Bugs Rust Won't Catch | corrode Rust Consulting - Analysis of Rust Coreutils (uutils) Bugs

https://corrode.dev/blog/bugs-rust-wont-catch/

I’m not writing this to criticize the uutils team. Quite the contrary; I actually want to thank them for sharing the audit results in such detail so that we can all learn from them.

53 points · 6 comments · view on lemmy.world

6 Comments

trevor@lemmy.blahaj.zone · 17 pts · 123d

This is an excellent article that breaks down common pitfalls and provides really concise rules for avoiding them. It's a great read if you're in to systems programming.

stoicEuropean@lemmy.ml · 9 pts · 123d

As someone who is not at all into programming, this title made me genuinely think I had a stroke.

onlinepersona@programming.dev · 7 pts · 123d (2 replies)

Those are bugs I dont think any programming language catch, unless it's a DSL for writing such programs on Linux or another OS.

novafunc@discuss.tchncs.de · 4 pts · 123d

It could be improved. Sebastian Wick and Lennart Poettering made comments on how hard POSIX makes it hard to be secure. There are better APIs that try to be safer.

And since uutils is not Linux only, it can't use these safer APIs directly, or at least not without writing more platform-specific code.

atzanteol@sh.itjust.works · 2 pts · 123d

Some of them seem to be harder to fix or to get right in Rust than C though. Mostly due to "convenience" methods that make application writing easier.

doodoo_wizard@lemmy.ml · 5 pts · 122d

Another stupendous reason to gpl uutils so that the decades of experence of hundreds of system programmers can be leveraged in the rewrite.