So if I go to Google docs, I can toggle spidermonkey (or whatever Firefox's JS compiler is called nowadays), but if I go to $randomwebsite, I'll get a secure and usable web.
1,066 karma · joined February 28, 2017
So if I go to Google docs, I can toggle spidermonkey (or whatever Firefox's JS compiler is called nowadays), but if I go to $randomwebsite, I'll get a secure and usable web.
How big of a deal is this IRL? Assuming you have 1000 modules, how long should it take to solve the graph?
It would be interesting to see what would happen with linux after that, as they are one of the biggest (if not the biggest) donors to Linux, and while you'll still find Enterprise Linux for the Server (whether it's them or some successor), they are also responsible for things like Linux on the Desktop and FOSS in general, so projects which don't directly make money like Cygwin, gtk, gnome, gcc, and PulseAudio may be in danger.
What do they rewrite? To the best of my knowledge, they have no problem using BSD licensed software, they just won't develop BSD license software[1] (mostly, though they do approve it here and there for new projects).
[1]. More accurately, they won't approve it for new projects. But the projects are fine.
For example:
1. JS is single-threaded, with extremely heavy threads only recently made available. So Dart is single threaded, with extremely heavy threads available.
2. JS is weak-typed, so Dart was made optional typed. Remember, it was made before typescript, so they probably didn't expect that such type-heavy features as ADT would interest people.
Kotlin does the same (for example, internal immutability would be much nicer, but since the JVM doesn't support that, neither does Kotlin).
[1]. Although it'll be a pity. JS is stuck as a compilation target because it's a standard, and it's old, and even then wasm may one day take over JS. Flutter could have been a library, and one could have written in Go or Rust or Java with Flutter bindings. As it is now, I don't know if its possible.
I wish there was:
1. A good Kotlin language server (unlikely, as the company behind the language is an IDE company).
2. A good reactive Kotlin GUI library (meaning, with the ergonomics of Flutter (as in, I don't have to work with Fragments and their lifecycles, just use views)).
3. A good JVM interpreter (to speed up Kotlin/Java compilation)
[1]. No I don't use Flutter to "write two apps for the price of one", as most (of my) apps are just a front-end over a back-end server, so they don't have any special logic worth saving between iOS and Android. I just find Flutter easier to work with relative to Android.
Not everything is fixable with rust. JS, for one, is JIT compiled, so Rust wouldn't help much there (it's one of the reasons it's not being oxidized).
"Also, Rust’s memory safety only applies to code written in Rust, but a JIT compiler also generates machine code and then jumps to it. That generated code does not benefit from rustc’s static analysis."[1]
[1]. https://www.reddit.com/r/rust/comments/8ptnfr/servo_to_upgra...
You also communicate to Java through serialization, rather than through shared memory.
Oh, and any communication goes through a Future, which is annoying.
Sorry, I'm slightly confused.
I browse newproduct.google.com. My browser calls the DNS, asking for the IP. The IP comes back as 192.168.0.1 [1]. It connects to 192.168.0.1. Gets hit by an XSS, and sends your cookie value to evildoer.example.com.
How would it help you that the reverse-IP of 192.168.0.1 issfo07s13-in-f14.1e100.net? The browser doesn't know that. It thinks its going to newproduct.google.com.
[1]. Yup, that number is just an example.
1. If it's a bug, it should overflow or crash (implementation defined, not undefined), or do what Rust does, crash on -o0 (or, if it's illegal to change defined behavior based on optimization level, create a --crash-on-overflow flag) and overflow on everything else.
2. There is plenty of code where it's intentional (such as the infamous if(a+5<a)).
What they could have done is made it implementation defined, like sizeof(int), which depends on the implementation (hardware) but on the other hand isn't undefined behavior (so on x86/amd4 sizeof(int) will always be equal to 4).
You created the first "better C" out there to get any traction, it had a perfect name (B -> C -> D), but due to factors that were partially [2] outside your control [3], D's niche got eaten by Go and Rust.
[1]. The D programming language. [2]. I've seen people blaming the D to D2.0 transition, but D was a niche language before too. I've also seen people blame D for not having an Open Source compiler for years, but neither did Java, and it took off anyways. [3]. Such as Sun's marketing, or the general push to scripting languages between 1995-2010 (such as perl, tcl, PHP, Ruby, Python and Node)
Except Debian's install CD. They only have nano.
Is it worse than running Firefox without firejail?
I think you can do that in Rust too (post 1.0). What's more impressive is that canonical go code from five years ago is still canonical.
So now, for each device, you have to port desktop Linux [3] to whatever generation kernel it came with.
Debian, in contrast, can assume that you're using the standard modern kernel.
[1]. I mean that it should work as a phone, not just a small tablet. So if it can't make phone calls, it ain't a phone. All the more so if you want a working GPS and Camera.
[2]. I would have said Gnu/Linux but postmarket is based on Alpine which is based on busybox/muslc and not gnu.
[3]. Anything which issues syscalls is fair game, so, for example, if your oldest phone you want to maintain is six years old, then you have to back port every single program (and library!) to work on a random seven year old kernel.
Even back porting android user space (which is mostly Java and doesn't interact directly with the kernel) is a huge pain (and sometimes is actually that hard that the maintainers just give up). Porting back Debian?
2. You may only use apps Apple approves. So no Firefox for you.
It's like Chromium on Debian. It's Google code compiled by Debian
If you want someone to volunteer their time, you'd better treat him well.