Re: [PATCH v3 02/15] xdiff: introduce rust
- From
Patrick Steinhardt <ps@pks.im>
- Date
- Sep 2, 2025, 11:16 UTC
- Message-ID
- <aLbSA5KsBdD4wW_B@pks.im>
- In-Reply-To
- <xmqqh5xszf91.fsf@gitster.g>
On Wed, Aug 27, 2025 at 01:22:34PM -0700, Junio C Hamano wrote:
Show 16 quoted lines
> Taylor Blau <me@ttaylorr.com> writes: > > > (As an aside, I mentioned in my earlier email to Randall that I have a > > suspicion that Rust code will have fewer security issues than C code, > > and so the likelihood of needing to backport a security fix from Rust to > > C seems lower to me than having to simply patch old C code. Time will > > tell, I guess.) > > Just like back when scripted Porcelains were rewritten in C, in 5 > years, when a lot of the existing C code is rewritten, who among us > would care to backport or "simply patch" old C code? > > This of course assumes that these platforms that lack Rust still > lack Rust after 5 years, yet still matters to the users, and the > vendor does not care to support Git themselves. Maybe one of these > three conditions would change and make the problem go away ;-)
It will definitely require additional maintenance by us. I think it's reasonable to say that platforms without Rust won't get new features anymore. But when it comes to security fixes or significant bugs I think it's less sensible to say that they're left on their own.
I proposed this in a separate branch of these threads, but we could counteract this by declaring the last major version before we introduce Rust as an LTS version that will receive both security and severe bug fixes going forward. Ideally, that LTS release would continue to be maintained until the gcc-rs backend is ready for prime time, which should alleviate a lot of the portability concerns.
As Pierre-Emmanuel menitoned in [1], the backend is likely to stabilize next year. One or two years of backports for that particular LTS version doesn't feel too bad. And if it does become more involved we can maybe also distribute the load and rely on maintainers of impacted platforms without Rust to help out with the backporting.
Also, all of this feels like a significant shift. I'm strongly in favor of adopting Rust in our codebase, but I think we should do so carefully. So we might take it extra carefully and say that Rust will become a mandatory dependency in Git 3.0, where the last release before Git 3.0 will become an LTS release.
Patrick
[1]: <7bf054a1-0196-4ad8-aaa4-a432cd2c93a5@embecosm.com>