• iopq@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    2 days ago

    Nobody is arguing C is complex. The argument is that it’s not the optimal syntax.

    For example, case statements needing breaks can cause logical issues with incorrect merges.

    How about this

    https://en.wikipedia.org/wiki/Unreachable_code#goto_fail_bug

    The if statement not requiring brackets caused this bug. Rust fixes these issues with pattern matching and mandatory curly braces in if body statements

    • Nalivai@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      Yeah, it’s not optimal, I don’t think anyone argues that it is. It has a bunch of ways to shot yourself in the foot, no questions about that, people were writing books about that for decades. Not like there is an optimal language that doesn’t allow you to make some stupid mistakes.
      But also, a lot of that non-optimality is what gives it advantage. Well, that and enormous amount of legacy code and expertise.
      Sometimes you need to pass around raw pointers without caring about memory ownership, and for that situation it’s optimal. I’m glad you have your mandatory curly brackets, but sometimes I just want my microcontroller to blink an LED and for that I’m in turn glad that I can be as quick and dirty as my filthy mind allows me.
      And for serious projects we’re all MISRA compliant anyway, and it mandates curly brackets for ifs and proper cases for switch.

      • iopq@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        2 days ago

        Let’s not get too abstract. Just because Rust made its own mistakes doesn’t mean it didn’t fix the mistakes I pointed out

        Serious projects have huge memory safety issues that don’t exist in Rust. More than half of security CVEs are due to the nature of C. Rust just has fewer bugs like Heartbleed because it doesn’t let you do a buffer overrun

        • Nalivai@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          2 days ago

          that don’t exist in Rust

          That’s because serious projects basically don’t exist in Rust. Yet, probably, Rust seem to be a good language that people like, so those are to follow, but for now they’re rare.
          Or don’t, if we discover that Rust has some other issue that only happens when the project grows old enough.
          Personally, I’m sticking to the devil I know, the one that has almost 60 years of accumulated knowledge and best practices.

          • iopq@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            1 day ago

            Rustls can already replace OpenSSL, but maybe that’s not serious enough for you. Sure, the ring backend embeds assembly for the crypto operations, but that’s the point:

            You can have a safe interface for interacting with potentially unsafe code. Do all of the memory allocation and string manipulation stuff in Rust and call out to crypto in assembly

            • Nalivai@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              1 day ago

              Yeah, it’s not serious enough for me. It will become serious if it actually replaces openssl, or at least actually is in use by any significant numbers. Until then, it’s a project that can potentially maybe sometimes be used by someone maybe, which by definition isn’t serious. Like any other project, it needs time under pressure, it needs to mature with use, be supported for some time, accept patches and changes, and sustain constant prodding by people who would like to break your stuff.
              OpenSSL is a standard for almost 3 decades, Rustls is cautiously maybe being pushed in experimental branches.
              It’s like that with everything Rust related really. We are at a phase where enthusiasts enthusiastically trying to convince someone to consider their new toy, which means we can’t really compare it with decades old projects that were scrutinized and stress-tested by millions of people.

              • iopq@lemmy.world
                link
                fedilink
                arrow-up
                1
                ·
                21 hours ago

                OpenSSL has proven itself to be security issue riddled, unmaintainable, bloated. It’s only lasted so long because people had the impression it was good, but it has proven itself unreliable

                • Nalivai@lemmy.world
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  6 hours ago

                  Paraphrasing, there are only two types of important projects, security issue riddled, unmaintainable, bloated ones, and those that nobody uses.