home.social

#riir — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #riir, aggregated by home.social.

  1. Back on my/someone elses bullshit... Jellyfin does not fill me with joy. Can we please #riir?

  2. 🦀 How (and why) we rewrote our production C++ frontend infrastructure in Rust

    While memory-safe languages like Rust offer real benefits, serious cryptographic implementations inevitably rely on unsafe code, assembly, and low-level control, eroding those guarantees. At that point, the added abstraction often increases complexity without meaningfully reducing risk.

    blog.nearlyfreespeech.net/2026

    #cpp #rust #riir

  3. 🦀 How (and why) we rewrote our production C++ frontend infrastructure in Rust

    While memory-safe languages like Rust offer real benefits, serious cryptographic implementations inevitably rely on unsafe code, assembly, and low-level control, eroding those guarantees. At that point, the added abstraction often increases complexity without meaningfully reducing risk.

    blog.nearlyfreespeech.net/2026

    #cpp #rust #riir

  4. Feeling a lot a sense that the first builds need to maximalize adaptability, refactorability. Only after digging in for a bit & building does what we are actually going reveal itself. Optimize for that velocity! Then go back & Rewrite It In Rust! #riir #🦀 On port-ability: bsky.app/profile/jaun...

    RE: https://bsky.app/profile/did:plc:zjbq26wybii5ojoypkso2mso/post/3mjur7xzzts2j

  5. I've recently been rewriting my substitution-tiling transducers code in #RustLang, replacing the old Sage code.

    One reason is that Sage is harder to run these days. It vanished from Ubuntu some time between 22.04 and 24.04 and hasn't (yet?) come back.

    Another reason was that reimplementing all my algorithms from scratch was a valuable exercise in making sure I understood them, when I wrote them up for my arXiv preprint. (Which I'm hoping to produce an improved edition of at some point, filling in some gaps.)

    But the third reason is shown in these pictures. The hexagonal one is straight from one of my blog posts, showing the centre of one of the 6-way 'singular' instances of the Spectre tiling. It takes my Sage code 2 minutes in total to generate that SVG.

    The second image is the result of the Rust version of the code working for the same 2 minutes. The hexagon marked in the middle shows the boundary of what the Sage code had calculated. Much faster!

    #TilingTuesday #RiiR

  6. I've recently been rewriting my substitution-tiling transducers code in #RustLang, replacing the old Sage code.

    One reason is that Sage is harder to run these days. It vanished from Ubuntu some time between 22.04 and 24.04 and hasn't (yet?) come back.

    Another reason was that reimplementing all my algorithms from scratch was a valuable exercise in making sure I understood them, when I wrote them up for my arXiv preprint. (Which I'm hoping to produce an improved edition of at some point, filling in some gaps.)

    But the third reason is shown in these pictures. The hexagonal one is straight from one of my blog posts, showing the centre of one of the 6-way 'singular' instances of the Spectre tiling. It takes my Sage code 2 minutes in total to generate that SVG.

    The second image is the result of the Rust version of the code working for the same 2 minutes. The hexagon marked in the middle shows the boundary of what the Sage code had calculated. Much faster!

    #TilingTuesday #RiiR

  7. A port on open only to one process. Can namespaces help me?

    Let's find out.

    The idea is to MitM between my IMAP server and Claws Mail. The proxy would ignore the password and instead use with a client to authenticate me (mTLS style).

    This way, there's one less to store in RAM and accidentally exfiltrate.

    As much as I like the Claws UI, it's crashy and I don't trust its a lot. anyone :P?

  8. A port on #localhost open only to one process. Can #linux #network namespaces help me?

    Let's find out.

    The idea is to MitM between my IMAP server and Claws Mail. The proxy would ignore the password and instead use #TLS with a client #certificate to authenticate me (mTLS style).

    This way, there's one less #password to store in RAM and accidentally exfiltrate.

    As much as I like the Claws UI, it's crashy and I don't trust its #security a lot. #RiiR anyone :P?

    #email #networking #dovecot

  9. here's an idea for the #RIIR crowd: #X11, for those use-cases where #wayland fails utterly. more useful than rewriting cat and ls in rust...

  10. CPython core developers are considering introducing Rust to the codebase. A lot of them are in favor, including Guido.

    “Rust will initially only be allowed for writing optional extension modules, but eventually will become a required dependency of CPython and allowed to be used throughout the CPython code base.”

    discuss.python.org/t/pre-pep-r

    #rustlang #python #riir

  11. CPython core developers are considering introducing Rust to the codebase. A lot of them are in favor, including Guido.

    “Rust will initially only be allowed for writing optional extension modules, but eventually will become a required dependency of CPython and allowed to be used throughout the CPython code base.”

    discuss.python.org/t/pre-pep-r

    #rustlang #python #riir

  12. Android team at Google posted another update of their use of Rust as a replacement for C and C++.

    Switching to Rust for writing performance sensitive and low level code allowed them to reduce memory safety vulnerabilities from ~70% to below 20% of total vulnerabilities for the first time.

    Notable quotes:

    "We adopted Rust for its security and are seeing a 1000x reduction in memory safety vulnerability density compared to Android’s C and C++ code. But the biggest surprise was Rust's impact on software delivery. With Rust changes having a 4x lower rollback rate and spending 25% less time in code review, the safer path is now also the faster one."

    "For medium and large changes, the rollback rate of Rust changes in Android is ~4x lower than C++. This low rollback rate doesn't just indicate stability; it actively improves overall development throughput. Rollbacks are highly disruptive to productivity, introducing organizational friction and mobilizing resources far beyond the developer who submitted the faulty change. Rollbacks necessitate rework and more code reviews, can also lead to build respins, postmortems, and blockage of other teams. Resulting postmortems often introduce new safeguards that add even more development overhead."

    "In a self-reported survey from 2022, Google software engineers reported that Rust is both easier to review and more likely to be correct. The hard data on rollback rates and review times validates those impressions."

    "With roughly 5 million lines of Rust in the Android platform and one potential memory safety vulnerability found (and fixed pre-release), our estimated vulnerability density for Rust is 0.2 vuln per 1 million lines (MLOC)."

    "Our historical data for C and C++ shows a density of closer to 1,000 memory safety vulnerabilities per MLOC. Our Rust code is currently tracking at a density orders of magnitude lower: a more than 1000x reduction."

    Do read the whole blog post. It's very informative.

    security.googleblog.com/2025/1

    #rustlang #android #google #riir

  13. Android team at Google posted another update of their use of Rust as a replacement for C and C++.

    Switching to Rust for writing performance sensitive and low level code allowed them to reduce memory safety vulnerabilities from ~70% to below 20% of total vulnerabilities for the first time.

    Notable quotes:

    "We adopted Rust for its security and are seeing a 1000x reduction in memory safety vulnerability density compared to Android’s C and C++ code. But the biggest surprise was Rust's impact on software delivery. With Rust changes having a 4x lower rollback rate and spending 25% less time in code review, the safer path is now also the faster one."

    "For medium and large changes, the rollback rate of Rust changes in Android is ~4x lower than C++. This low rollback rate doesn't just indicate stability; it actively improves overall development throughput. Rollbacks are highly disruptive to productivity, introducing organizational friction and mobilizing resources far beyond the developer who submitted the faulty change. Rollbacks necessitate rework and more code reviews, can also lead to build respins, postmortems, and blockage of other teams. Resulting postmortems often introduce new safeguards that add even more development overhead."

    "In a self-reported survey from 2022, Google software engineers reported that Rust is both easier to review and more likely to be correct. The hard data on rollback rates and review times validates those impressions."

    "With roughly 5 million lines of Rust in the Android platform and one potential memory safety vulnerability found (and fixed pre-release), our estimated vulnerability density for Rust is 0.2 vuln per 1 million lines (MLOC)."

    "Our historical data for C and C++ shows a density of closer to 1,000 memory safety vulnerabilities per MLOC. Our Rust code is currently tracking at a density orders of magnitude lower: a more than 1000x reduction."

    Do read the whole blog post. It's very informative.

    security.googleblog.com/2025/1

    #rustlang #android #google #riir

  14. @wyatt I've seen others interpret it as rav1d offering a $20,000 bug bounty for dav1d, the C decoder. If you find exploitable undefined behavior that the dav1d devs have to spend 5% of CPU time to prevent, you win.

    #rav1d #dav1d #av1 #BugBounty #UndefinedBehavior #riir #rustlang

  15. @wyatt I've seen others interpret it as rav1d offering a $20,000 bug bounty for dav1d, the C decoder. If you find exploitable undefined behavior that the dav1d devs have to spend 5% of CPU time to prevent, you win.

    #rav1d #dav1d #av1 #BugBounty #UndefinedBehavior #riir #rustlang

  16. sudo-rs might become the default in future Ubuntu releases!

    The details from Ubuntu VP of Engineering Jon Seager: discourse.ubuntu.com/t/careful

    Our team, Marc, Bjorn, Ruben and Marlon are core contributors of sudo-rs, which is now part of Trifecta Tech Foundation, the non-profit backed by Tweede golf and the long-term home for open infrastructure projects such as sudo-rs, zlib-rs and Pendulum.

    @jnsgruk
    @trifectatech

  17. sudo-rs might become the default in future Ubuntu releases!

    The details from Ubuntu VP of Engineering Jon Seager: discourse.ubuntu.com/t/careful

    Our team, Marc, Bjorn, Ruben and Marlon are core contributors of sudo-rs, which is now part of Trifecta Tech Foundation, the non-profit backed by Tweede golf and the long-term home for open infrastructure projects such as sudo-rs, zlib-rs and Pendulum.

    @jnsgruk
    @trifectatech

    #rustlang #riir

  18. @atoponce holymoly, i just had a look at github.com/uutils/coreutils/bl

    this thing has 419 dependencies! maybe irrelevant mem-safety benefits are not in balance with the consequences of this kind of supply-chain attack surface? maybe we should have a talk about this?

    #uutils #rust #riir

  19. @atoponce holymoly, i just had a look at github.com/uutils/coreutils/bl

    this thing has 419 dependencies! maybe irrelevant mem-safety benefits are not in balance with the consequences of this kind of supply-chain attack surface? maybe we should have a talk about this?

    #uutils #rust #riir

  20. and I thought one couldn't improve upon #cat github.com/sharkdp/bat (available in #Debian as "bat", which was surprisingly not taken yet!) #riir #rust

  21. and I thought one couldn't improve upon #cat github.com/sharkdp/bat (available in #Debian as "bat", which was surprisingly not taken yet!) #riir #rust

  22. This week in #FDroid (TWIF) is live:

    - the faster you test 1.22.0 the faster the #MaterialDesign3 UI update is released. Do.Your.Part!
    - #DeltaChat and ArcaneChat tell stories about #RIIR
    - #emacs is more complete
    - #CLT2025 sched app is live
    - monitor your #BTC mempool

    And 100 more apps in the news at f-droid.org/2025/02/20/twif.ht

  23. This week in #FDroid (TWIF) is live:

    - the faster you test 1.22.0 the faster the #MaterialDesign3 UI update is released. Do.Your.Part!
    - #DeltaChat and ArcaneChat tell stories about #RIIR
    - #emacs is more complete
    - #CLT2025 sched app is live
    - monitor your #BTC mempool

    And 100 more apps in the news at f-droid.org/2025/02/20/twif.ht

  24. It still shocks me that no one has #RIIR the homebrew yet. The slowest package/dependency manager/tool these days (no parallel casks downloading, no multi-threads downloading, and no parallel attestation verification).

  25. It still shocks me that no one has #RIIR the homebrew yet. The slowest package/dependency manager/tool these days (no parallel casks downloading, no multi-threads downloading, and no parallel attestation verification).

  26. I’ve fallen to the Rewrite It In (#RIIR ) movement. I’m currently rewriting my internal API (which only I use and performs absolutely fine) to move from Python + Flask to Rust + Axum because I wanted better performance.

  27. CW: fish-shell 4b has been RIIR'd; I like

    My favourite shell[0] has been rewritten in rust. That must have been a massive amount of work!

    They helpfully provide a PPA[1], so installing was easy.

    As per their blog post[2], everything continues to work.

    --

    [0]: fishshell.com
    [1]: sudo add-apt-repository ppa:fish-shell/beta-4; sudo apt install fish
    [2]: fishshell.com/blog/fish-4b/

    #fish #fishshell #rust #shell #RIIR

  28. CW: fish-shell 4b has been RIIR'd; I like

    My favourite shell[0] has been rewritten in rust. That must have been a massive amount of work!

    They helpfully provide a PPA[1], so installing was easy.

    As per their blog post[2], everything continues to work.

    --

    [0]: fishshell.com
    [1]: sudo add-apt-repository ppa:fish-shell/beta-4; sudo apt install fish
    [2]: fishshell.com/blog/fish-4b/

    #fish #fishshell #rust #shell #RIIR

  29. Now that looks better... there _is_ an open source tool for the K230 after all that runs on Linux, just not mentioned in the docs.

    github.com/kendryte/k230_flash

    Let's #RiiR! (it's written in C++ and does not fit my needs)