C++ still rules the Chromium roost though Rust has caught our eye, say browser devs
- Reference: 1597867284
- News link: https://www.theregister.co.uk/2020/08/19/c_plus_plus_chromium_rust/
- Source link:
Rust is an open-source systems-oriented programming language championed by Mozilla that's known for its memory safety, a characteristic of particular interest to developers interested in browser security.
The Chromium team makes clear that C++ is "the ruler" and that its current interest is having Rust code make calls into existing C++ rather than the other way around. But its recognition of Rust as a subordinate language suggests that Google devs want Rust to play a more prominent role in the Chromium court.
"Chrome engineers are experimenting with Rust," the techies declared in [1]documentation this month about Rust and C++ interoperability. "For the foreseeable future, C++ is the reigning monarch in our codebase, and any use of Rust will need to fit in with C++ — not the other way around. This seems to present some C++/Rust interoperability challenges which nobody else has faced."
The page describes how Rust and C++ code should exchange data, which isn't so straightforward due to differences between the languages. The Chromium team's approach relies on a library published in January called [2]cxx , created by Rust developer David Tolnay, which automatically creates bridges between C++ and Rust functions. You can do this by hand if you wish, though once you start juggling more than a few APIs – and Chromium has 1,700-plus – you should use a tool to avoid mistakes.
Robust Rust trust discussed after Moz cuts leave folks nonplussed: Foundation mulled for coding language [3]READ MORE
The Rust compiler [4]catches during compile-time, among other things, potential memory access errors and refuses to build software that is hazardous, so that these bugs do not manifest nor are exploited during run-time. It is, for instance, rather strict on the use and passing of pointers. The C++ code a Rust function interacts with doesn't come with the same level of guarantee. The role of cxx will be to help the two languages interoperate and exchange information in a well-defined and [5]safe way.
Google engineers have been exploring Rust for years, but without any official endorsement of the language. Rust received a mention on the Chromium Project's [6]page about memory safety when it was first published back in May, but the page lacked the link to the project's "Rust and C++ interoperability" post that appeared [7]over the weekend . And Rust shows up before that in various posts to the Gerrit source code collaboration system used by the Chromium project.
Apple's Swift programming language is [8]also being explored as a way to create fewer unsafe memory bugs, though apparently not to the extent seen for Rust.
Google's Fuchsia project has been more public in its affinity for Rust, declaring in March that the programming language "is [9]approved for use throughout the Fuchsia Platform Source Tree," except in the Zircon kernel. The Linux kernel project is also [10]embracing Rust.
Google did not respond to a request for comment.
Rust, which earlier this year marked five years since its 1.0 release, has become something of a darling among programmers. It keeps winning popularity polls and continues to get favorable mentions from large companies looking to write more secure software without sacrificing rum-time speed.
On Tuesday, the Rust Project let it be known that [11]a foundation will be formed by the end of the year to take over management of the language, a move to signal that Rust will be under stable, neutral management whatever happens at cash-strapped Mozilla.
"For now, Chrome investment in Rust will remain a background investigation (mostly directed towards prototyping these tools and techniques)," the Chromium team post says. "If we become convinced this sort of interoperability is possible, we’ll revisit widespread use of Rust in Chrome, and at that point we plan to work hard to achieve this with robust production-quality solutions." ®
Get our [12]Tech Resources
[1] https://www.chromium.org/Home/chromium-security/memory-safety/rust-and-c-interoperability
[2] https://github.com/dtolnay/cxx
[3] https://www.theregister.com/2020/08/18/rust_new_foundation/
[4] http://cs242.stanford.edu/f18/lectures/05-1-rust-memory-safety.html
[5] https://github.com/dtolnay/cxx#safety
[6] https://www.chromium.org/Home/chromium-security/memory-safety
[7] https://www.google.com/search?q=inurl%3Ahttps%3A%2F%2Fwww.chromium.org%2FHome%2Fchromium-security%2Fmemory-safety%2Frust-and-c-interoperability&rlz=1C5CHFA_enUS816US816&oq=inurl%3Ahttps%3A%2F%2Fwww.chromium.org%2FHome%2Fchromium-security%2Fmemory-safety%2Frust-and-c-interoperability&aqs=chrome.0.69i59l2j69i58.20176j0j7&sourceid=chrome&ie=UTF-8&as_qdr=y15
[8] https://chromium-review.googlesource.com/c/chromium/src/+/1904747
[9] https://fuchsia.googlesource.com/fuchsia/+/refs/heads/master/docs/contribute/governance/policy/programming_languages.md
[10] https://www.theregister.com/2020/07/13/rust_code_in_linux_kernel/
[11] https://www.theregister.com/2020/08/18/rust_new_foundation/
[12] https://whitepapers.theregister.com/
Swift is a good choice. It runs so slowly, crashes never get around to happening.
Kinda sad.
On one hand it always saddens me to see more projects use Rust as it means that I won't be able to contribute to them as I won't learn that language.
On the other hand I also do not get why Rust is hyped. Not that I'm a big C++ fan, I'm more of an Ada kind of person, which is exactly why I don't get why Rust is supposed to be 'better'.
Rust doesn't have super strong typing of Ada, it follows by default more the dynamic typing of Python, its syntax is symbol-based and thus offers a severe learning curve over languages that use plain English (like Ada), it doesn't offer contract-based programming, access types for heap memory and on top of all that it doesn't follow a single one of the Steelman requirements, in particular the restricting of how many ways one can write the same code.
C++ is 'safe' enough that it has been certified by the DoD to be used to program the avionics of the F-35 jet. As someone who has plenty of professional experience in C and C++ as well, I can see how modern C++ (i.e. C++11 with standardised memory model) can totally work in safety-first applications. It's mostly about pushing the C baggage to the side, instead using the bits of C++ that do not allow you to easily shoot yourself in the foot.
Yet neither C, nor C++ nor Rust do much to prevent the most common kind of error that makes stuff catch fire in production: logic errors and faulty assumptions. Those incidentally happen to be the reasons why Ada requires explicit termination of blocks with a named end statement, why contract-based programming is part of the core language since Ada 2012 and why nothing is done implicitly. The compiler will bludgeon you over the head with 'are you really sure?' errors until you have addressed every single point.
So yeah, unless an open source project happens to be written in C, C++ or Ada, it might as well be closed source to me. And that makes me somewhat sad.
Re: Kinda sad.
"Rust doesn't have super strong typing of Ada, it follows by default more the dynamic typing of Python" that is quite simply totally and utterly wrong. It allows types to be inferred, but every variable has a well-defined type at compile time, which is extended to include lifetime analysis to ensure variables are not used beyond the point their value is valid. It's one of the strongest type systems I've seen. It is immensely more safe than C++. The compiler is extremely strict.
Re: Kinda sad.
"logic errors and faulty assumptions"
FWIW Rust is strict on trying to stop common errors. For example, Rust's equivalent of a switch-case block (called match) does not allow you to fall through it. You must match one of the arms, and this is checked at compile time. You can put a catch all in ( _ ) but you must explicitly set it up with a handler.
I skipped C++ and went from C to Rust and the thought of writing C now scares me. I've been meaning to do a 'Rust for C/C++ programmers' article for ages now.
C.
Re: Kinda sad.
> Rust's equivalent of a switch-case block (called match) does not allow you to fall through it.
switch statement fallthrough in C/C++ is not an error, unless the programmer didn't intend it in the first place, but let it happen by mistake. So, I wouldn't count disallowing switch statement fallthrough as a feature.
Please allow me to introduce you to [1]Duff's Device , which is a way of doing loop unrolling in C/C++ -- for loops with a known compile-time trip count -- based entirely on switch statement fallthrough.
Also, -Wimplicit-fallthrough both in GCC and clang.
[1] https://en.wikipedia.org/wiki/Duff%27s_device
Why Rust is hyped
> On the other hand I also do not get why Rust is hyped.
Because (a) Mozilla has been pushing it - it's their brainchild so why not inflict it on everyone else - and because (b) Microsoft discovered a convenient scapegoat - well two scapegoats actually - to blame for the piss-poor quality of their products: C and C++. See, it wasn't Microsoft's fault that their stuff crashes, is under-tested (if at all), is inherently insecure, b0rked, bloated and dumb. It was the programming language's fault all along. At least according to Microsoft.
> C++ is 'safe' enough that it has been certified by the DoD to be used to program the avionics of the F-35 jet.
That means very little to (a) someone who can't be bothered to learn how pointers or computers work or (b) someone who spends most of their time copying and pasting Python code fragments from StackOverflow. Now they'll have two languages to copy and paste from StackOverflow.
The interop is always an issue. It is in fact what gives rise to all these dependency "solutions" such as NPM, PIP, CPAN, crates.io and other language based package managers. These rack up a technical debt that makes future maintenance a mess. Bindings suck to make and suck to maintain.
The only way this can be truly solved is by adding a basic C compiler to the new language. Not because C is the nicest language to use but because it gives you access to APIs that the real world uses. For example, do you think C++ would have ever become a success if it couldn't consume C libraries?
I love Rust but I hate dependencies so C++ is still the only solution for me for now :/