Workflow
内存安全
icon
Search documents
从安全内核到可用系统:星绽NixOS发行版发布,加速OS行业向Rust迁移
Huan Qiu Wang· 2025-12-26 09:01
星绽NixOS继承了NixOS的一大优势——"系统状态稳定复刻"。星绽NixOS支持开发者只需写出软件、 服务及配置的需求,系统就能按要求自动构建,并实现同一份需求在不同机器、不同时间重复执行,得 到的结果高度一致,且系统每个建设步骤均可追溯、可复查,从而显著降低发行版在集成、测试和交付 时的偶发问题与不确定性。 更重要的是,星绽NixOS融合了该老牌Linux系统丰富的软件生态——NixOS拥有超过12万的软件包与选 项,为桌面和服务器等场景提供成熟生态底座。由此,星绽NixOS避免了从零开始的软件包生态搭建过 程,把星绽内核快速带入到一个可安装体验的成熟系统形态。而让更多真实应用与服务更早地跑起来, 也有助于在真实、可对比的实践环境中对星绽的Linux兼容性与工程成熟度进行迭代,并以此加速促进 社区共建。 "今天的热点不再是'有没有Rust内核',而是'Rust内核能否以发行版形态进入真实应用负载并可对标评 估'。"北京大学讲席教授、通明湖中心主任谢涛指出,"原生内存安全已成为国际业界的明确趋势。星 绽NixOS通过复用NixOS生态,让星绽在桌面和服务器等场景中夺得先机去建立可复现、可比较的基 线,让星 ...
“我们要彻底告别C++”,微软启动代码史上最大“拆迁”:Windows、Azure将用Rust重写
3 6 Ke· 2025-12-23 09:42
微软正在推动一项可能重塑整个软件工程史的长期工程:在 2030 年结束前,彻底消除其核心代码库中的 C 和 C++ 代码,并全面迁移至 Rust 语言。这一 目标不仅涉及 Windows、Azure 等关键基础设施,也意味着对全球规模最大的商业代码资产之一进行系统性重构。 1 微软工程师发帖称 2030 年前彻底淘汰 C/C++ 根据 LinkedIn 上的个人介绍,Hunt 长期从事系统软件与操作系统方向的研究与工程实践,目前的研究重点集中在 将大型语言模型(LLM)引入系统软件 领域,以解决长期存在的复杂工程难题。 在微软期间,他创立并领导了 Azure Sphere 的开发团队。Azure Sphere 是微软面向物联网和嵌入式设备推出的端到端安全平台,旨在使任何设备制造商 都能够构建高度安全的设备。该平台系统性覆盖了微软提出的"高度安全设备的七项核心属性",成为微软在设备安全领域的重要基础设施之一。 这一目标并非来自外界猜测,而是微软内部核心工程负责人亲自对外公开表达的战略愿景。 近日,微软杰出工程师(Distinguished Engineer)Galen Hunt 在 LinkedIn 上发布的一 ...
用了 Rust,谷歌实测安卓内存漏洞率比 C/C++ 低 1000 倍!
程序员的那些事· 2025-11-16 10:14
Core Insights - Rust has become a controversial programming language, with government agencies in the U.S. advocating for its adoption over C/C++ due to its memory safety features, while some developers express skepticism about its complexity and perceived overhype [1][2]. Group 1: Rust's Impact on Android Security - Memory safety vulnerabilities in Android have dropped below 20% for the first time, according to Google's 2025 data [2]. - Rust has reduced the density of memory safety vulnerabilities by 1000 times compared to existing C/C++ code in Android [4]. - The introduction of Rust has not only improved security but also enhanced software delivery efficiency, with rollback rates decreasing by 4 times and code review times reduced by 25% [4][15]. Group 2: Adoption and Trends - Since 2021, Google has been integrating Rust into the Android system as a safer alternative to C/C++ [5]. - The usage of Rust is rapidly increasing, while new C++ code is declining [6]. - Rust's new code volume is now comparable to that of C++, indicating similar development efficiency [9]. Group 3: Performance Metrics - Google utilized the DORA framework to assess performance, focusing on throughput and stability [10]. - Rust code requires approximately 20% fewer modifications than C++ code of similar scale [11]. - Rust's rollback rate is about one-fourth that of C++ in medium to large changes, indicating higher stability [18]. Group 4: Broader Applications of Rust - Google is expanding Rust's use in various areas, including system services, libraries, and applications, due to its safety and productivity advantages [22]. - Specific implementations include Nearby Presence for Bluetooth device discovery, RCS security messaging, and various parsers in Chromium [23]. Group 5: Addressing Concerns and Future Outlook - Google acknowledges that while Rust does not guarantee zero vulnerabilities, it significantly reduces vulnerability density, estimating 0.2 vulnerabilities per million lines of Rust code compared to 1000 per million lines of C/C++ [32][33]. - The company believes that Rust allows for a balance between speed and safety, potentially restoring performance and productivity previously sacrificed for security [37][38].
吴说每日精选加密新闻 - 美国 2025 年非农就业基准变动初值 -91.1 万人,预期 -70 万人
Xin Lang Cai Jing· 2025-09-10 14:24
Group 1 - The initial value of the U.S. non-farm employment benchmark change for 2025 is -911,000, which is worse than the expected -700,000 and the previous value of -598,000, leading traders to anticipate a rate cut by the Federal Reserve [1] - The U.S. Producer Price Index (PPI) for August shows a year-on-year rate of 2.6%, the lowest since June, compared to an expected 3.3% and a previous value of 3.3%, with a month-on-month rate of -0.1% against an expectation of 0.3% [2] - The SEC has postponed the decision on Bitwise Dogecoin ETF and Grayscale Hedera ETF until November 12, with a total of 31 altcoin spot ETF applications and 92 crypto ETF products pending as of 2025 [3] Group 2 - SOL Strategies has officially listed on NASDAQ under the ticker STKE, holding 435,064 SOL valued at approximately $94.25 million [4] - The co-founder of Cobo, Shen Yu, stated that the iPhone 17's upgrade enhances the security of wallet signatures and Passkeys through hardware-level memory safety technology [5] - Vietnam has launched a five-year pilot program for cryptocurrency trading, allowing only local platforms and mandating transactions in Vietnamese Dong, with foreign investors allowed but limited to 49% ownership [6]
Rust 天花板级大神公开发帖找工作:3000 次核心提交,不敌 “会调 OpenAI API、用 Cursor”?
AI前线· 2025-09-06 05:33
Core Viewpoint - The Rust community is facing challenges as two prominent contributors, Nicholas Nethercote and Michael Goulet, publicly seek new job opportunities due to budget cuts at their current organization, Futurewei, which reflects a broader trend of resources being diverted towards AI projects, leaving foundational projects like Rust underfunded [2][9][11]. Group 1: Contributors' Background - Nicholas Nethercote is a key contributor to the Rust project and has a notable background, including a PhD from Cambridge and co-authorship of the Valgrind tool, which is essential for memory debugging and performance analysis [4][5]. - He has made significant contributions to the Rust compiler, with over 3,375 commits, and has been instrumental in improving the compiler's performance and maintainability through various technical debt cleanup efforts [5][6]. Group 2: Current Job Search Context - Nethercote's job search is attributed to budget cuts in his team, which has led to a reduction in positions, highlighting the impact of international factors and the shift of attention and funding towards AI [9][11]. - Both Nethercote and Goulet express a desire to continue working within the Rust ecosystem, explicitly avoiding sectors like blockchain and generative AI [13]. Group 3: Industry Implications - The situation underscores a paradox in the tech industry where highly skilled engineers in foundational technologies like Rust are struggling to find opportunities, while demand for AI-related skills surges [15][19]. - The recruitment landscape has shifted, with a focus on AI capabilities overshadowing traditional programming skills, leading to a disconnect between the needs of foundational projects and the current job market [19]. Group 4: Rust's Future and Challenges - The ongoing debate about Rust's potential to replace C continues, with notable figures like Brian Kernighan expressing skepticism about Rust's performance and usability compared to C [21][23]. - The retention of top talent in the Rust community is critical for its future, especially in light of the increasing competition for resources and attention from AI projects [23].