10 comments

  • lrvick 21 minutes ago
    The linux distribution I co-maintain uses mold as our bootstrap linker to bootstrap rust itself, and it saved us -hours- on long version-by-version build chains. Mold being in c meant we could build it very early and use it as the default linker distro wide and enjoy build speedups everywhere.

    Now sadly we will have to fork and maintain the c version as mold2 forever.

    Rust is not actually the right tool for all problems.

    • nicce 6 minutes ago
      If the need is well justified, maybe there is great chance to ask adding #[no_mangle] and extern C support? Since release is very fresh. If that is causing the problem. Is some dependency as the issue?
    • someonebaggy 18 minutes ago
      That's your choice and your responsibility. You don't get to bind upstream, at least not without paying money. You can't say Rust is a bad solution, just because you developed a bootstrap chain that happens to find useful the fact that mold is written in C.
      • Imustaskforhelp 2 minutes ago
        I do understand what you are trying to say, but I think that this fails to be kind to Irvick and the other maintainers of the stage0 project who are actually being quite underfunded (someone like OAI should fund them in the name of security!)

        So asking them to pay money is well.. not quite the solution.

        What can happen as it often happens, is this, Mold creator created the project, Stage0 found it useful, Mold ports itself to rust, Stage0 now founds it not useful, Stage0 can comment on the new update and be slightly disappointed and comment how they would've preferred to not rust in this particular case for them.

        Yes this doesn't prevent mold from changing to rust or anything as it was shown but I guess we can allow the ability for Irvick to drop a comment I guess without saying that's your responsibility while they are just being maintainers of the open source and an underfunded/mostly volunteer one of work at that.

        Also, @Irvick, stage0 is extremely cool, I hope that a lot more companies sponsor the work that stage0 contributors are doing. I think that it can help the supply-chain issues that the industry is facing at, and is honestly just a really cool idea and I love reading your comments and thank you!

    • DetroitThrow 14 minutes ago
      I'm a bit confused why a decision to decrease the maintenance burden of Mold by switching languages makes Rust the wrong tool here? Fearless concurrency sounds like a huge benefit for what they're doing, given the resources they have.
      • compiler-guy 1 minute ago
        It's simply an ordering problem. When building the entire world from scratch, usually the C and C++ toolchains are built somewhat early, and Rust toolchains built somewhat later. Anything written in Rust must come after that. You need a linker as part of your C++ toolchain, so it must be written in a language ready to go at that point. If it is written in C, you are done. If it is written in Rust you have to wait.

        It's not a big deal for normal users, where you have Rust ready to go. Kind of a bummer in this case, but this is a specialized one.

  • Aissen 1 hour ago
    I expected this to be a multi-months rewrite, not 3 weeks. I almost forgot we live in the agents era now.

    Edit: this seems to have been cooking for a while when the first commit dropped: https://github.com/rui314/mold/commit/f41bfcd5c72ca30cce6498...

  • mi_lk 23 minutes ago
    Damn. I thought Zig would be a perfect rewrite language for Mold since it's a better C in many ways
    • vlovich123 18 minutes ago
      Zig makes you choose either safe or fast, not both. With Rust you can get both (generally).
  • awoimbee 39 minutes ago
    So what differentiates mold from wild now ? Is wild using different data structures?

    (Wild is another fast linker, that only supports Linux)

    • vlovich123 19 minutes ago
      Wild's primary purpose is incremental linking - I guess now the primary difference is a race + subtle differences in performance between projects.
  • uncle_kostya 2 hours ago
    I'm curious about motivation - bounds checks for corrupted inputs seems like it would be one, but it also seems that fixing corrupted input handling in a C/C++ code base would not be too hard, and probably less of an effort? So why did you choose the rewrite?

    And second, did you use any AI tools for the rewrite?

    • fotcorn 1 hour ago
      > fixing corrupted input handling in a C/C++ code base would not be too hard

      The best programmers on the planet have tried and failed with this task for 50 years now, so I don't think this is true.

      The main disadvantage of Rust right now is not supporting some more obscure platforms, but because mold wouldn't support them anyway I don't see that as a problem.

      • embedding-shape 1 hour ago
        > The main disadvantage of Rust right now is not supporting some more obscure platforms

        Last time I checked, I got impressed by the wide platform support, once you go down the tier list (https://doc.rust-lang.org/nightly/rustc/platform-support.htm...). What "obscure platform" specifically are you thinking about, that is currently missing from those lists?

        • fotcorn 1 hour ago
          Just to be clear, I think this is a very small disadvantage. GCC and therefore C/C++ supports some old stuff like SuperH, Intel Itanium, PA-RISC and a bunch of microcontroller archs that LLVM does not.

          However, there is now a Rust codegen plugin for GCC, so even this disadvantage is now basically moot.

          Rewrite all the things!

        • torginus 1 hour ago
          yeah this makes no sense to me. Why would Rust limit the LLVM backend's ability to generate code for a particular platform?
          • panzi 1 hour ago
            I think the claim is that GCC supports a few obscure platforms that LLVM doesn't. Don't ask me which, that is just the claim that I heard multiple times. So it's not Rust that limits platforms, but LLVM. And they say the GCC backend efforts of Rust are meant to deal with that.
            • bkallus 53 minutes ago
              > Don't ask me which

              There are many. Two big ones are Alpha and PA-RISC. NetBSD and Linux continue to support both. Linux distro choices are pretty much limited to Gentoo though.

          • steveklabnik 46 minutes ago
            1. You've got the causality backwards. LLVM backends don't come for free, you have to write code to enable support for them.

            2. LLVM does not support as many backends as GCC does, so even if you did get 100% of the LLVM supported backends up and running, you'd still be missing some.

    • someonebaggy 16 minutes ago
      It's possible to write safe code in C or C++ but it's extremely difficult to read existing code and prove it's safe, without using as much effort as it takes to write it in the first place. This includes the code you wrote last month whose surrounding code has changed. And you have to be right every time while the attacker only needs you to be wrong once.
    • saghm 1 hour ago
      My very naive understanding is that a part of what makes mold fast is concurrency, which I'd expect to be a lot more error-prone in C/C++. Not having to worry about data races might give more confidence with trying out more complex techniques for how to split up work in a way that ends up making things faster
    • pornel 1 hour ago
      I suspect fearless concurrency is another motivating factor. Better perf can be achieved by squeezing more parallelism, but without borrow checking it's difficult to do fine-grained parallelism correctly.
    • LoganDark 2 hours ago
      > And second, did you use any AI tools for the rewrite?

      IMO, given the recent commits: almost certainly.

    • marsven_422 1 hour ago
      [dead]
  • rvz 1 hour ago
    Software X now rewritten in Rust™ is the new sales pitch.
  • acedTrex 1 hour ago
    unfortunate world we live in, the amount of trustable/ethical software is going to near zero.
    • gbin 1 hour ago
      What warrants an off the cuff comment like this? I can take any piece of software and just say a vague statement like that. All of software... What does it even bring to the conversation? Just vague "they"s again we keep on propping up? Who is unethical? The mold team? The AI? The rust foundation? The ASCII character set? The cloud system it has been compiled on? Oh no obviously the backdoors in there?! Oh let us guess!!
      • acedTrex 1 hour ago
        I didn't think it needed to be said... If you need it spelled out the LLM rust rewrite is very clearly what is being referred to.
        • gbin 1 hour ago
          I think it needed to be said because I really don't see why.

          LLM are excellent translation tools. Nothing is learned or stolen from them out of this exercise if this is a copyright issue you are getting at.

          Then Rust? Why picking on it, the language is morally corrupt? In what way? If it were a rewrite in Object Pascal it would be better?

          • DetroitThrow 8 minutes ago
            I personally think object pascal, or perhaps think c, would be a better choice here.

            I will not explain why.

        • germoney 1 hour ago
          Help me get the argument please I might be dense: is the rewrite unethical or the llm use or rust or any of the combinations?
          • hansvm 50 minutes ago
            The usual argument I see goes something like:

            1. There are major obvious flaws

            2. Most of those are obviously LLM-induced, unless there's a new breed of human trained on just the failures of LLMs and not the successes or other relevant information

            3. I therefore assume that the rest of the project is an unverified LLM psychosis without meaningful human review

            That's not the worst thing in the world for all software maybe. I recently found out my apartment complex in their latest AI rewrite generates SMS OTP based purely on the timestamp and ignores passwords, so I can log in as anyone else by knowing their email and having a valid email to grab the current OTP. That's a major security failing, but how bad is it really? I can grab the last-4 of their credit card numbers, pay their rent, see how much other tenants are being screwed, and so on, and only if I know their email addresses (solvable with a tiny bit of social engineering, but let's assume that's also moderately hard). How bad is that really? On the one hand, it's terrifying, since I presume they have the same level of attention to detail with respect to payment methods and PII despite my having opted out of having them stored, but (a) that's all already been exposed via dozens of breaches and is being handled behind the scenes by my bank anyway, and (b) if we examine the immediate blast radius of the known bugs then there's approximately fuck-all an attacker can do with that information.

            For a multi-threaded linker? Come the fuck on. I don't care if it's written in Rust. If you ignore all of the memory ordering intrinsics and `unsafe` then maybe it's more okay, but not having easily available UAF and other memory bugs is very different from actually implementing the correct behaviour, and for a linker where you're explicitly joining together multiple independent binary blobs and choosing what and how to execute on a machine instruction level, Rust's guarantees 100% don't save you from broken, unvalidated "business logic."

            • cleaning 8 minutes ago
              How do you feel about the bun rust rewrite having no major issues, with it being used to run claude code for months now?
        • boxed 1 hour ago
          The fact that it's less C++ and more rust makes it more trustable and more ethical, not less.
          • hansvm 1 hour ago
            /s?
            • someonebaggy 14 minutes ago
              No? Rust code has lower rated of exploitable vulnerabilities than C or C++ code.
    • 478336632929 22 minutes ago
      Cry harder.

      Hope you're posting this from a GNU Hurd system or some other luddite-appoved zeroes and ones. You wouldn't want to be a hypocrite.

      • someonebaggy 13 minutes ago
        Numbered throwaway account means you know this is against the guidelines.
  • asjq178 24 minutes ago
    I don't want a slop linker. Why are people selling out their projects?
    • iTokio 1 minute ago
      This is NOT a slop linker, Mold is a reference in the world of linkers and this port is official.
  • WhereIsTheTruth 17 minutes ago
    It was transpiled, not rewritten, rewrite implies by hand
    • dcre 12 minutes ago
      No it doesn't.