git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: what's missing from newer C? [was: [PATCH v5 0/9] Introduce Rust ....]

From
EWEric Wong <e@80x24.org>
Date
Oct 4, 2025, 01:02 UTC
Message-ID
<20251004010201.M85772@dcvr>
In-Reply-To
<CAH=ZcbCEioNGaksTKnYyakABWGwTWv4WQZCnOtARydtLrx11MQ@mail.gmail.com>
Ezekiel Newren <ezekielnewren@gmail.com> wrote:
Show 33 quoted lines
> On Wed, Sep 24, 2025 at 7:10 PM Eric Wong <e@80x24.org> wrote:
> > What else is missing from C?
> 
> 1. Checked Arithmetic
>   * C23: <stdckdint.h> for checked integer operations.
>   * Rust: built-ins like checked_add, wrapping_add.
> 2. __counted_by__ attribute
>   * Clang 18 / GCC 15: experimental, helps catch buffer overflows.
>   * Rust: slices already carry length, preventing out-of-bounds by design.
> 3. __cleanup__ attribute
>   * GCC, Clang, TinyCC: long-standing extension for RAII-like cleanup.
>   * Rust: Drop trait ensures deterministic cleanup.
> 4. RCU / concurrency libraries
>   * Userspace RCU, ConcurrencyKit, etc. available in C.
>   * Rust: crossbeam, Arc, lock-free crates.
> 5. Format string checking
>   * GCC/Clang/MSVC check format strings at compile time.
>   * Rust: format! macros type-check arguments.
> 6. Regex and parsing
>   * C: POSIX regex, PCRE2, re2c, wuffs.
>   * Rust: regex crate (safe, no unchecked buffer access).
> 7. Dynamic analysis
>   * C: Valgrind, ASan, TSan, UBSan, MSan.
>   * Rust: Miri, LLVM sanitizers.
> 
> What else is missing in C?
> 
> Compared to Rust, here's where C still falls short at the language
> level (not just tooling):
> 
> 1. Ownership and lifetimes
>   * No borrow checker; compiler can't prevent use-after-free, double
> free, or aliasing bugs.

As I understand it, the borrow checker is a big part of the slow compile times which makes it impractical for poor (and/or anti-consumerist) folks to contribute. At least Rc/Arc exists but we can also rely on __cleanup__ to do RC in C.

RCU also has GC-like properties for resource management with less overhead than a full-blown GC.

> 2. Async/await coroutines
>   * No language support. Async requires threads, callbacks, or libraries.
>   * Rust: async fn / .await integrated into the language.

As someone who's worked on implementing async/green threads for a VM; I find myself disagreeing with async/green-threads these days because stacks end up eating large amounts of memory in less-than-obvious ways. Memory used by a pure event loop (or event loop combined w/ native threads|processes) is a sunk cost in either design. However, (last I checked,) even Golang ends up growing stacks in giant 2KB increments whereas event systems only need dozens or hundreds of bytes (not KB) per FD.

> 3. Explicit numeric conversions
>   * C silently promotes between ints/floats/signed/unsigned.
>   * Rust requires explicit casts (down and up), reducing surprises.

I think the "new" -Wconversion switch can help <https://gcc.gnu.org/wiki/NewWconversion>, but I haven't tried it. Using C23 ckd_* functions and wrappers can also help, of course.

> 4. Sum types with exhaustiveness checks
>   * C: enum + union is manual, compiler won’t enforce full handling.
>   * Rust: enum + match requires covering all variants.

Not sure what you mean by "full handling" (banning the `default:' label?), but C switch + enums do a pretty good job of warning, already.

I certainly wish enums were more widely used in C projects.
> 5. Safer error handling
>   * C: errno, return codes, ad hoc conventions.
>   * Rust: Result<T, E> + ? operator, forcing handling.

It's down to coding style, yes, but it's not bad. Linux kernel uses __attribute__((__warn_unused_result__)) (aka `__must_check') to force error checking.

> 6. Concurrency safety by design
>   * C11 added atomics, but race conditions are unchecked.
>   * Rust: Send / Sync traits enforce thread-safety at compile time.

I assume you mean "parallelism" safety? (referencing our terminology below). It's never been a big problem to me with RCU and proper understanding of POSIX semantics.

> 7. Namespaces / modules
>   * C: relies on foo_bar() prefixes and headers.
>   * Rust: mod and crate system.

I don't miss namespaces; it seems to be mainly dealing with colons vs underscores. (Side note: underscores tend to be cheaper for Xapian (and presumably other search engines) to deal with :>).

AFAIK, Rust modules + crates are centrally controlled and publishing requires an account on a proprietary service owned and operated by a convicted monopolist. That doesn't fly with some folks such as myself.

> 8. Default immutability
>   * C: everything mutable unless marked const.
>   * Rust: immutable by default, opt into mut. You have a choice of 1
> mutable reference xor many immutable references to something.

Sure mistakes were made ~50 years ago, but const exists and we can enforce that via coding style.

> 9. Package management
>   * C: out of scope for the language
>   * Rust: built in with Cargo dependencies

As a Perl user who has avoided CPAN for ~25 years, I prefer to let distros manage packages and ignore language-specific managers. This seems out-of-scope for this discussion, so more in footnote[1]

Show 7 quoted lines
> In Rust there is a difference between concurrency and parallelism.
> Concurrency in Rust is about running multiple tasks with a single
> system thread. Whereas parallelism is about assigning tasks to
> multiple threads. I highly doubt that C will ever get coroutines
> because it requires the compiler to create a state machine out of each
> function that uses async or await keywords. The C language just isn't
> robust enough for that in my opinion.

Your terminology matches mine even outside of Rust (IOW, "ConcurrencyKit" probably should've been named "ParallelismKit").

There's certainly been attempts at coroutines for C. From what I've seen in headlines, it certainly seems async + function coloring in Rust has its fair share of problems and growing pains. Again, I really don't think async is worth the problems and surprises, especially in a low-level(?) language.

> And there's probably more that I haven't covered here.

Again, I would've been much happier if git used more very high-level language(s) instead of rewriting things to C years ago. Given that ship has long sailed, an evolutionary approach towards improving C would be less exclusionary than a revolutionary one such as Rust.

Rust seems to try to be a replacement for C++ (with even slower build times) rather than a thin layer to interface with the OS + hardware. C++ mixes high-level and low-level concepts too much for my liking (and Rust the same). This is down to personal taste, but I prefer a good distinction between high and low-level languages.

[1] - I strongly prefer to only use distro package managers due
      to multi-language projects, distro-specific quirks, extra
      review, ethics/license checks, etc.  I also strongly prefer
      NOT having a central entity affecting users across all
      distros.
Previous: Ezekiel NewrenNext: Pierre-Emmanuel Patry
Message 160 of 210 in “Introduce Rust and announce that it will become mandatorty”
  1. 0/3 Introduce Rust and announce that it will become mandatortyPatrick Steinhardt, Sep 4, 2025
  2. 1/3 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 4, 2025
  3. Junio C HamanoSep 4, 2025
  4. Patrick SteinhardtSep 5, 2025
  5. brian m. carlsonSep 4, 2025
  6. Junio C HamanoSep 4, 2025
  7. Patrick SteinhardtSep 5, 2025
  8. Eli SchwartzSep 5, 2025
  9. Patrick SteinhardtSep 5, 2025
  10. Eli SchwartzSep 5, 2025
  11. 2/3 rust: implement a test balloon via the "varint" subsystemPatrick Steinhardt, Sep 4, 2025
  12. brian m. carlsonSep 4, 2025
  13. Patrick SteinhardtSep 5, 2025
  14. Ezekiel NewrenSep 4, 2025
  15. Eli SchwartzSep 5, 2025
  16. Patrick SteinhardtSep 5, 2025
  17. Eli SchwartzSep 5, 2025
  18. Ben KnobleSep 7, 2025
  19. Junio C HamanoSep 8, 2025
  20. Patrick SteinhardtSep 8, 2025
  21. Ben KnobleSep 9, 2025
  22. Junio C HamanoSep 9, 2025
  23. Patrick SteinhardtSep 8, 2025
  24. 3/3 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Sep 4, 2025
  25. Eric SunshineSep 4, 2025
  26. Patrick SteinhardtSep 5, 2025
  27. 0/7 Introduce Rust and announce that it will become mandatortyPatrick Steinhardt, Sep 5, 2025
  28. 1/7 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 5, 2025
  29. Justin ToblerSep 5, 2025
  30. Patrick SteinhardtSep 8, 2025
  31. Elijah NewrenSep 7, 2025
  32. Patrick SteinhardtSep 8, 2025
  33. 2/7 Makefile: introduce infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 5, 2025
  34. brian m. carlsonSep 5, 2025
  35. Patrick SteinhardtSep 8, 2025
  36. Elijah NewrenSep 7, 2025
  37. Patrick SteinhardtSep 8, 2025
  38. SZEDER GáborSep 7, 2025
  39. Patrick SteinhardtSep 8, 2025
  40. 3/7 help: report on whether or not Rust is enabledPatrick Steinhardt, Sep 5, 2025
  41. brian m. carlsonSep 5, 2025
  42. Elijah NewrenSep 7, 2025
  43. 4/7 rust: implement a test balloon via the "varint" subsystemPatrick Steinhardt, Sep 5, 2025
  44. Junio C HamanoSep 5, 2025
  45. Junio C HamanoSep 5, 2025
  46. brian m. carlsonSep 5, 2025
  47. 5/7 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Sep 5, 2025
  48. Matthias AßhauerSep 5, 2025
  49. Patrick SteinhardtSep 5, 2025
  50. Eli SchwartzSep 5, 2025
  51. Patrick SteinhardtSep 8, 2025
  52. Elijah NewrenSep 7, 2025
  53. Patrick SteinhardtSep 8, 2025
  54. Phillip WoodSep 5, 2025
  55. Eli SchwartzSep 5, 2025
  56. brian m. carlsonSep 5, 2025
  57. Elijah NewrenSep 7, 2025
  58. 6/7 ci: convert "pedantic" job into full build with breaking changesPatrick Steinhardt, Sep 5, 2025
  59. Junio C HamanoSep 7, 2025
  60. Patrick SteinhardtSep 8, 2025
  61. 7/7 ci: enable Rust for breaking-changes jobsPatrick Steinhardt, Sep 5, 2025
  62. brian m. carlsonSep 5, 2025
  63. Patrick SteinhardtSep 8, 2025
  64. Junio C HamanoSep 5, 2025
  65. Patrick SteinhardtSep 8, 2025
  66. Phillip WoodSep 5, 2025
  67. Patrick SteinhardtSep 5, 2025
  68. Elijah NewrenSep 7, 2025
  69. Patrick SteinhardtSep 8, 2025
  70. brian m. carlsonSep 8, 2025
  71. Patrick SteinhardtSep 10, 2025
  72. Elijah NewrenSep 9, 2025
  73. Patrick SteinhardtSep 10, 2025
  74. Phillip WoodSep 9, 2025
  75. Patrick SteinhardtSep 10, 2025
  76. Phillip WoodSep 10, 2025
  77. Patrick SteinhardtSep 10, 2025
  78. 0/8 Introduce Rust and announce that it will become mandatortyPatrick Steinhardt, Sep 8, 2025
  79. 1/8 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 8, 2025
  80. brian m. carlsonSep 8, 2025
  81. brian m. carlsonSep 9, 2025
  82. Patrick SteinhardtSep 10, 2025
  83. 2/8 Makefile: reorder sources after includesPatrick Steinhardt, Sep 8, 2025
  84. 3/8 Makefile: introduce infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 8, 2025
  85. 4/8 help: report on whether or not Rust is enabledPatrick Steinhardt, Sep 8, 2025
  86. 5/8 rust: implement a test balloon via the "varint" subsystemPatrick Steinhardt, Sep 8, 2025
  87. Ezekiel NewrenSep 8, 2025
  88. brian m. carlsonSep 8, 2025
  89. Patrick SteinhardtSep 10, 2025
  90. 6/8 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Sep 8, 2025
  91. 7/8 ci: convert "pedantic" job into full build with breaking changesPatrick Steinhardt, Sep 8, 2025
  92. 8/8 ci: enable Rust for breaking-changes jobsPatrick Steinhardt, Sep 8, 2025
  93. Kristoffer HaugsbakkSep 8, 2025
  94. 0/9 Introduce Rust and announce that it will become mandatoryPatrick Steinhardt, Sep 10, 2025
  95. 1/9 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 10, 2025
  96. brian m. carlsonSep 11, 2025
  97. D. Ben KnobleJan 20, 2026
  98. brian m. carlsonJan 20, 2026
  99. Patrick SteinhardtJan 21, 2026
  100. 2/9 Makefile: reorder sources after includesPatrick Steinhardt, Sep 10, 2025
  101. 3/9 Makefile: introduce infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 10, 2025
  102. 4/9 help: report on whether or not Rust is enabledPatrick Steinhardt, Sep 10, 2025
  103. 5/9 varint: use explicit width for integersPatrick Steinhardt, Sep 10, 2025
  104. Junio C HamanoSep 10, 2025
  105. 6/9 varint: reimplement as test balloon for RustPatrick Steinhardt, Sep 10, 2025
  106. 7/9 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Sep 10, 2025
  107. Junio C HamanoSep 10, 2025
  108. Patrick SteinhardtSep 15, 2025
  109. Junio C HamanoSep 22, 2025
  110. Patrick SteinhardtSep 23, 2025
  111. LTS "lieutenant", was Re: [PATCH RFC v4 7/9] BreakingChanges: announce Rust becoming mandatoryJohannes Schindelin, Sep 23, 2025
  112. Patrick SteinhardtSep 24, 2025
  113. Junio C HamanoSep 23, 2025
  114. Patrick SteinhardtSep 24, 2025
  115. Junio C HamanoSep 24, 2025
  116. Kristoffer HaugsbakkSep 10, 2025
  117. Patrick SteinhardtSep 15, 2025
  118. 8/9 ci: convert "pedantic" job into full build with breaking changesPatrick Steinhardt, Sep 10, 2025
  119. 9/9 ci: enable Rust for breaking-changes jobsPatrick Steinhardt, Sep 10, 2025
  120. brian m. carlsonSep 11, 2025
  121. Patrick SteinhardtSep 15, 2025
  122. SZEDER GáborSep 12, 2025
  123. Junio C HamanoSep 12, 2025
  124. Patrick SteinhardtSep 15, 2025
  125. 0/9 Introduce Rust and announce that it will become mandatoryPatrick Steinhardt, Sep 15, 2025
  126. 1/9 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 15, 2025
  127. 2/9 Makefile: reorder sources after includesPatrick Steinhardt, Sep 15, 2025
  128. 3/9 Makefile: introduce infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 15, 2025
  129. 4/9 help: report on whether or not Rust is enabledPatrick Steinhardt, Sep 15, 2025
  130. 5/9 varint: use explicit width for integersPatrick Steinhardt, Sep 15, 2025
  131. 6/9 varint: reimplement as test balloon for RustPatrick Steinhardt, Sep 15, 2025
  132. 7/9 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Sep 15, 2025
  133. SZEDER GáborSep 17, 2025
  134. brian m. carlsonSep 18, 2025
  135. SZEDER GáborSep 22, 2025
  136. Junio C HamanoSep 22, 2025
  137. brian m. carlsonSep 22, 2025
  138. Junio C HamanoSep 22, 2025
  139. Elijah NewrenSep 23, 2025
  140. Patrick SteinhardtSep 23, 2025
  141. Junio C HamanoSep 23, 2025
  142. Ezekiel NewrenSep 23, 2025
  143. Phillip WoodSep 19, 2025
  144. Patrick SteinhardtSep 22, 2025
  145. Phillip WoodSep 22, 2025
  146. Patrick SteinhardtSep 22, 2025
  147. 8/9 ci: convert "pedantic" job into full build with breaking changesPatrick Steinhardt, Sep 15, 2025
  148. 9/9 ci: enable Rust for breaking-changes jobsPatrick Steinhardt, Sep 15, 2025
  149. Junio C HamanoSep 15, 2025
  150. Ezekiel NewrenSep 16, 2025
  151. Patrick SteinhardtSep 16, 2025
  152. Sam JamesSep 17, 2025
  153. Ezekiel NewrenSep 17, 2025
  154. Ramsay JonesSep 16, 2025
  155. Ezekiel NewrenSep 16, 2025
  156. Ramsay JonesSep 17, 2025
  157. Elijah NewrenSep 18, 2025
  158. what's missing from newer C? [was: [PATCH v5 0/9] Introduce Rust ....]Eric Wong, Sep 25, 2025
  159. Ezekiel NewrenSep 26, 2025
  160. Eric WongOct 4, 2025
  161. Pierre-Emmanuel PatryOct 6, 2025
  162. John Paul Adrian GlaubitzSep 19, 2025
  163. Patrick SteinhardtSep 22, 2025
  164. 0/9 Introduce Rust and announce that it will become mandatoryPatrick Steinhardt, Sep 23, 2025
  165. 1/9 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 23, 2025
  166. 2/9 Makefile: reorder sources after includesPatrick Steinhardt, Sep 23, 2025
  167. 3/9 Makefile: introduce infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 23, 2025
  168. 4/9 help: report on whether or not Rust is enabledPatrick Steinhardt, Sep 23, 2025
  169. 5/9 varint: use explicit width for integersPatrick Steinhardt, Sep 23, 2025
  170. 6/9 varint: reimplement as test balloon for RustPatrick Steinhardt, Sep 23, 2025
  171. 7/9 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Sep 23, 2025
  172. Phillip WoodSep 23, 2025
  173. Junio C HamanoSep 23, 2025
  174. Patrick SteinhardtSep 24, 2025
  175. 8/9 ci: convert "pedantic" job into full build with breaking changesPatrick Steinhardt, Sep 23, 2025
  176. 9/9 ci: enable Rust for breaking-changes jobsPatrick Steinhardt, Sep 23, 2025
  177. Ezekiel NewrenSep 23, 2025
  178. Patrick SteinhardtSep 24, 2025
  179. Ezekiel NewrenSep 24, 2025
  180. 0/9 Introduce Rust and announce that it will become mandatoryPatrick Steinhardt, Sep 25, 2025
  181. 1/9 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 25, 2025
  182. 2/9 Makefile: reorder sources after includesPatrick Steinhardt, Sep 25, 2025
  183. Ramsay JonesSep 25, 2025
  184. 3/9 Makefile: introduce infrastructure to build internal Rust libraryPatrick Steinhardt, Sep 25, 2025
  185. 4/9 help: report on whether or not Rust is enabledPatrick Steinhardt, Sep 25, 2025
  186. 5/9 varint: use explicit width for integersPatrick Steinhardt, Sep 25, 2025
  187. Kristoffer HaugsbakkSep 30, 2025
  188. Ezekiel NewrenOct 1, 2025
  189. Patrick SteinhardtOct 2, 2025
  190. 6/9 varint: reimplement as test balloon for RustPatrick Steinhardt, Sep 25, 2025
  191. Ezekiel NewrenOct 1, 2025
  192. Junio C HamanoOct 1, 2025
  193. 7/9 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Sep 25, 2025
  194. 8/9 ci: convert "pedantic" job into full build with breaking changesPatrick Steinhardt, Sep 25, 2025
  195. 9/9 ci: enable Rust for breaking-changes jobsPatrick Steinhardt, Sep 25, 2025
  196. Junio C HamanoSep 25, 2025
  197. Ezekiel NewrenOct 1, 2025
  198. 0/9 Introduce Rust and announce that it will become mandatoryPatrick Steinhardt, Oct 2, 2025
  199. 1/9 meson: add infrastructure to build internal Rust libraryPatrick Steinhardt, Oct 2, 2025
  200. 2/9 Makefile: reorder sources after includesPatrick Steinhardt, Oct 2, 2025
  201. 3/9 Makefile: introduce infrastructure to build internal Rust libraryPatrick Steinhardt, Oct 2, 2025
  202. 4/9 help: report on whether or not Rust is enabledPatrick Steinhardt, Oct 2, 2025
  203. 5/9 varint: use explicit width for integersPatrick Steinhardt, Oct 2, 2025
  204. 6/9 varint: reimplement as test balloon for RustPatrick Steinhardt, Oct 2, 2025
  205. 7/9 BreakingChanges: announce Rust becoming mandatoryPatrick Steinhardt, Oct 2, 2025
  206. 8/9 ci: convert "pedantic" job into full build with breaking changesPatrick Steinhardt, Oct 2, 2025
  207. 9/9 ci: enable Rust for breaking-changes jobsPatrick Steinhardt, Oct 2, 2025
  208. Junio C HamanoOct 2, 2025
  209. Patrick SteinhardtOct 7, 2025
  210. Ezekiel NewrenOct 2, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.