threads / rfc / 64170

patch, 3 partsRe: [PATCH RFC 0/3] Introduce Rust and announce that it will become mandatorty

Subject: Re: [PATCH RFC 0/3] Introduce Rust and announce that it will become mandatorty

## tl;dr

10 messages between Sep 19, 2025 and Sep 23, 2025. Diffs are folded; open one to read it.

replies: 9people: 8as markdown or json

Sergey Fedorov· Sep 19, 2025, 17:36 UTC · lore

This will be a disaster, please consider not making rust mandatory. It will break git for all systems without rust, in effect killing not only possibility to use GitHub and other git-based services, but also breaking build systems, since many ports – and package managers – rely on git to fetch sources. As for local version control, git could be replaced with some alternative (likely inferior, but at least that is not the end). There is no replacement, AFAIK, for build systems and for git-based online services.

P. S. In case anyone wonders, this is personally relevant for me: I won’t be able to continue contributing to open-source anymore (at least certainly not like in past years) with git being unusable due to broken rust.
Ezekiel Newren· Sep 19, 2025, 17:56 UTC · re: Sergey Fedorov · lore

On Fri, Sep 19, 2025 at 11:36 AM Sergey Fedorov <barracuda@macos-powerpc.org> wrote:

Show 6 quoted lines
> This will be a disaster, please consider not making rust mandatory.
> It will break git for all systems without rust, in effect killing not only possibility to use GitHub and other git-based services, but also breaking build systems, since many ports – and package managers – rely on git to fetch sources.
> As for local version control, git could be replaced with some alternative (likely inferior, but at least that is not the end).
> There is no replacement, AFAIK, for build systems and for git-based online services.
>
> P. S. In case anyone wonders, this is personally relevant for me: I won’t be able to continue contributing to open-source anymore (at least certainly not like in past years) with git being unusable due to broken rust.

The mailing list has had extremely heated debates about this, and there are many who would agree and disagree with you. So please try to read my comment as a genuine interest in trying to understand your situation. I would like to hear why making Rust mandatory would make using and contributing to Git insurmountable. We know for sure that NonStop currently does not support Rust at all, and that there are problems with porting Rust to Gentoo, but I'd like to hear what OSes and Architectures you use personally and professionally and why adding Rust would be a bad idea. Is it corporate policy? Is it that the Rust toolchain doesn't exist for your os/arch? Is it that Rust is a new language and isn't as battle tested as C? Something else?

I believe that even "I don't know Rust and don't want to learn it." would be a valid comment to add as well. I think the discussion of Rust has been so hot because we (the Git community) don't understand everyone's situations and how they'll be affected, and what could possibly be done to address concerns.

Collin Funk· Sep 19, 2025, 18:14 UTC · re: Ezekiel Newren · lore
Ezekiel Newren <ezekielnewren@gmail.com> writes:
Show 26 quoted lines
> On Fri, Sep 19, 2025 at 11:36 AM Sergey Fedorov
> <barracuda@macos-powerpc.org> wrote:
>> This will be a disaster, please consider not making rust mandatory.
>> It will break git for all systems without rust, in effect killing not only possibility to use GitHub and other git-based services, but also breaking build systems, since many ports – and package managers – rely on git to fetch sources.
>> As for local version control, git could be replaced with some alternative (likely inferior, but at least that is not the end).
>> There is no replacement, AFAIK, for build systems and for git-based online services.
>>
>> P. S. In case anyone wonders, this is personally relevant for me: I won’t be able to continue contributing to open-source anymore (at least certainly not like in past years) with git being unusable due to broken rust.
>
> The mailing list has had extremely heated debates about this, and
> there are many who would agree and disagree with you. So please try to
> read my comment as a genuine interest in trying to understand your
> situation. I would like to hear why making Rust mandatory would make
> using and contributing to Git insurmountable. We know for sure that
> NonStop currently does not support Rust at all, and that there are
> problems with porting Rust to Gentoo, but I'd like to hear what OSes
> and Architectures you use personally and professionally and why adding
> Rust would be a bad idea. Is it corporate policy? Is it that the Rust
> toolchain doesn't exist for your os/arch? Is it that Rust is a new
> language and isn't as battle tested as C? Something else?
>
> I believe that even "I don't know Rust and don't want to learn it."
> would be a valid comment to add as well. I think the discussion of
> Rust has been so hot because we (the Git community) don't understand
> everyone's situations and how they'll be affected, and what could
> possibly be done to address concerns.

Based on the domain of their email they use MacOS PowerPC. AFAIK LLVM has not supported it for a long time.

Collin
Florian Märkl· Sep 20, 2025, 08:24 UTC · re: Ezekiel Newren · lore
Show 5 quoted lines
> Ezekiel Newren <ezekielnewren@gmail.com> wrote:
> 
> I'd like to hear what OSes
> and Architectures you use personally and professionally and why adding
> Rust would be a bad idea.

To add some specific cases from my side as well, problematic platforms include Mac OS X on ppc as well as OpenBSD/macppc (32-bit). Both of these are still relevant, as OpenBSD is actively maintained on this architecture and Mac OS X 10.5 is supported by MacPorts, resulting in a system with modern tools that is still able to run and debug certain legacy software.

In particular, in the Rizin project, we use both platforms regularly to test our code for architecture and OS-specific bugs, and we also support them to run Rizin itself for debugging and analyzing software there.

I do not advocate not adopting Rust because of the language itself, but I think it is important to compare the maturity of the compiler and ecosystem to the project that will strictly depend on it.

Michael Orlitzky· Sep 22, 2025, 15:59 UTC · re: Ezekiel Newren · lore
Show 7 quoted lines
> We know for sure that NonStop currently does not support Rust at
> all, and that there are problems with porting Rust to Gentoo, but
> I'd like to hear what OSes and Architectures you use personally and
> professionally and why adding Rust would be a bad idea. Is it
> corporate policy? Is it that the Rust toolchain doesn't exist for
> your os/arch? Is it that Rust is a new language and isn't as battle
> tested as C? Something else?

There is no problem with supporting rust on Gentoo. Gentoo users build from source, and rust is a problem for anyone who builds from source. I'm writing this on a riscv/musl system. If there are no binaries for your CPU/libc, let me tell you, it's not fun. And this is like, my job. A normal person would be completely helpless.

Nevertheless, the arch support issues are secondary. I'm sure it's a lot of fun for the people who are writing rust code to do cargo updates in the two or three directories they work in all day. But I'm not writing rust code, don't care what language git is written in, and have hundreds of other packages to keep up-to-date on multiple machines. I want to be able to use my package manager to do that efficiently. You know, the main tangible benefit of using a linux distribution.

But every distribution is "packaging" rust the same way. They're bundling random old versions of crates in violation of their own policies because the ecosystem is unstable and the tooling encourages tight coupling. By requiring rust, you are require me to go back to managing dependencies like I'm on Windows XP again. Git is the most important program I use, but it's not more important than package management itself.

Sam James· Sep 22, 2025, 16:17 UTC · re: Michael Orlitzky · lore
Michael Orlitzky <michael@orlitzky.com> writes:
Show 14 quoted lines
>> We know for sure that NonStop currently does not support Rust at
>> all, and that there are problems with porting Rust to Gentoo, but
>> I'd like to hear what OSes and Architectures you use personally and
>> professionally and why adding Rust would be a bad idea. Is it
>> corporate policy? Is it that the Rust toolchain doesn't exist for
>> your os/arch? Is it that Rust is a new language and isn't as battle
>> tested as C? Something else?
>
> There is no problem with supporting rust on Gentoo. Gentoo users build
> from source, and rust is a problem for anyone who builds from
> source. I'm writing this on a riscv/musl system. If there are no
> binaries for your CPU/libc, let me tell you, it's not fun. And this is
> like, my job. A normal person would be completely helpless.
>

That is precisely the problem that Eli and I have been describing in this thread (along with some more minor issues for Prefix to figure out, and then missing arch support where Rust doesn't support it at all).

He is referencing issues we brought up earlier in the (various) threads, not plucking it out of thin air.

Show 16 quoted lines
> Nevertheless, the arch support issues are secondary. I'm sure it's a
> lot of fun for the people who are writing rust code to do cargo
> updates in the two or three directories they work in all day. But I'm
> not writing rust code, don't care what language git is written in, and
> have hundreds of other packages to keep up-to-date on multiple
> machines. I want to be able to use my package manager to do that
> efficiently. You know, the main tangible benefit of using a linux
> distribution.
>
> But every distribution is "packaging" rust the same way. They're
> bundling random old versions of crates in violation of their own
> policies because the ecosystem is unstable and the tooling encourages
> tight coupling. By requiring rust, you are require me to go back to
> managing dependencies like I'm on Windows XP again. Git is the most
> important program I use, but it's not more important than package
> management itself.
Indeed, this is all terrible, and I agree with you, of course.
brian m. carlson· Sep 22, 2025, 21:35 UTC · re: Michael Orlitzky · lore
On 2025-09-22 at 15:59:49, Michael Orlitzky wrote:
Show 5 quoted lines
> There is no problem with supporting rust on Gentoo. Gentoo users build
> from source, and rust is a problem for anyone who builds from
> source. I'm writing this on a riscv/musl system. If there are no
> binaries for your CPU/libc, let me tell you, it's not fun. And this is
> like, my job. A normal person would be completely helpless.

This is a problem with languages that bootstrap from earlier versions of themselves. It also happens with other, less common languages. GHC (a Haskell runtime) also has this problem and any distro that ships pandoc has to deal with it.

It is certainly inconvenient, but there is mrustc to help the bootstrap process. Granted, it does not work everywhere yet, but it should also not be too difficult to make it do so.

I do think the difficulty is worth it, though. With Rust, we're going to get code that is thread-safe and memory-safe by the virtue of the fact that it compiles and that will allow us to have threading in more parts of the code where it might benefit us. I also cannot tell you how many segfaults and null pointer dereferences I've written in Git (some in the past week) that are just no longer possible with Rust.

As my proposal originally mentioned, there is enormous pressure from governments, security professionals, and large companies to improve memory safety, which I believe are legitimate concerns. If we want Git to continue to be used widely, then we need to address those issues and Rust seems to be the best possible way to do that. I don't think continuing in C only is going to be viable long term.

Show 8 quoted lines
> Nevertheless, the arch support issues are secondary. I'm sure it's a
> lot of fun for the people who are writing rust code to do cargo
> updates in the two or three directories they work in all day. But I'm
> not writing rust code, don't care what language git is written in, and
> have hundreds of other packages to keep up-to-date on multiple
> machines. I want to be able to use my package manager to do that
> efficiently. You know, the main tangible benefit of using a linux
> distribution.

I don't think this is going to happen as you anticipate it will. My original policy was to target Debian stable's release for a year after the new Debian stable came out and that will make using many crates nearly impossible. We are going to have to be _extremely_ careful about dependencies in general and the things we are likely to use are things like bindgen and cbindgen, where typically an old version will work just fine and which are already packaged in major distros. We are not going to be adding dependencies willy-nilly and running `cargo update` every other day.

Show 7 quoted lines
> But every distribution is "packaging" rust the same way. They're
> bundling random old versions of crates in violation of their own
> policies because the ecosystem is unstable and the tooling encourages
> tight coupling. By requiring rust, you are require me to go back to
> managing dependencies like I'm on Windows XP again. Git is the most
> important program I use, but it's not more important than package
> management itself.

I expect Debian already packages the crates that we need in acceptable versions, and I assume other distros do as well, so I don't anticipate this being a problem for us.

-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Sam James· Sep 22, 2025, 21:47 UTC · re: brian m. carlson · lore
"brian m. carlson" <sandals@crustytoothpaste.net> writes:
Show 11 quoted lines
> On 2025-09-22 at 15:59:49, Michael Orlitzky wrote:
>> There is no problem with supporting rust on Gentoo. Gentoo users build
>> from source, and rust is a problem for anyone who builds from
>> source. I'm writing this on a riscv/musl system. If there are no
>> binaries for your CPU/libc, let me tell you, it's not fun. And this is
>> like, my job. A normal person would be completely helpless.
>
> This is a problem with languages that bootstrap from earlier versions of
> themselves.  It also happens with other, less common languages.  GHC (a
> Haskell runtime) also has this problem and any distro that ships pandoc
> has to deal with it.
Usually there's nothing too critical in such a language ;)
Show 37 quoted lines
>
> It is certainly inconvenient, but there is mrustc to help the bootstrap
> process.  Granted, it does not work everywhere yet, but it should also
> not be too difficult to make it do so.
>
> I do think the difficulty is worth it, though.  With Rust, we're going
> to get code that is thread-safe and memory-safe by the virtue of the
> fact that it compiles and that will allow us to have threading in more
> parts of the code where it might benefit us.  I also cannot tell you how
> many segfaults and null pointer dereferences I've written in Git (some
> in the past week) that are just no longer possible with Rust.
>
> As my proposal originally mentioned, there is enormous pressure from
> governments, security professionals, and large companies to improve
> memory safety, which I believe are legitimate concerns.  If we want Git
> to continue to be used widely, then we need to address those issues and
> Rust seems to be the best possible way to do that.  I don't think
> continuing in C only is going to be viable long term.
>
>> Nevertheless, the arch support issues are secondary. I'm sure it's a
>> lot of fun for the people who are writing rust code to do cargo
>> updates in the two or three directories they work in all day. But I'm
>> not writing rust code, don't care what language git is written in, and
>> have hundreds of other packages to keep up-to-date on multiple
>> machines. I want to be able to use my package manager to do that
>> efficiently. You know, the main tangible benefit of using a linux
>> distribution.
>
> I don't think this is going to happen as you anticipate it will.  My
> original policy was to target Debian stable's release for a year after
> the new Debian stable came out and that will make using many crates
> nearly impossible.  We are going to have to be _extremely_ careful about
> dependencies in general and the things we are likely to use are things
> like bindgen and cbindgen, where typically an old version will work just
> fine and which are already packaged in major distros.  We are not going
> to be adding dependencies willy-nilly and running `cargo update` every
> other day.

That brings me significant comfort and I'm glad to hear it. I hope others agree with your position on having significant restraint on the use of external crates.

git has always been quite good about dependencies pre-Rust.
Show 12 quoted lines
>
>> But every distribution is "packaging" rust the same way. They're
>> bundling random old versions of crates in violation of their own
>> policies because the ecosystem is unstable and the tooling encourages
>> tight coupling. By requiring rust, you are require me to go back to
>> managing dependencies like I'm on Windows XP again. Git is the most
>> important program I use, but it's not more important than package
>> management itself.
>
> I expect Debian already packages the crates that we need in acceptable
> versions, and I assume other distros do as well, so I don't anticipate
> this being a problem for us.

Yes, I expect on our end in Gentoo, that we'll probably need to use this to finally migrate to a Debian-style handling of crates, though that's not your problem.

Patrick Steinhardt· Sep 23, 2025, 05:05 UTC · re: Sam James · lore
On Mon, Sep 22, 2025 at 10:47:03PM +0100, Sam James wrote:
Show 16 quoted lines
> "brian m. carlson" <sandals@crustytoothpaste.net> writes:
> > I don't think this is going to happen as you anticipate it will.  My
> > original policy was to target Debian stable's release for a year after
> > the new Debian stable came out and that will make using many crates
> > nearly impossible.  We are going to have to be _extremely_ careful about
> > dependencies in general and the things we are likely to use are things
> > like bindgen and cbindgen, where typically an old version will work just
> > fine and which are already packaged in major distros.  We are not going
> > to be adding dependencies willy-nilly and running `cargo update` every
> > other day.
> 
> That brings me significant comfort and I'm glad to hear it. I hope
> others agree with your position on having significant restraint on the
> use of external crates.
> 
> git has always been quite good about dependencies pre-Rust.

I certainly echo brian's sentiment here. Rust dependencies are easy to use, but they are also one part that worries me quite significantly due to multiple reasons:

  - Pulling in many dependencies opens us up for supply chain attacks.
  - Every single dependency is a source for vulnerabilities in general.
    We're already good enough in creating these ourselves.
  - Dependencies may have hard requirements on the Rust version,
    requiring us to bump the minimum required toolchain version.
  - In general, I'm not a fan of having even dozens of dependencies. It
    causes bloat and externalizes a bunch of knowledge.

So I think we should and need to be very conservative about adding any new dependencies. There will be cases where it makes sense, but every new dependency should be well-reasoned.

After this patch series lands, one of the next steps will also be to add a policy for how we want to use Rust in the Git project. brian has already written such a policy (see e.g. [1]), and it already mentions that we'll need to be careful about adding dependencies. Might be worth it to flesh that part out a bit more, but that's something we can discuss at a later point.

Patrick
[1]: <6d065f550fe871cf010409f7bd2a63438cf52723.1756496539.git.gitgitgadget@gmail.com>
Michael Orlitzky· Sep 22, 2025, 23:23 UTC · re: brian m. carlson · lore
On Mon, 2025-09-22 at 21:35 +0000, brian m. carlson wrote:
Show 11 quoted lines
> On 2025-09-22 at 15:59:49, Michael Orlitzky wrote:
> > There is no problem with supporting rust on Gentoo. Gentoo users build
> > from source, and rust is a problem for anyone who builds from
> > source. I'm writing this on a riscv/musl system. If there are no
> > binaries for your CPU/libc, let me tell you, it's not fun. And this is
> > like, my job. A normal person would be completely helpless.
> 
> This is a problem with languages that bootstrap from earlier versions of
> themselves.  It also happens with other, less common languages.  GHC (a
> Haskell runtime) also has this problem and any distro that ships pandoc
> has to deal with it.
Spectacular example.

In Gentoo we support the following arches: alpha, amd64, arm, arm64, hppa, loong, m68k, mips, ppc, ppc64, riscv, s390, sparc, and x86. We support both glibc and musl, for 23 arch/libc combinations (we don't support musl on every arch).

Pandoc supports: amd64, arm64, ppc64, riscv and x86, but only on glibc. That's 5 out of 23. If you're able to use GHC 9.2 released in 2021, that is. Otherwise it's 0 out of 23. No one "has to deal with" anything.

Coincidentally, I am one of only a few people to bootstrap a modern GHC on riscv/musl:

  https://wiki.gentoo.org/wiki/User:Mjo/GHC_binary_packages

Knowing the amount of work involved, I can promise that if Git switched to Haskell today, it would be our users who would have to deal with... not having Git any more.

I agree completely when it comes to the benefits of static typing and memory safety. (I've been writing Haskell for 15 years, after all.) But for the time being, all of the cures are worse than the disease.

← back to recent threads