Ubuntu's 'Rust-ification' Hits New Milestone: Coreutils Migration is Complete (itsfoss.com)
- Reference: 0185663658
- News link: https://news.slashdot.org/story/26/09/15/2115242/ubuntus-rust-ification-hits-new-milestone-coreutils-migration-is-complete
- Source link: https://itsfoss.com/news/ubuntu-rustification-coreutils-migration/
The last three utilities — cp , mv and rm — have been moved to versions from the uutils project (which reimplements utilities in Rust).
> Everything else, from ls and cat to chmod and du , made that jump in earlier releases... Canonical [2]started "oxidizing" Ubuntu last year , and Ubuntu 25.10 became the first release to ship
the uutils project's] coreutils as the default. That release also made [3] sudo-rs the default privilege tool, replacing a command that had been in place for decades.
>
> 26.04 was the release where the plan did slow down quite a bit, as Canonical kept cp , mv , and rm on their GNU versions due to a bunch of [4]TOCTOU issues that were blocking the full implementation. These were caught during an audit, when Canonical commissioned Zellic [5]for two rounds between December 2025 and March 2026, focusing on the most security-sensitive utilities first. Across both rounds, Zellic raised 113 issues, and 44 of them were assigned CVEs. Canonical says the vast majority have been resolved.
>
> Getting here has had its ups and downs, and the last stretch was not clean. In July, uutils cp went [6]back into the archive and came straight out again after it broke live image builds. The fix was quick; as the developers marked it "Critical," the fix went upstream, and the migration landed in time for 26.10.
>
> When typing commands, nothing changes for you on the surface. uutils coreutils is designed to be a drop-in replacement for essential GNU tools, and the project treats any divergence from GNU as a bug, further pointing out that some options may still be missing or behave differently. So if you prefer staying on the GNU version, you have the option to install the coreutils-from-gnu [7]package that houses all the required components.
[1] https://itsfoss.com/news/ubuntu-rustification-coreutils-migration/
[2] https://discourse.ubuntu.com/t/carefully-but-purposefully-oxidising-ubuntu/56995
[3] https://itsfoss.com/sudo-vs-sudo-rs/
[4] https://en.wikipedia.org/wiki/Time-of-check_to_time-of-use
[5] https://discourse.ubuntu.com/t/an-update-on-rust-coreutils/80773
[6] https://bugs.launchpad.net/ubuntu/+source/coreutils-from/+bug/2158691
[7] https://packages.ubuntu.com/stonking/coreutils-from-gnu
Different license (Score:5, Informative)
The Rust version is licensed under the MIT license, in case anyone was wondering. The Ubuntu Discourse post says the change is not about licensing, but about security. What it does not provide is any kind of statistic on security issues related to coreutils.
Re:Different license (Score:5, Funny)
Yeah this project has nothing to do with security... it's just the Ubuntu developers are REALLY REALLY tired of hearing the FSF folks say "it's GNU Linux" every time they turn around.
Re: (Score:3)
> Yeah this project has nothing to do with security... it's just the Ubuntu developers are REALLY REALLY tired of hearing the FSF folks say "it's GNU Linux" every time they turn around.
Not sure if I should mod that insightful or funny so I'll leave it to others to decide. Seems a little of both.
Ok, but⦠(Score:4, Funny)
Not in any way trying to diminish work developers put into this effort, but with all due respect, how difficult can it be to re-write utilities such as cp, mv and rm?
Re: Ok, but⦠(Score:4, Interesting)
From what little experience I have with rust, the ideology of the language is rather different from c, so while the full set of use cases across all those supported OSes is largely analogous, the implementation has little potential for copypasta, especially where those subtle differences exist.
Re:Ok, but (Score:2)
There's versions available in every language, as far as I can tell...
Re:Ok, but⦠(Score:4, Insightful)
Literally every one of the coreutils tools have some odd edge cases - some that make sense, some that do not. But at some point that behavior is something that callers expect, and when a replacement does not behave that way... You know the rest. "#define bad" etc.
Re: Ok, but⦠(Score:2)
One thing I noticed about modern Linux is if you "cat > file" and then press CTRL-C it overwrites with a blank file. It's not supposed to do that. It's not supposed to create a file at that point and it's supposed to leave the file untouched if it already existed. It's actually a little worrisome that such basic things are wrong.
Re: Ok, but⦠(Score:2)
What exactly is wrong with that?
Re: Ok, but⦠(Score:2)
Because now you are fighting a language that is trying to prevent you from making mistakes and not getting any benefit out of it and you are reinventing the wheel for little reason. Furthermore you are limiting yourself in terms of the ecosystem. You can't use anything really powerful like Qt because then you are just admitting that C++ is better in the first place.
Re: (Score:2)
It's worth noting that busybox replicates many of them, and it has its own oddities.
Re: (Score:2)
Busybox, Toybox and others. The vast majority of docker images running in the wild probably aren't even using coreutils because their aim is small containers with minimalist userland with some even going distroless. They don't even use glibc, using something like musl instead.
I think for a general purpose Linux dist you'd definitely need coreutils or a drop-in replacement. I think coreutils has a lot of very esoteric features, which uutils have copied so even so, there is merit in examining these and depr
Re:Ok, but (Score:2)
It's one git clone and a couple of Claude prompts. What could it cost? 10M tokens?
Re: (Score:3)
Considerably more difficult than you imagine. Between them, they have almost 70 command-line options or flags. Taking into account that many of those behave differently depending on the presence or absence of other flags, there's a couple hundred different code paths. Then you need to handle directories, files, sparse files, sym- and hard-links, on and across different filesystems, not to mention the various file-like things scattered around (pipes, streams, etc.)
It's not rocket science, but neither is it t
Nothing of value was added (Score:1)
They might as well have rewritten SystemD in Rust and made again zero impact.
Re: Nothing of value was added (Score:5, Insightful)
They made impact alright. The big difference is loads of new security issues and loads of incompatibility with edge case usage. It is such a big set-back that it would be unwise to even keep using Ubuntu at this point.
Re: Nothing of value was added (Score:5, Insightful)
Which is in no way surprising. Re-implementing well-working, _old_ tools is just dumb.
Re: Nothing of value was added (Score:3, Interesting)
Famous last words. "Proven because it is old" is a much weaker argument than "Proven because the compiler validates every individual unit." Period. Not to mention, we keep seeing this argument fall apart, especially when the "old code" egos prevail even when they obviously shouldn't have.
[1]https://openprinting.github.io... [github.io]
Common sense should tell you that old code is not proven simply because nobody has exploited it. But here you are, making that argument. You have implementations confused with specifications
[1] https://openprinting.github.io/OpenPrinting-News-Flash-cups-browsed-Remote-Code-Execution-vulnerability
Re: (Score:3)
Did you overlook that the Rust implementation for some of these was subject to a TOUTOC vulnerability that the Rust compiler did not catch and that the GNU versions did not have? Your "Period." sounds pretty dumb now, doesn't it? Especially because that problem got referenced in the story...
Rust is not magic. Stop believing it is. You may also want to think about what "well working" could mean in the context of this story.
Re: Nothing of value was added (Score:5, Interesting)
I think Ubuntu (and other's desire) to remove coreutils is precisely because coreutils is old, brittle and written in an unsafe language. So they've chosen to modernize the code base, attract new developers while still maintaining strict compatibility. And since uutils is MIT instead of GPLv3, and far more portable between operating systems it may encourage adoption elsewhere, e.g. Microsoft already have build for example.
That said, rewriting code always carries risk and uutils has its own set of bugs which have been uncovered and need fixing. There is a "if it isn't broke don't fix it" mantra but I suppose it depends on the definition of broke - if development is moribund then that could be considered an issue too.
It's worth noting that coreutils have derived benefit from the exercise too. The extensive test suite for uutils has uncovered bugs in coreutils and improved the overall code coverage. So even if people don't want to switch (even though they're functionally interchangeable), the existing package has derived benefit too.
Re: Nothing of value was added (Score:2)
If your developers are so bad that they can't write safe code, from what I see from the outside Rust isn't going up be enough to save them. They are free to make their code "unsafe" from one end to the other and do what they always did.
Re: (Score:3)
History shows that developers cannot write safe code. Especially when there is a lot of code, developed over a long time with many people working on it. Rust at least offers to provide memory safety, which is a huge win, but not safety from all manner of other logical errors.
Of course if you have a lot of "unsafe" blocks in your Rust code because you are trying to make it do what C did in the same way C did it then you are not gaining anything much. I would not like to see that released until the "unsafe" h
Re: (Score:2)
If you think Rust provides "Proven because the compiler validates every individual unit." you are seriously uninformed about what Rust's memory safety guarantees are, what they are safe against and what they are not safe against.
Rust prevents sill memory use errors, like out of bounds array access, use of after free, dereferencing null or invalid pointers etc, etc. It also provides a great type checking system.
Of course catching such silly mistakes in a huge thing, a great benefit and will of course prevent
Re: (Score:1)
OpenBSD folk re-implemented Openssl as Libressl because its codebase sucked.
Apple chose Zsh over Bash because licensing.
Mysql was forked as Mariadb.. for no good reason it seems, seeing as Oracle didn't break anything in the 15 years since.
Libreoffice was forked from Openoffice because its maintainers sucked.
None of those decisions looks dumb to me.
So dumb that coreutils did it (Score:2)
Try running a Loki Games installer and watch it fall over because head and tail are no longer compatible with themselves without using random, obscure environment variables to try and restore the original default behaviour. That is just the tip of the iceberg for backwards incompatible changes internal to "old" utilities which do in fact still receive regular changes.
My only complaint with Canonical's approach was pushing half and half into an Ubuntu LTS, which was clearly a terrible idea to anyone watch
Re: Nothing of value was added (Score:2)
If you could, you'd be using Debian and not its rusted version.
Re: (Score:3)
People who use commercial software on Linux are often on Ubuntu because it's what corps choose as the only thing "supported."
It may even be the majority of the user base.
Re: (Score:2)
The coreutils are surprisingly complex. If you know a little about kernel functions, it feels like any of those tools should basically map to just a single kernel call. The requirements of the POSIX-standard(s) that define how exactly the tools should work, including how they should handle and report errors, as well as limitations of filesystems (such as long filenames, unsupported characters, ACLs) make correct implementations quite a chore. I'm wondering if the rust implementations pass the test suite th
Re: (Score:2)
"loads of new security issues and loads of incompatibility with edge case usage."
That is measurable, so it will be easy to see if what you say is true or not, and therefore whether this should be repeated for other code.
Re: (Score:1)
The first thing I do on installing newer Ubuntu releases:
apt-get remove coreutils-from-uutils --allow-remove-essential
(and similarly revert to the original sudo version)