Opinions of Greg Crow-Hartman and Case Cook on promoting Rust into the Linux kernel

Greg Kroah-Hartman, responsible for maintaining the stable branch of the Linux kernel, has expressed support for developing new kernel components in Rust. As someone through whom all information about bugs and vulnerabilities in the Linux kernel has passed for the last 15 years, he claims that most kernel errors are caused by unconsidered features of the C language (corner case) that are completely excluded in Rust code.

Using Rust will leave behind problems like accessing memory after it has been freed, partial buffer overflows, incorrect resource deallocation during error handling, and forgotten checks for returned error codes. This will allow maintainers to focus on real issues like race conditions and logic problems, rather than getting distracted by trivialities during reviews.

Existing old code in C will remain as it is, but for new code and new drivers, the introduction of Rust will significantly improve quality. The adoption of Rust will also enable the structuring of internal kernel APIs in such a way that errors in using the internal API will be practically eliminated — the kernel has accumulated too many complex and convoluted APIs, which create a substantial burden on maintainers in ensuring that these APIs are used correctly. As Rust bindings evolve, maintainers will have the opportunity to rethink and streamline the APIs, benefiting everyone, including those using C.

Greg does not consider Rust a "silver bullet" that will solve all problems in the kernel, but this language will certainly help in numerous situations. The support for Rust will also meet the needs of driver developers who hope to have a tool that allows them to write code for their hardware while excluding many types of errors. Regarding the mixing of multiple languages, Greg does not see a significant problem; in his opinion, kernel developers have handled more serious challenges in the past, and there is no reason to reject the promotion of new good ideas into the kernel that will help ensure the project's success for the next 20+ years.

Kees Cook, former chief system administrator of kernel.org and leader of the Ubuntu Security Team, also joined the discussion. Kees clarified that this is not about rewriting existing code in the kernel, but about providing the ability to use Rust to create new drivers and subsystems. Utilizing Rust for new code will not only reduce memory-related errors but will also shorten development time. The speed of development increases due to reduced debugging efforts and strict guarantees in the language that allow for error detection at an early stage of coding, even before product testing begins.

The effectiveness of the tactic of using Rust to improve the quality of new code has already been demonstrated by Google in the Android platform. It has been shown that the main source of security problems is new code, and improving its quality should be given primary attention. For older code, there is an exponential relationship between security and age (for example, code that is 5 years old has an average vulnerability density that is 3.4 times lower than that of new code).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster