". This means errors are uncovered in fewer test cases. Also, you need good heuristics for minimizing/shrinking a known failing error. Some of the error cases shrank from 80 commands down to 5, and furthermore simplified the input so it was easier to see what stood out.
https://github.com/jlouis/maps_eqc
There is also an accompanying series of blog posts:
https://medium.com/@jlouis666/breaking-erlang-maps-4-4ebc3c6...
(Part 4 here links to the other 3 parts in the beginning for interested readers).
https://github.com/erlang/otp/commit/37f143e9e16e89d753b0e5e...
The Erlang/OTP team runs a mantra where everything is covered by tests and they are doing a really good job at what they are doing. So I would not be surprised to see this having been caught by a test.
http://learnyousomeerlang.com/time
(BTW, there's also a talk from Erlang Factory by Lukas Larsson on the subject:
https://www.youtube.com/watch?v=gfsc2MyP8p8&list=PLWbHc_FXPo... )
Also switching to the Apache license will make adoption of Erlang/Elixir more possible for certain organizations.
Elixir also gets to reap any performance improvements at runtime and compilation.
I could make small incremental updates to a toy language and release them every week to get to FooBarLang 200.0.0, that doesn't mean it's progressing faster than a language at release 2 or 10.
It's amazing how many people actually confuse version numbers this way, including on HN (check any discussion about semver).
> ssl: Remove default support for RC4 cipher suites, as they are consider too weak.
I'm not following Erlang news but was just wondering, aren't these fixes coming out way too late?
https://www.rabbitmq.com/ssl.html
It is different from an end-user application in the sense that you can configure this in a safe way, and that has indeed been the typical workaround.
Now we just make it impossible for people to misconfigure this in any way.
The fix was also backported to 17.5 w.r.t the padding for TLS-1.0.
Another point worth mentioning is that Erlang/OTP uses OpenSSL, but only for the cryptographic ciphers. `ssl` is a complete standalone implementation of TLS in Erlang and this automatically avoids a lot of trouble. The common case is that an attack on OpenSSL leaves the `ssl` application unaffected by the error.