News: 1656012613

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Linus Torvalds says Rust is coming to the Linux kernel 'real soon now'

(2022/06/23)


At The Linux Foundation's Open Source Summit in Austin, Texas on Tuesday, Linus Torvalds said he expects support for Rust code in the Linux kernel to be merged soon, possibly with the next release, 5.20.

At least since last December, when [1]a patch added support for Rust as a second language for kernel code, the Linux community has been anticipating this transition, in the hope it leads to greater stability and security.

In a conversation with Dirk Hohndel, chief open source officer at Cardano, Torvalds said the patches to integrate Rust have not yet been merged because there's far more caution among Linux kernel maintainers than there was 30 years ago.

[2]

"A lot of people actually think we're somewhat too risk averse," said Torvalds. "So when it comes to Rust, it's been discussed for multiple years by now. It's getting to the point where real soon now, we will actually have it merged in the kernel. Maybe next release."

[3]

[4]

Torvalds however did his best to dampen enthusiasm expressed by the applauding audience.

"Before the Rust people get all excited," the Linux kernel creator and chief said. "Right? You know who you are. To me, it's a trial run, right? We want to have [Rust's] memory safety. So there are real technical reasons why Rust is a good idea in the kernel.

[5]

"But at the same time, it's one of those things: We tried C++ 25-plus years ago and we tried it for two weeks and then we stopped trying it. So to me, Rust is a way to try something new. And hopefully, it works out, and people have been working on it a lot, so I really hope it works out because otherwise they'll be bummed."

Keep in mind that Torvalds in April, 2021 suggested Rust [6]might get merged into Linux kernel 5.14. The current stable release is [7]5.18.6 , with 5.19-rc waiting in the wings.

[8]Rusty Linux kernel draws closer with new patch adding support for Rust as second language

[9]Latest patches show Rust for Linux project making great strides towards the kernel

[10]Linus Torvalds launches Linux kernel 5.13 after seven release candidates

[11]Huawei dev flamed for 'useless' Linux kernel code contributions

Analysis firm SlashData last month published [12]a report stating that the Rust development community has almost tripled over the past two years, from just 0.6 million developers in Q1 2020 to 2.2 million in Q1 2022. For the seventh straight year, Rust was voted the most loved programming language in the annual [13]StackOverflow Survey .

Hohndel asked Torvalds whether the introduction of Rust code will make the maintenance of Linux code harder due to the introduction of a language and patterns that are less familiar.

Torvalds said he doesn't see that as a significant issue, and said there have been other languages in the kernel, such as those used in the build subsystem.

[14]

"I'm quite used to seeing Perl code or our make files," Torvalds said. "Our makefiles are makefiles in name only. They are an unholy mess of various macros and other helper functions that are really hard to understand. And I'm in the situation where if somebody sends me a patch with some of the scripting and the makefiles, I don't even pretend to understand Perl. I'm one of those people who think that Perl is a write-only language."

[15]

Linus Torvalds, left, with Dirk Hohndel on stage at the Open Source Summit this week

Torvalds said he's perfectly happy to trust maintainers, at least until they screw up.

"Then I sometimes am overly impolite," he said. "And if I've been impolite to any of you in the audience, I apologize. It's a personal failing of mine and I mean that, very seriously."

If I've been impolite to any of you in the audience, I apologize. It's a personal failing of mine and I mean that, very seriously

"In a loving way," Hohndel interjected, in an effort to ameliorate his guest's confession.

"No," Torvalds responded, eliciting laughter from the audience. "I wish I could say that. I have had to apologize multiple times. So let me preemptively apologize to the Rust people."

Torvalds said he is aware people are concerned that not everyone involved will understand Rust and he's fine with that.

"People don't understand the VM subsystem, even when it's written in C," he said. "So the language is usually not the biggest hindrance to understanding." ®

Get our [16]Tech Resources



[1] https://www.theregister.com/2021/12/07/rusty_linux_kernel_draws_closer/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrTigNOGAK@59Il-NlQluwAAABY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrTigNOGAK@59Il-NlQluwAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrTigNOGAK@59Il-NlQluwAAABY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrTigNOGAK@59Il-NlQluwAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/07/05/rust_for_linux_kernel_project/

[7] https://www.kernel.org/

[8] https://www.theregister.com/2021/12/07/rusty_linux_kernel_draws_closer/

[9] https://www.theregister.com/2021/07/05/rust_for_linux_kernel_project/

[10] https://www.theregister.com/2021/06/27/linux_kernel_5_13_official_release/

[11] https://www.theregister.com/2021/06/26/linux_kernel_contributor_from_huawei/

[12] https://www.slashdata.co/free-resources/state-of-the-developer-nation-22nd-edition

[13] https://survey.stackoverflow.co/2022/#technology

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrTigNOGAK@59Il-NlQluwAAABY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://regmedia.co.uk/2022/06/23/linus_at_oss_2022_2.jpg

[16] https://whitepapers.theregister.com/



Sounds good to me

Henry Wertz 1

Sounds good to me.

Rust will be unfamiliar and something new to learn to many, but it's more like C than like, say, Python, Java, or C# etc. I found it relatively similar to a very pedantic dialect of C -- that's both the weakness and the strength of it.

Weakness -- I found it hard to use. It's very pedantic and requires some things to be explicitly stated that are not even required in C let alone some "higher-level" languages. There were some hoops to jump through to get things done that are easier in both plain C and in other languages.

Strengths -- those hoops and pedanticness I was talking about? These allow the compiler to PROVE the code is safe from many problems (you cannot have buffer overflows, memory leaks, if you're using threaded code it proves you're access to any shared data structures is thread-safe, among others). It's not imposing overhead to do garbage collection, check buffer lengths, run some expensive mutual exclusion system at runtime, the very pedanticness I was saying is a weakness is a strength here in that these properties can be proved at compile-time. Similar to C# in one aspect, Rust does have a way to flag "unsafe" calls etc., so you can interface with code written in conventional languages.

So -- the strengths mentioned are obviously good things for kernel code, keep the kernel bugs down to actual logic errors and avoid the unsafe buffer use, memory leaks, and unsafe thread behaviors. The weaknesses I mention are not significant weaknesses for kernel code, there's already a lot of restrictions on what can and should be done for drivers and so on written in C anyway, documented in both the kernel docs for writing drivers and so on, and embodied in the sample drivers included for most Linux subsystems. Rust will simply take advantage of these restrictions to perform some static code analysis ahead of time.

Re: Sounds good to me

bazza

I firmly agree.

I'm also relieved. I think that, long term, Rust is the way OS kernels will go, because of the pedantic compiler / memory safety / etc. The "proof" starts becoming a reason to use the OS, if one is security minded. If Windows / MacOS / FreeBSD all went towards Rust, and Linux didn't (or at least, didn't give it a go), Linux might in the long run have become a liability.

Seriously, are programmers that bad?

martinusher

I had a look at "memory safe" Rust and found the C problems it manages are the sort of problems that an experienced C programmer will never make. (OK, "never" is a big word, we all make mistakes but but...) The reason is straightforward -- writing any kind of C level code is a highly disciplined activity where the programmer has to keep in mind exactly where everything is and what its doing at all times. Its true that if you're writing a complete piece of software in C, say and embedded application -- then higher level code will still be written in C but at that point the C programmer will avoid mixing 'high' and 'low' level functions because it breaks the overall structure of the program. Still, if Rust can do the job of "higher level low level code" then why not?

I can't quite see what the problem that Linus has with Perl. Perl is a powerful language but ultimately "its just another language". It excels at file manipulation which is why you might come across it orchestrating complex builds (I've used it for this purpose). I'm not an expert, a "Perl Monk", so this might have saved both me and the code since Perl has a great many shortcuts that allow people to write extremely terse and so essentially unreadable programs. You don't have to do this, though -- you can write a fairly normal looking piece of software and if you add appropriate comments where the syntax might be a bit arcane (pattern matching and search within files, for example) then others shouldn't have a problem with it. Like with C you've got to be disciplined and above all resist the temptation to show off -- unless collecting millstones is your thing you need to be able to pass your magnum oerve onto someone else.

Re: Seriously, are programmers that bad?

elsergiovolador

There is no money for workers doing this kind of job. So as the rewards are low, it does not attract talent that could score more doing something else.

Big corporations especially want to use free things - including labour. If you look at CEOs or shareholders, their biggest contribution are their contacts and money (likely from wealthy parents), not actual meaningful work.

In their interest is to keep engineering wages low, so that the influx of newcomers into "their" world is as low as possible and only those "accepted" can enter it.

So yeah, with things like "co-pilot" and "safe" languages the agenda is to make anyone being able to "code" - ideally accepting or rejecting the code proposed by the AI and get paid minimum wage (with benefits paid for by engineers caught by higher tax rates - again part of multi-faceted effort to ensure a worker will always be a worker and can't climb the class ladder).

Re: Seriously, are programmers that bad?

Gene Cash

experienced C programmer

You got some of them? We could use one or two. We won't pay them what they're worth, of course.

The people we've got can't remember the order of arguments to strcpy.

you can write a fairly normal looking piece of software [in perl]

Yeah, and I hope some day to see some. All the perl I've had to deal with has been 1200baud-modem-line-noise. I don't even attempt to understand it, I just rewrite it in something sane. I've yet to see any perl with comments.

What I tell you three times is true.
-- Lewis Carroll