From: Ezekiel Newren Date: Fri, 26 Sep 2025 22:17:49 GMT Subject: Re: what's missing from newer C? [was: [PATCH v5 0/9] Introduce Rust ....] Message-ID: In-Reply-To: <20250925011043.M401827@dcvr> On Wed, Sep 24, 2025 at 7:10 PM Eric Wong wrote: > What else is missing from C? 1. Checked Arithmetic * C23: for checked integer operations. * Rust: built-ins like checked_add, wrapping_add. 2. __counted_by__ attribute * Clang 18 / GCC 15: experimental, helps catch buffer overflows. * Rust: slices already carry length, preventing out-of-bounds by design. 3. __cleanup__ attribute * GCC, Clang, TinyCC: long-standing extension for RAII-like cleanup. * Rust: Drop trait ensures deterministic cleanup. 4. RCU / concurrency libraries * Userspace RCU, ConcurrencyKit, etc. available in C. * Rust: crossbeam, Arc, lock-free crates. 5. Format string checking * GCC/Clang/MSVC check format strings at compile time. * Rust: format! macros type-check arguments. 6. Regex and parsing * C: POSIX regex, PCRE2, re2c, wuffs. * Rust: regex crate (safe, no unchecked buffer access). 7. Dynamic analysis * C: Valgrind, ASan, TSan, UBSan, MSan. * Rust: Miri, LLVM sanitizers. What else is missing in C? Compared to Rust, here's where C still falls short at the language level (not just tooling): 1. Ownership and lifetimes * No borrow checker; compiler can't prevent use-after-free, double free, or aliasing bugs. 2. Async/await coroutines * No language support. Async requires threads, callbacks, or libraries. * Rust: async fn / .await integrated into the language. 3. Explicit numeric conversions * C silently promotes between ints/floats/signed/unsigned. * Rust requires explicit casts (down and up), reducing surprises. 4. Sum types with exhaustiveness checks * C: enum + union is manual, compiler won’t enforce full handling. * Rust: enum + match requires covering all variants. 5. Safer error handling * C: errno, return codes, ad hoc conventions. * Rust: Result + ? operator, forcing handling. 6. Concurrency safety by design * C11 added atomics, but race conditions are unchecked. * Rust: Send / Sync traits enforce thread-safety at compile time. 7. Namespaces / modules * C: relies on foo_bar() prefixes and headers. * Rust: mod and crate system. 8. Default immutability * C: everything mutable unless marked const. * Rust: immutable by default, opt into mut. You have a choice of 1 mutable reference xor many immutable references to something. 9. Package management * C: out of scope for the language * Rust: built in with Cargo dependencies In Rust there is a difference between concurrency and parallelism. Concurrency in Rust is about running multiple tasks with a single system thread. Whereas parallelism is about assigning tasks to multiple threads. I highly doubt that C will ever get coroutines because it requires the compiler to create a state machine out of each function that uses async or await keywords. The C language just isn't robust enough for that in my opinion. And there's probably more that I haven't covered here.