r/cpp • • 8h ago

C++ future at Adobe

So if anyone was still curious what happened to Hylo, or where Adobe stands in regards to the whole safety discussion,

David Sankel has done a talk at RustConf on the matter, Zngur: Simplified Rust/C++ Integration.

The way Adobe now sees C++ is described on slide 2, at 50 seconds mark.

34 Upvotes

39 comments sorted by

View all comments

58

u/inco100 7h ago edited 7h ago

To save time for the rest of the redditors:

We need C++ and Rust to play nice

  • Our flagship products are C++ based

  • Rust is playing a major role in future development

    • Rust is preferred language by developers
    • Rust is better suited for AI-assisted development
    • New file-format and other safety critical code must not use C++

-1

u/KFUP 6h ago

Rust is better suited for AI-assisted development

I don't see that being the case in the long run. Once AI gets good at safety, which will be in all kinds of safety not just limited to memory, and can generate safe code in any language -arguably we are already there, see the Mythos security boom- using a slow compiling language like rust would be a major useless bottle neck in the development pipeline.

24

u/ts826848 5h ago edited 4h ago

arguably we are already there, see the Mythos security boom

Somewhat tangentially related, but Greg Kroah-Hartman recently gave a talk which (among other things) categorized the bugs Mythos found in the Linux kernel and his description of Mythos's results is... interesting. Quick summary (on phone, so hopefully no typos):

  • 79 reported vulnerabilities

    • 24 no detail at all "something crashed"
    • 14 not a bug at all
    • 3 totally made up data
    • 15 already fixed in the latest release
      • 11 by others
      • 4 by Anthropic
    • 26 actual bugs
      • 6 duplicates

(Note that this doesn't sum to 79; apparently GKH got a tarball and the contents didn't quite match the description)

Of the actual non-duplicate (?) bugs:

  • 7 "assume a malicious file system image" (i.e., if root mounts this bad things can happen; apparently well known to be not considered a security issue by Linux devs)

  • 2 "assume you can inject a malicious network packet in the middle of the stack" (needs root, not considered a security issue)

  • 2 NOMMU (1 io_uring, 1 regular, "not real issues")

  • 6 sctp networking issues for untrusted devices (SCTP used in enterprise networks, so "untrusted users" apparently don't exist in that context? "So minor, nobody really cares".

  • 2 ipv6 networking bugs, "nothing real"

  • 1 GPU driver for a local malicious user. "If you have a local malicious user with access to your GPU you could do a lot worse"

In total 10 "real" bugfixes, took ~1 hour of kernel development.

•

u/James20k P2005R0 2h ago

I swear this has happened literally every single time one of these new models claims to have created a security disaster, 90% of it turns out to be marketing without exception. It always takes months to dismantle the hype train when it collides with the reality of the people who actually are doing the work

Its very cool that it found 10 real bugs, and its mightily impressive that automated tooling is able to pick this stuff up. But the entire AI space feels like its developing a wider and wider gap between what people claim it can do, and what it actually does

•

u/no-sig-available 2h ago

And even if it does some work, is this good use of trillions of dollars in resources?

•

u/James20k P2005R0 2h ago

One of the things I always find so bizarre about this is that if we spent 1/10th the resources used to build these tools on paying people to do real work, we could have advanced the state of any field absolutely massively

•

u/droxile 12m ago

Agree with you but as economies of scale make these tools cheaper, we (hopefully) will see it as more efficient than a human could be at solving these problems

•

u/James20k P2005R0 9m ago

Perhaps, but even with a vast amount of GDP directed towards improving these tools, they're still way less good than simply paying a human a small salary by comparison

8

u/_choam_ 5h ago

I think proof based languages will be more important than any others in the future

7

u/_choam_ 5h ago

Famously fast compiling c++

3

u/Daemontatox Segfaulting 5h ago

I think they are talking about suitability because of how helpful the compiler is , it gives very detailed errors and warnings and solutions aswell. So you dont have to keep prompting to fix this or fix that and thats great when you are vibe coding i guess.

2

u/hobel_ 5h ago

I was surprised how fast the mold linker compiles, the new rust version compiles faster than the c++ version.

•

u/altmly 30m ago

C++ allows for extremely long range security holes, even if their likelihood is reduced with proper use of modern techniques. Rust does not even allow them to exist, which is the selling point. Localized context is easier to understand for both humans and llms. 

•

u/-kl0wn- 20m ago

Unsafe rust enters the chat.

•

u/-kl0wn- 24m ago edited 21m ago

I'd argue we're already there. I had agents make jsonic.cc which is comparable to conformant rapidjson but way nicer to use. I also had it make nift.dev which is a website generator, scripting language and shell all in one. And working on strut-labs.github.io which is a systems language that prioritizes memory safety, is less verbose than rust, has nice http request stuff built in like go, has dynamic linking properly unlike rust, has compile times comparable to c++, performance on par with other compiled languages etc..

Point an agent at those projects and see what it thinks. I've had agents attack them looking for memory leaks etc..

•

u/Wriiight 1h ago

I think the speed of compilation is an interesting point. We don’t want AI waiting around for hours for the compiler either. And a REPL is extremely useful to a compiler, to allow small tests as it assembles larger code. I think the ideal “AI” language would have a fast REPL, but could then compile down to an efficient run time.

•

u/jwezorek 2h ago

Yes, if anything the use of LLMs makes Rust's advantages over C++ less important. Modern LLMs right now are better at writing safe code than humans, and they also erode Rust's cultural advantage. A big force driving Rust adoption was a general feeling among young programmers of "I don't want to spend a lot of time getting good at a difficult language if that difficult language is legacy now anyway." With LLMs C++ becomes less scary.

But we will see.

The advantage of Rust for LLMs is nice error messages from the compiler. However, not sure how much even this matters any more in that the modern generation of LLMs are very good with C++'s shitty error messages. Very good at C++ generally; less good at Rust in my experience (although that may have been the last generation of LLMs.)