As part of the collaboration between Canonical and the University of Bristol, the project will target AppArmor and snap-confine as industrial case studies. Both are critical to Ubuntu’s security posture, and provide a substantially harder test than isolated translation examples. They will help us evaluate whether the techniques can cope with the structure and constraints of mature production software.
Note that this is not a commitment to replace AppArmor or snap-confine with what is generated, rather that we have a vested interest in the software and are keen to see the results.
The most optimistic outcome would be a system capable of translating substantial C repositories into Rust with strong evidence of behavioural equivalence and relatively little manual intervention. The research could also produce better methods for decomposing repositories, stronger validation techniques, reusable translation datasets, improved program-repair tools and a more precise understanding of where automated migration stops being reliable.



This is a bit of a tangent, so I didn’t include it in the above comment, but I don’t think “open source” is sufficiently anti-capitalist, so the (A)GPL was never going to save us to begin with. “Open source”, as defined by the OSI (a.k.a. a handful of megacorps in a trench coat) and the FSF, prevent “discrimination of use”. So if you want your software to be “open source” or “free software”, you have to accept that your software can be used by for-profit entities to exploit your labor, and potentially to perform heinous acts, such as military or surveillance usage. What we currently call “copyleft” is actually just copylib 😭
No open source license, not even the (A)GPL, allows you to forbid this. Unfortunately, I don’t see an alternative framework being widely adopted anytime soon. It seems that the best you can do for now is use niche licenses like this and just accept that your software can’t be considered “open source” :/