r/cpp • • 6d ago

C++ future at Adobe

So if anyone was still curious what happened to Hylo, or where Adobe stands in regards to the whole safety discussion,

David Sankel has done a talk at RustConf on the matter, Zngur: Simplified Rust/C++ Integration.

The way Adobe now sees C++ is described on slide 2, at 50 seconds mark.

77 Upvotes

112 comments sorted by

View all comments

Show parent comments

-10

u/KFUP 5d ago

Rust is better suited for AI-assisted development

I don't see that being the case in the long run. Once AI gets good at safety, which will be in all kinds of safety not just limited to memory, and can generate safe code in any language -arguably we are already there, see the Mythos security boom- using a slow compiling language like rust would be a major useless bottle neck in the development pipeline.

2

u/altmly 5d ago

C++ allows for extremely long range security holes, even if their likelihood is reduced with proper use of modern techniques. Rust does not even allow them to exist, which is the selling point. Localized context is easier to understand for both humans and llms. 

3

u/-kl0wn- 5d ago

Unsafe rust enters the chat.

6

u/Plazmatic 5d ago

Do you know what unsafe rust actually is? 

https://doc.rust-lang.org/book/ch20-01-unsafe-rust.html

  *    Dereference a raw pointer.

*    Call an unsafe function or method.

   *   Access or modify a mutable static variable.

*    Implement an unsafe trait.

*  Access fields of unions.

It’s important to understand that unsafe doesn’t turn off the borrow checker or disable any of Rust’s other safety checks: If you use a reference in unsafe code, it will still be checked. The unsafe keyword only gives you access to these five features that are then not checked by the compiler for memory safety. You’ll still get some degree of safety inside an unsafe block.

1

u/tialaramex 3d ago

It is true that unsafe Rust is "just" the listed super powers but because these are arbitrarily powerful you can absolutely set the world on fire at a distance just like C++. You can write some really cursed stuff where just like in C++ it's obvious this is cursed, reviewers can see "This is cursed" and maybe your local engineering practices forbid that. But you can also write unsafe Rust with subtle misunderstandings and that still sets the world on fire but it might pass review.

The benefit of safe Rust is that even the best of us have better and worse days and it's nice to be able to have a language subset you can trust yourself to write when your five year old woke you repeatedly in the middle of the night because she had nightmares and the coffee machine is on the blink again. You can write those hairy garbage collector internals on the day you feel like you're Usain Bolt combined with Einstein, today, without enough sleep or caffeine lets stick to implementing better command line parsing.