what's missing from newer C? [was: [PATCH v5 0/9] Introduce Rust ....]
- From
- Eric Wong <e@80x24.org>
- Date
- Sep 25, 2025, 01:10 UTC
- Message-ID
- <20250925011043.M401827@dcvr>
- In-Reply-To
- <20250915-b4-pks-rust-breaking-change-v5-0-dc3a32fbb216@pks.im>
Patrick Steinhardt <ps@pks.im> wrote:
> this small patch series introduces Rust into the core of Git. This patch > series is designed as a test balloon, similar to how we introduced test > balloons for C99 features in the past. The goal is threefold:
Show 6 quoted lines
> - Give distributors time to ease into the new toolchain requirements. > Introducing Rust is impossible for some platforms and hard for > others. > > - Announce that Git 3.0 will make Rust a mandatory part of our build > infrastructure.
Newer (and perhaps experimental) C has some safety and ergonomic features which Rust advocates might be overlooking:
1. C23 has stdckdint.h for checked arithmetic to prevent overflows
2. __counted_by__ attribute in clang 18 and gcc 15 for guarding against buffer overflows: https://people.kernel.org/gustavoars/how-to-use-the-new-counted_by-attribute-in-c-and-linux It's easy to fall back to disabling it for unsupported compilers.
3. __cleanup__ attribute is supported by TinyCC, gcc, and clang for many years (even decades), now. Auto cleanup makes managing locks for parallelism much easier along with normal resource management ergonomic improvement. __cleanup__ should be trivial for other compiler maintainers to add (even TinyCC supports it)
4. Userspace RCU provides concurrent data structures even w/o RCU (and AFAIK ConcurrencyKit, too, but I've never used CK)
5. compilers check format strings nowadays (but I dislike format strings for performance reasons unless using qrintf)
6. regexps (POSIX ERE or PCRE2) are already used by git and can be used more extensively to make safer parsers. There's also things like wuffs and re2c to generate C (I've yet to try either).
We also have Valgrind, ASAN, TSAN, etc...
__cleanup__ and __counted_by__ are the biggest deals to me and I hope they'll be standardized soon. The rest of the other stuff is pretty well-known at this point...
What else is missing from C?
FWIW, I detest hacking in verbose AOT languages in general and don't write a lot of C as a result. However, I've spent a large part of this century fixing C code written by others for the usual memory leaks, memory errors, races, overflows, etc.
I'm not particularly a fan of the C code in git for a variety of reasons but have sought to improve it here and there (container_of, list.h, etc.)
Building git nowadays is painful for me due to the (lack of) speed from lld/gold/mold on my ancient hardware. Rust's famously slow compilation speeds would mean only developers willing to work for and/or promote $MEGACORP interests would be able to afford to hack on code.
Thanks for reading.