HNHacker News
TopNewBestAskShowJobs

pml1

0 karma · joined May 28, 2020

submissionscomments
pml1··on New fuzzing tool finds USB bugs in Linux, Windows, macOS, and FreeBSD
> When you write C/C++, 100% of that codebase is unsafe.

Don't you think that statement is a bit over-the-top ? Large parts of C/C++ codebases are just as safe as the equivalent Rust code, as it doesn't do any pointer/memory manipulation.

For example, how is making a os system call in Rust any safer than the equivalent call in C ?

pml1··on New fuzzing tool finds USB bugs in Linux, Windows, macOS, and FreeBSD
> Writing C, you're constantly at risk of making these mistakes. Writing Rust, you can keep the vast majority of your code safe and more closely examine the smaller unsafe area for memory errors.

I think this is a fallacy...The majority of C code doesn't manipulate pointers either. The point is, the moment that you have _any_ unsafe code (C or Rust), it's a question of time before you will have some bugs, especially if you have a very large number of people working on the same code base...you may be extra careful, maybe the next guy is not...Rust is not going to magically solve these problems for unsafe code...

pml1··on New fuzzing tool finds USB bugs in Linux, Windows, macOS, and FreeBSD
It won't be rare in driver code.
pml1··on New fuzzing tool finds USB bugs in Linux, Windows, macOS, and FreeBSD
>So there will of course be some unsafe. In a well implemented driver it will also be very limited in scope and relatively easy to check.

I'm sure that is what the C developer thought as well...I'm not trying to be snarky, but that same arguments that are made against C code holds equally true for unsafe code...

I don't think it is a reasonable position to suggest that unsafe Rust code is somehow safer than C code...

pml1··on New fuzzing tool finds USB bugs in Linux, Windows, macOS, and FreeBSD
So the same argument that is made against the "mythical C programmer that never makes memory corruption mistakes" is also valid for the mythical Rust developer that never makes mistakes in unsafe code... It's two sides of the same coin.
pml1··on New fuzzing tool finds USB bugs in Linux, Windows, macOS, and FreeBSD
really ? You've checked all the code in question and you are a 100% sure that you would have required _zero_ unsafe code ?

Drivers by their very nature require a lot of unsafe pointer passing...Having worked on a lot of embedded Linux driver code, I'm not convinced that you could do without a ton of unsafe code...which basically negates all of Rust's safety guarantees...The current architecture just doesn't lend itself well to Rust (in my opinion), so you would have to basically rewrite very large parts of the plumbing, which by its very nature would introduce a ton of new bugs...