• atzanteol
    link
    fedilink
    English
    arrow-up
    139
    ·
    2 months ago

    Why the swipe at Linus? He’s been supportive of rust in the Linux kernel.

      • atzanteol
        link
        fedilink
        English
        arrow-up
        69
        ·
        edit-2
        2 months ago

        I did - it says he’s supporting rust in the kernel.

        • Captain Aggravated
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          7
          ·
          2 months ago

          I do know that Linus is on record with low opinion of C++. I have heard of him compare the cult-like following Rust has with the whole Vim/Emacs tribalism thing.

          • xav@programming.dev
            link
            fedilink
            arrow-up
            23
            ·
            2 months ago

            I didn’t understand this. He said the bickering between C and rust devs reminds him of the vim/emacs debate.

          • MajorHavoc@programming.dev
            link
            fedilink
            arrow-up
            15
            arrow-down
            4
            ·
            2 months ago

            I have heard of him compare the cult-like following Rust has with the whole Vim/Emacs tribalism thing.

            Heh.

            I do think the worst thing going for Rust, right now, is the Rust community.

            It feels like few specific jackasses from the Java community made the jump to Rust, and no one had the sense to slap them with a newspaper.

            • bamboo@lemm.ee
              link
              fedilink
              arrow-up
              8
              ·
              2 months ago

              Can you be more specific? I’ve had nothing but great experiences from the rust community.

              • MajorHavoc@programming.dev
                link
                fedilink
                arrow-up
                4
                ·
                edit-2
                2 months ago

                Can you be more specific?

                Sure.

                I’ve had discussions about my impression that Rust’s build chain can be a bit surly compared to other popular languages.

                I don’t particularly mean it as a criticism - of course Rust’s security enforcement comes with more warnings and errors.

                But the novel part of the interactions, for me, was Rust community members coming at me with ‘well get gud, newbie’.

                These interactions are particularly ironic, given my experiences and specialties. I’m an old school veteran software developer. I have spent over half of my career in dedicated Cybersecurity roles.

                These conversations converted me from a mildly interested Rust proponent into a casual Rust critic.

                • bamboo@lemm.ee
                  link
                  fedilink
                  arrow-up
                  4
                  ·
                  2 months ago

                  Well I’m sorry that you got shitty responses like that. Which platform(s) was this on?

  • JakenVeina@lemm.ee
    link
    fedilink
    English
    arrow-up
    90
    arrow-down
    2
    ·
    2 months ago

    If only it were that easy to snap your fingers and magically transform your code base from C to Rust. Spoiler alert: It’s not.

    How utterly disingenuous. That’s not what the CISA recommendation says, at all.

  • Solemarc@lemmy.world
    link
    fedilink
    arrow-up
    87
    ·
    2 months ago

    I don’t get why we’re taking a swing at Linus here. The article only mentions him in relation to the rust for Linux project being slow going. But, it IS going and the US government has only stated that “you need a plan to move to a memory safe language by 2025 or you might be liable if something bad happens as a result of the classics (use after free/double free/buffer overflow/etc.)” but I don’t think Linux would count it’s free software and it does have a plan.

  • riodoro1@lemmy.world
    link
    fedilink
    arrow-up
    44
    arrow-down
    3
    ·
    2 months ago

    The US government has more pressing issues I think.

    Maybe it can shut the fuck up an let me do my job in contrast to its judicial branch.

  • tourist@lemmy.world
    link
    fedilink
    arrow-up
    35
    arrow-down
    6
    ·
    2 months ago

    My friend from university sends me his Rust code snippets sometimes. Ngl it looks like a pretty cool language.

    There was also that tldr reimplemention in Rust that is a gatrillion times faster than the original.

    I really want to give it a try but I have executive dysfunction and don’t have any ideas of what I could use it for.

    • ScreaminOctopus
      link
      fedilink
      English
      arrow-up
      23
      arrow-down
      2
      ·
      2 months ago

      The main issue I have with rust is the lack of a rust abi for shared libraries, which makes big dependencies shitty to work with. Another is a lot of the big, nearly ubiquitous libraries don’t have great documentation, what’s getting put up on crates.io is insufficient to quickly get an understanding of the library. It’d also be nice if the error messages coming out of rust analyzer were as verbose as what the compiler will give you. Other than that it’s a really interesting language with a lot of great ideas. The iterator paradigm is really convenient, and the way enums work leads to really expressive code.

      • snaggen@programming.dev
        link
        fedilink
        arrow-up
        17
        arrow-down
        3
        ·
        2 months ago

        As someone that have worked in software for 30 years, and deplying complicated software, shared libraries is a misstake. You think you get the benefit of size and easy security upgrades, but due to deployment hell you end up using docker and now your deployment actually added a whole OS in size and you need to do security upgrades for this OS instead of just your application. I use rust for some software now, and I build it with musl, and is struck by how small things get in relation to the regular deployment, and it feels like magic that I no longer get glibc incompatibility issues.

        • 0x0@programming.dev
          link
          fedilink
          arrow-up
          5
          arrow-down
          1
          ·
          2 months ago

          due to deployment hell you end up using docker

          Maybe tackle that deployment hell instead of band-aiding it with docker?

          • FizzyOrange@programming.dev
            link
            fedilink
            arrow-up
            4
            arrow-down
            3
            ·
            2 months ago

            He is. By using statically linked binaries.

            Technically this is conflating two things: bundling dependencies and static/dynamic linking. But since you have to bundle your dependencies to use static linking, and there’s little point dynamic linking if you bundle your dependencies… most of the time they are synonymous.

            Exceptions are things like plugins, but that’s pretty rare.

        • ScreaminOctopus
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          1
          ·
          2 months ago

          Maybe for your use cases that’s OK, but there are many situations where the size and ease of upgrading provided by shared libraries is worthwhile. For example it would suck to need to push a 40+ GB binary to a fleet of systems with a poor or unreliable internet connection. You could try to mitigate this sort of thing by splitting the application up into microservices, but that adds complexity, and isn’t always a viable tradeoff if maximizing compute efficiency is also a concern.

          • calcopiritus@lemmy.world
            link
            fedilink
            arrow-up
            3
            arrow-down
            1
            ·
            edit-2
            2 months ago

            I’m not so sure that dynamic libraries always reduces the size. Specially with libraries that are linked by a single binary.

            With static libraries, you can conditionally compile only the features you’re gonna use. With dynamic libraries, however, the whole library must be compiled.

            EDIT: just to clarify, I’m not saying that static libraries result always in less size. I’m saying that it’s not a black and white issue.

      • nous@programming.dev
        link
        fedilink
        English
        arrow-up
        15
        arrow-down
        1
        ·
        2 months ago

        Documentation is generally considered one of the stronger points of rust libraries. Crates.io is not a documentation site you want https://docs.rs/ for that though it is generally linked to on crates.io. A lot of bigger crates also have their own online books for more in depth stuff. It is not that common to find a larger crate with bad documentation.

        • ScreaminOctopus
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          2 months ago

          One specific example I encountered was ndarray. I couldn’t figure out how to make a function take an array and an arrayslice without rewriting the function for both types. This could be because I’m novice with the language, but it didn’t seem obvious. I ended up giving up after trying to dig through the docs for a few hours and went back to C++.

      • asdfasdfasdf@lemmy.world
        link
        fedilink
        arrow-up
        7
        arrow-down
        3
        ·
        edit-2
        2 months ago

        Why not just use the C ABI?

        And what libraries are you referring to? Almost all the ones I’ve used have fantastic docs.

    • Kacarott@aussie.zone
      link
      fedilink
      arrow-up
      17
      arrow-down
      1
      ·
      2 months ago

      Rust is definitely a really cool language (as someone who has played with it just a little) but it’s quite headache inducing, at least for me at the moment.

        • Kacarott@aussie.zone
          link
          fedilink
          arrow-up
          2
          ·
          2 months ago

          Mostly the ownership model, trying to remember which functions expect borrowed types or not, etc.

          The error messages in rust are really good, so I can usually make the code work quickly, but I need to properly understand the reason behind the error in order to learn, so that’s when I get headaches

  • it_depends_man@lemmy.world
    link
    fedilink
    Deutsch
    arrow-up
    27
    arrow-down
    4
    ·
    2 months ago

    To address this concern, CISA recommends that developers transition to memory-safe programming languages such as Rust, Java, C#, Go, Python, and Swift.

    If only it were that easy to snap your fingers and magically transform your code base from C to Rust.

    guy_butterfly_meme.jpg is this unbiased journalism?

    • Successful_Try543@feddit.org
      link
      fedilink
      arrow-up
      17
      arrow-down
      4
      ·
      edit-2
      2 months ago

      As the article is denoted as a comment, it is not its aim to be unbiased journalism.

      In contrast to usual articles, comments usually elaborate on the opinion of the jounalist.

        • Successful_Try543@discuss.tchncs.de
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          2 months ago

          My mind was making one transfer to much, as the opinion clip in German TV news is called comment. There were no additional downvotes after I added the second sentence for clarification.

    • MajorasMaskForever@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 months ago

      As someone who learned Ada for a defense job years ago, I’ve been wondering how long it was going to take until I saw others comparing Rust to it, both in the sense of the language “safety” goals and the USG pushing for it.

      While the rust compiler is leagues better than any Ada compiler I ever had the misfortune of dealing with, the day to day pain that Rust incurs will probably always be a thorn in it’s side

  • rational_lib@lemmy.world
    link
    fedilink
    arrow-up
    7
    ·
    2 months ago

    Imagine if there was a hack so bad that it caused everyone to become unable to develop in C and C++.

    Classic “let’s just make the cure worse than the disease” mindset among security enthusiasts.

    • ulterno@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      2 months ago

      Imagine if there was a hack so bad that it caused everyone to become unable to develop in C and C++.

      Well, there is one that will imply you can only develop using anything that you have bootstrapped yourself, using hardware that you have designed and manufactured yourself, using tools that you have designed and manufactured yourself, using tools that you have designed and manufactured yourself …

      … with your own bare hands.