Remix.run Logo
steveklabnik 9 hours ago

One thing that I'm curious about regarding all of this: I thought all of this stuff landed in C++26, yet we are still getting papers like https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2026/p43...

> The C++26 draft has not yet had its final ballot

This is co-authored by Bjarne, and so I'm sure it's not trivially false, but maybe I am just missing some detail. I know Bjarne was threatening to cast a veto of C++26 over this, but I thought he did not?

Anyone who follows the process a bit more than me have some context here?

whateverboat 8 hours ago | parent | next [-]

The current state of C++ next is maintained in what is called the C++ draft.

People (from the committee of experts appointed as national body representatives or invited experts) submit proposals which is essentially merge requests to make changes to the C++ draft. A proposal, by the way of it's changes, can either add a feature to C++ or remove features from C++ (kind of like deleted code).

In each C++ meeting, they have a vote for each proposal in the meeting and decide whether that proposal is allowed to act on the C++, thereby determining if the features gets in the draft (if the proposal was proposing a feature) or if the features is kicked out of the draft (if the proposal was advocating for removal of a feature).

Once a proposal has been voted in the draft, only another proposal can remove that feature from the draft.

Every 3 years, they seal the current state of the draft into a standard and send it for voting to the official ISO C++ committee of national bodies (different from committee of experts we mentioned above). And I think each national body has a veto. (that is the vote has to be unanimous, but not sure here).

At this point, first the National bodies can make comments where they can threaten to veto the standard if their comment is not looked at. Then, the committee of experts can either respond to the comment or follow the comment or do whatever.

The official committee (essentially national body members) then votes and can only approve or reject the standard in the whole. So, if they reject of example C++ next now, there will be no C++26.

The whole process from sealing to actual voting takes around a year or so. In the mean time the committee of experts starts working on the next c++ standard from the sealed state forward without waiting for the committee to ratify the current one.

What Bjarne is doing is that he was threatening to get a national body to veto the proposal so that there is no C++26 at all. So, his point was, either accept his paper as it is (which calls for removal of contracts from the C++ draft before it goes to committee of national bodies), or he probably gets US or Denmark or some NB (not sure which) to vote no on the C++ standard (when it eventually goes to the committee of national bodies with the contracts in it, kind of like throwing baby with the bathwater).

r0ze-at-hn 6 hours ago | parent | next [-]

I recently watched the c++ documentary and it was super sobering in how it mirrors this description of the process. https://herbsutter.com/2026/06/04/c-the-documentary-released...

The true goal of C++ is the self-preservation and funding of the ISO Committee specification “engine”, while compilers are merely an accidental by-product.

Once you see this then suddenly a lot of odd behavior makes sense. For example the committee can’t break ABI because then the old companies wouldn’t fund the new c++ standard, but would fund a committee that maintains/forks the old thing. The complexity / bureaucracy also provides jobs for those involved in many ways including writing new books every year and or consulting.

While end consumers might really care about compile speed, modularization, security, and all of the things modern languages give, that is secondary to keeping the committee alive.

Younger me would be like, oh no this is horrible someone will fix this! Older me is more sober and understands that once a system is up and running it will continue as is (this being an example of Pournelle’s Iron Law of Bureaucracy). Security by the way of migrations to Rust is causing what the committee sees as the first real threat to its existence as its patrons start adopting more and more Rust. As a result the committee is proposing to break compatibility as a means to keep them around just a little longer. Note: Actually fixing the security issues is not important only giving enough for sponsors to not leave so we will see what actually happens.

Guvante 2 hours ago | parent | next [-]

You paint the sponsors in an unnecessarily negative light here.

They want to fund code they will use and that requires updating versions to be doable for like a million not twenty million.

Everyone loses site of the massive sizes of the codebases involved. When your codebase is measured in millions LoC minor breaks can be devastating.

Minor steps are fine and appreciated but "rip off the bandaid" is better left to alternative projects like Rust.

kmeisthax 4 hours ago | parent | prev | next [-]

Between how long it took us to get standard library hardening in C++ and seeing what ISO did to the co-founder of MPEG, I'm convinced ISO is fundamentally incapable of actually being responsive to stakeholders, specifically because of the insane national body vetocracy.

For context, under Leonardo Chiariglione's stewardship, MPEG attempted to ship a royalty-free codec called Internet Video Coding (IVC) and it was immediately torpedoed by Samsung claiming ownership. In any sane environment you would amend the standard to remove the claimed technology, but ISO specifically does not allow you to do this. There is no obligation for an ISO participant to identify the patents being claimed unless they refuse to offer a license on FRAND terms. Ergo, Samsung just said "we own this and will sell licenses for money", and IVC was dead in the water as a standard[0].

Leonardo attempted to bring this to the attention of ISO, but the actual formal process for this was blocked by... you guessed it, a national body vetoing it. So the patent policy that prohibits ISO from distinguishing between royalty-free and royalty-bearing codecs stayed. Oh, and then they cut MPEG up into six pieces so Leonardo would have nothing to run anymore.

C++ was an unusual language in that, for about 10-15 years, the only other competing systems programming language was C - another ISO standard, and the one C++ was originally based off of. The standard answer to "but I want memory safety" was "use a garbage collector"[1]. I distinctly remember hearing interviews with compiler developers talking about how adding even these basic features to C++ would be interminably painful, because you'd inevitably have to debug some deeply nested macro in a library somewhere, so shut up and just enjoy that we gave you Vector<T>.at().

The day Rust becomes an ISO standard is the day it becomes dead to me.

[0] IVC was specifically designed to be inferior to the royalty-bearing H.265 standard, as Leonardo himself wanted to keep the royalty-free codecs second-tier.

[1] To be clear, there was research into non-GC languages with memory safety - that's where Rust got its ideas from - but it was a very small niche until Mozilla put their feet down and gave legitimacy to something.

Xirdus 3 hours ago | parent [-]

Re: [1] - correct me if I'm wrong, but from what I remember, Rust originally did have GC and relied on it for safety, but as development went on, they added more static checks and eventually, very late into pre-alpha phase, realized they don't actually depend on GC anymore and can cut it out? As in, Rust wasn't part of the non-GC safety research at all, it just happened organically?

3 hours ago | parent | next [-]
[deleted]
kmeisthax 2 hours ago | parent | prev [-]

Yes, but at this point the critical piece that made no-GC memory safety possible - linear types - had already been researched and known in the FP community. Rust's critical invention was "what if we modeled heap ownership and borrowing with linear types".

Okay, strictly speaking, Rust types are affine, not linear. Leaking Rust values is a safe operation. In a linear Rust the compiler would have to prove all values do not leak, but this would be incredibly difficult and probably make reference counting illegal.

Xirdus an hour ago | parent [-]

Yeah, this makes sense. Although all this affine type stuff was also the basis for the C++ move semantics (although the resulting type system isn't affine at all, the mental model is very much that, with deleted copy constructors and all), which predates Rust project by at least a few years. So by the time Rust 1.0 rolled out, it wasn't a new concept at all even in system programming circles.

The actually innovative thing about Rust is how they made object lifetimes into a H-M-esque type system and used this 50 year old algorithm to detect dangling pointers at compile time.

steveklabnik an hour ago | parent [-]

To further this, "destructive move" as C++ calls it almost happened, but ended up not. So it almost had it the same way as Rust too.

4 hours ago | parent | prev [-]
[deleted]
steveklabnik 8 hours ago | parent | prev | next [-]

Thanks for this! I vaguely knew most of it but it's great to hear more details.

I think that my misunderstanding here is because I thought that the vote in Croydon back in March was the last chance to veto things, but re-reading https://herbsutter.com/2026/03/29/c26-is-done-trip-report-ma...

> are now producing the final document to be sent out for its international approval ballot

So yeah, I guess in most cases this final ballot is a rubber stamp (not a bad thing, actually, I'd argue it's the way it should be) but maybe this time it is not.

whateverboat 8 hours ago | parent [-]

Yeah, Croydon was the deadline according to the committee's internal process on changing the draft before it is sent for ballot (rubber stamped as you said typically). What Bjarne is asking for is: 1. either an exception to the c++ committee's internal rule about changing the draft after the definitive meeting (in this case croydon) 2. or veto in the national ballot as you said.

By the way, didn't realise when I answered this that I was answering to you. Thanks for all the work on Rust! Your views on Rust and C++ are both much appreciated.

steveklabnik 6 hours ago | parent [-]

You're welcome!

Just to be extra clear about it, while there's clearly some dysfunction going on in WG21, I don't think Rust's process is free of it either. I do think there's a lot of pros to the way Rust does things, but this stuff is just very hard, in general.

I wish I had actually written "The elephant in the room" back when the safe c++/profiles stuff was going on, but I never actually did. Oh well. Probably wouldn't have changed much anyway.

MFHava 6 hours ago | parent | prev | next [-]

> And I think each national body has a veto. (that is the vote has to be unanimous, but not sure here).

No veto. Every P-member has a vote (abstain/approve/disapprove). Whether C++26 gets published is decided by numerical consensus.

Mond_ 7 hours ago | parent | prev [-]

This does sound a lot like there's a real risk of C++ imploding, in some form or another. (Arguably, it has been in that state for a while now.)

I personally agree that contracts probably shouldn't be in the standard, but this whole situation looks like a mess.

jcranmer 7 hours ago | parent | prev | next [-]

I haven't followed the contracts discussion particularly closely, but my understanding of the situation is this:

Contracts has the problem that everybody has a slightly different idea of what they want from the feature. What exists today in the draft standard is a messy compromise that has a very broad consensus. However, there are few people who are vehemently against the current compromise and are taking every opportunity to try to upset that compromise.

Now on top of that, there is a separate issue in that the C++ standards committee has started to become too aggressive in adopting new features, and implementers are starting to complain about that. Contracts is one of the new features that is in the camp of the-standard-is-moving-too-quickly, but it's far from the only one and probably not the worst offender, given that there is fairly high demand for contracts. (Constexpr-all-the-things is probably the worst offender from a cost/benefit ratio?)

Currently, the C++26 draft is out to the national bodies for balloting, and the vote in the US national body passed by the thinnest of margins. I haven't heard of the results from other national bodies yet.

bluGill 9 hours ago | parent | prev | next [-]

Everybody has their own ideas of what they want from Contracts. C++26 contracts are trying to get a minimal system that everybody can agree on. The current contracts are not good enough for anybody who wants them - but it is good enough that they can start figuring out the details of making all the different factions happy.

C++26 contracts are written by people with experience in ADA/SPARK. While we don't have experience in C++ contracts, there is plenty of experience elsewhere. I find it odd that the paper didn't mention Spark at all!

The criticism that it is experimental in all compilers is a fact that can never be anything else. Chicken and egg - nobody will make this non-experimental until it is in the standard. There have many small scale experienements with contracts - enough to agree we want to use this on a larger scale but we need it in the standard first.

maccard 6 hours ago | parent [-]

> The current contracts are not good enough for anybody who wants them -

This is a recurring pattern across large changes to c++. Modules and coroutines both are great examples of this.

> but it is good enough that they can start figuring out the details of making all the different factions happy.

I don’t think there’s really a plan to make the factions happy, there’s a plan to get X in, say it’s in and then ignore any actual criticism in favor of “it was the best we could do” while pointing at the other groups for not accepting the massive flaws.

MFHava 4 hours ago | parent | next [-]

>> The current contracts are not good enough for anybody who wants them - > This is a recurring pattern across large changes to c++. Modules and coroutines both are great examples of this.

Coroutines are ready since C++20, there is some stuff missing in the language (`for co_await` being the most obvious thing), but the feature is useful as is...

bluGill 6 hours ago | parent | prev [-]

The only complaints I've heard about modules that is real is it took some time to be ready. Everything to use is from people who don't use C++ and want to pick on it.

maccard 2 hours ago | parent [-]

I’ve written c++ every day for the last 15 years. The problem with modules is they’re the meeting point of a pile of decisions (or lack of). Modules have been talked about for longer than I have been programming and I still don’t know of a project that is using them that has seen a compile time improvement.

You might argue that modules aren’t the solution to compile times, but for a very long time they were. Now they’re a better way to structure code, except they’re not really backwards compatible. That dorsnt matter because the committee doesn’t consider that bit at the same time refuses other changes that may have similar impacts.

I think c++ is caught between a rock and a hard place. There’s a group that wants only existing behaviours standardised, and another that wants the language to be a force that brings the ecosystem with it. What we get is the latter group proposing changes that look like progress, but no (or limited) real change happening due to the first group, while the first group are forced to have the language change almost for the sake of it to placate the latter group.

RicardoLuis0 8 hours ago | parent | prev | next [-]

bjarne/hsutter and their whole "club" have been (from my admittedly outsider perspective) using the "founding principles" in bad faith in the c++ comittee for a while now, see the strong-arming of safety profiles into the standard while they are in no way workable or anything more than a half-useless solution to anything they claim to solve https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2024/p34... / https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2024/p34... / https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2025/p36...

fg137 5 hours ago | parent [-]

[dead]

scott_s 8 hours ago | parent | prev | next [-]

I have not been following, but some searching lead me to the conclusion that contracts are currently in the draft, but Stroustrup and some others are loudly saying that is a mistake. See: https://wrocpp.github.io/posts/contracts-dispute/

8 hours ago | parent | prev | next [-]
[deleted]
reisse 3 hours ago | parent | prev [-]

Off-topic: oh wow the most of the Appendix part looks Claude verbatim. Not something I'd expect in a paper from Stroustrup.