HNHacker News
TopNewBestAskShowJobs

accelbred

550 karma · joined November 4, 2018

archit@accelbread.com

This account is accelbred because I lost the password to accelbread...

submissionscomments
accelbred··on C Is Best (2025)
The amount of paranoia I need for unsafe Rust is orders of magnitudes higher than C. Keeping track of the many things that can implicity drop values and/or free memory, and figuring out if im handling raw pointers and reference conversions in a way that doesn't accidentally alias is painful. The C rules are fewer and simpler, and are also well known, and are aleviated and documented by guidelines like MISRA. Unsafe Rust has more rules, which seem underspecified and underdocumented, and also unstable. Known unknowns are preferable over unknown unknowns.
accelbred··on Rust--: Rust without the borrow checker
The code I have in C is often code that does't fit in Rusts safety model. Dealing with ffi is annoying because slices have no defined layout. `dyn` is limited compared to what I can do with a manual vtable. I have seriously attempted porting my personal stuff to Rust, but theres enough papercuts that I go back to C. I want the parts of Rust I find to be helpful without those parts I don't.
accelbred··on Rust--: Rust without the borrow checker
For me its everything being an expression, macro_rules, dyn, automatic conversions (the few that it does have), traits, and the ? operator.
accelbred··on Rust--: Rust without the borrow checker
I've been thinking of writing a language with Rust's ergonomics but less of the memory safety stuff. I prefer using no dynamic allocations, in which case the only memory safety feature I need is leaking references to locals into outer scopes. As for the thread safety stuff, most of my stuff is single-threaded.
accelbred··on Meta is using the Linux scheduler designed for Valve's Steam Deck on its servers
CFS was replaced by EEVDF, no?
accelbred··on Linux Kernel Rust Code Sees Its First CVE Vulnerability
The kernel policy for CVEs is any patch that is backported, no? So this is just the first Rust patch, post being non-experimental, that was backported?
accelbred··on Interview with Kent Overstreet (Bcachefs) [audio]
As far as I can tell, the only missing feature for me to try to switch to bcachefs is fs-verity.
accelbred··on It seems that OpenAI is scraping [certificate transparency] logs
Seems like you could set up a cert for a honeypot domain to collect ips of bots running off of the certificate transparency logs. If domain isnt linked from anywhere, then its pretty sure to be a bot isn't it?
accelbred··on Rust in the kernel is no longer experimental
That would be possible but also make its usage unergonomic and not the experience customers are expecting when requesting a Rust API.
accelbred··on Rust in the kernel is no longer experimental
Arenas aren't the issue. Its objects with mixed lifetimes and mutability. I cant easily model the lifetimes of objects when there are cases like an instance where buffer memory reachable from the object has a different lifetime than maps/lists. Also these objects could be transively shared or mutable. In order to make a Rust friendly model, I'd have the tree be all shared or all mutable, and have all reachable memory have the same lifetime. This would often mean allocating the full tree into one arena. That is where the overhead comes from. Each arena would need enough memory to store the entire object; currently they can be smaller since they often only need to hold parts of objects, not the entire thing.
accelbred··on Rust in the kernel is no longer experimental
That works for functions. For datatypes that are used throughout the API, it does not work so well.
accelbred··on Rust in the kernel is no longer experimental
rustup is also downloading binary toolchains
accelbred··on Rust in the kernel is no longer experimental
Lack of stable build-std and panic_immediate_abort features result in a order of magnitude size difference for some rust code I have. Using no_std brings it to ~60kb from ~350kb, but still more than the ~40kb for the C version
accelbred··on Rust in the kernel is no longer experimental
It really isn't if bootstrapping from source.
accelbred··on Rust in the kernel is no longer experimental
The code is written in an embedded style, i.e. no dynamic memory allocation or thread creation/deletion after program initialization. It's also prioritizing reducing memory usage over performance since we are targeting memory constrained devices (and our performance target is 10 tps and we have like 100k tps). Thus we'd use trait objects over monomorphization. Dynamic collections are also off the table unless backed by a fixed-size arena on the stack or static mem.

We heavily use arenas. We also have runtime-typed objects used to represent dynamically typed data like that obtained from JSON/Yaml or over IPC. If we were to be more friendly to modeling in Rust, we'd likely require that all memory reachable from an object node be in the same arena, disallowing common patterns like having list/map's arrays in one arena and having keys/strings in another or in static mem (this allows reusing other buffers without forcing copying all the data, so backing arrays can be smaller).

accelbred··on Rust in the kernel is no longer experimental
I've been working on Rust bindings for a C SDK recently, and the Rust wrapper code was far more complex than the C code it wrapped. I ended up ceding and getting reasonable wrappers by limiting how it can be used, instead of moddeling the C API's full capabilities. There are certainly sound, reasonable models of memory ownership that are difficult or impossible to express with Rust's ownership model.

Sure, a different model that was easy to model would have been picked if we were initially using Rust, but we were not, and the existing model in C is what we need to wrap. Also, a more Rust-friendly model would have incured higher memory costs.

accelbred··on Dependable C
Is there a way to force reader mode or force text not to be justified like that? I'm having a difficult time reading the content (on mobile at least).
accelbred··on Linux CVEs, more than you ever wanted to know
I, this last week, had to spend hours dealing with a fake CVE that was opened 2 years ago on an open source dependency of our project for a bug that amounts to "if you have RCE, you can construct a malicious java datatype and call this function on it to trigger a stack overflow". The github thread on the lib is full of the maintainers having to deal with hundreds of people asking them for updates on an obviously fake CVE. Yet the CVE is still up and has not been deleted. And I now get a request from a customer about fixing this vuln in our code their CVE scanner found.

The CVE system is broken and its death would be a good riddance.

accelbred··on The C++ standard for the F-35 Fighter Jet [video]
The rule isnt there to say "don't do this". It's there to say "you must prove that this holds true, in any circumstance".
accelbred··on The C++ standard for the F-35 Fighter Jet [video]
Yeah, for work stuff where we follow MISRA conventions, its easiest to use no_std and ban using third-party crates as runtime dependencies.
accelbred··on The C++ standard for the F-35 Fighter Jet [video]
No they could not. Rusts standard library heavily uses dynamic memory allocation and panics, for example. MISRA C:2025 Addendum 6 covers MISRA rules that still apply to Rust, as an example of how one would restrict Rust in safety-critical contexts.
accelbred··on What's Hiding Inside Haribo's Power Bank and Headphones?
I highly recommend avoiding their cables. Their 100W rated cables fail when connected to to 60W chargers (of thier own brand). I had tons of issues with devices intermittently charging or continuously connecting and disconnecting. Narrowed it down to Anker cables. Replaced them all and have had no issues since.
accelbred··on A programmer-friendly I/O abstraction over io_uring and kqueue (2022)
It still does not hook up to seccomp, so needs to be blocked by things doing syscall filtering. Its blocked by docker/podman. It may also be disabled with hardened kconfig or selinux.

If it ever integrates with LSMs, then it may be time to give it another look.

accelbred··on Giving C a superpower: custom header file (safe_c.h)
I wouldn't mind two types. I mind shared pointer not using atomics if I statically link pthreads and dlload a shared lib with them, or if Im doing clone3 stuff. Ive had multiple situations in which the detection method would turn off atomic use when it actually needs to be atomic.
accelbred··on Giving C a superpower: custom header file (safe_c.h)
Unfortunately, for C++, thats not true. At least with glibc and libstdc++, if you do not link with pthreads, then shared pointers are not thread-safe. At runtime it will do a symbol lookup for a pthreads symbol, and based off the result, the shared pointer code will either take the atomic or non-atomic path.

I'd much rather it didnt try to be zero-cost and it always used atomics...

accelbred··on GNOME 50 completes the migration to Wayland, dropping X11 backend code
I've used it. It works fine. You connect with RDP, get a gdm login screen, and can log in.
accelbred··on X.org Security Advisory: multiple security issues X.Org X server and Xwayland
Good. Disallowing software to position its own windows has been a major usability improvement over the X11 days of software making stupid positioning decisions and having to patch it out everywhere...
accelbred··on ARM Memory Tagging: how it improves C/C++ memory safety (2018) [pdf]
Pixels with GrapheneOS also use MTE for security hardening
accelbred··on Why Is SQLite Coded In C
You'd want to statically prove that any panic is unreachable
accelbred··on Love C, hate C: Web framework memory problems
If using C23, _BitInt allows for integer types without promotion.
← PreviousPage 2 of 7Next →