653 karma · joined October 19, 2015
1. "Undefined behavior" due to typical memory bugs: code written in 100% safe Rust cannot trigger this behavior.
2. "Undefined behavior" due to a stack overflow: this can happen in safe Rust, but you can provably guard against it by banning recursion and dynamic dispatch, and doing static stack depth analysis on your program.
3. Panic/abort: naively written bare-metal Rust typically has many potential calls to panic!() due to bounds checks, integer overflows, .unwrap(), etc, and if these get called the system will typically fail catastrophically. I like to solve this by having CI fail if the optimized binary contains ANY call-sites to the panic handler. This forces the developer to handle these edge cases with idiomatic error handling before they can merge their code (but can cause some development pain/brittleness when the optimizer heuristics change).
4. Infinite loops: in most bare metal systems, if a section of code doesn't complete within some reasonable time, a watchdog will fire and the system will crash. Ideally there would be some static analysis that could tell me whether some particular code is capable of exceeding the allotted time bounds, but I'm not aware of such tooling, and need to resort to hacky solutions such as fuzzing and handling resets "gracefully" at runtime.
Today's computers, operating systems, networks, and human bureaucracies are so full of security holes that it is incredible hubris to assume we can effectively sandbox a "superintelligence" (assuming we are even capable of building such a thing).
And even air gaps aren't good enough. Imagine the system toggling GPIO pins in a pattern to construct a valid Bluetooth packet, and using that makeshift radio to exploit vulnerabilities in a nearby phone's Bluetooth stack, and eventually getting out to the wider Internet (or blackmailing humans to help it escape its sandbox).
This works well until the requirements change and you have to run two structured control flows simultaneously. If I find myself in such a situation and have no SRAM for a second thread, rust async may be the quickest way to accomplish the goal without a major rewrite into manual event driven code.
Because of RAM constraints, all the bare-metal projects I've worked on have used manually-written state machines, and I'm comfortable enough with this approach. But sometimes these state machines can be hard to understand when the control flow is complicated, and I am seriously considering adding some compiler-generated state machines that will fit nicely into my existing model.
If you care about RAM consumption, you need to share the stack between tasks, forcing you to write event-driven code. Rust async makes this easy, and a bit of function coloring is no big deal compared to converting blocking code into event-driven code the traditional way...
"Buying an entire development" is arguably anticompetitive behavior and can be prevented by the government.
I think Johnson and Johnson's covid vaccine (also an adenovirus vaccine) was also associated with blood clots, but do you have any evidence of clots with the mRNA vaccines? I recall reports of Myocarditis in younger men that got little value from the mRNA vaccines, but this is the first I've heard of blood clots.
AstraZeneca's Covishield is not an mRNA vaccine; it is a viral vector vaccine, using Adenovirus. The small possibility of blood clots was acknowledged by medical authorities after a few months of use, with some jurisdictions going so far as to suspend its use, citing the mRNA vaccines as a safer alternative.
https://en.wikipedia.org/wiki/Oxford%E2%80%93AstraZeneca_COV...
I hope most Amish communities can avoid the following:
1. Off-grid solar systems that eventually shutdown if they lose network connectivity.
2. Tractors and other agricultural equipment connected to the internet, likely susceptible to remote security vulnerabilities that could threaten the harvest.
3. Complex supply chains that require cloud services and network connectivity to function.
If you're serious enough about home networking to run cables through your walls, $700 for a switch is nothing compared to the labor cost.
https://www.servethehome.com/mikrotik-crs504-4xq-in-a-4x-100...
When the lifetime of cables in the walls is typically more than 40 years, it makes sense to avoid limited technologies like copper or multi-mode fiber.
What I found worked best was to buy a bunch of 50 meter pre-terminated plenum-rated cables and cut them in half. I'd plug the pre-terminated ends into the wall-jack coupler, then weave the cut end through the walls back to the splicing cabinet, where I'd leave several turns of slack and fusion splice the pigtail which I plugged into the patch panel.
I don't believe I'm moving any goalposts. From the first paragraph of my original comment:
> Imagine a world where everyone in the state has an overbuilt solar battery system installed, but still relies on the grid those few times a year with extended cloud cover.