3 ms·
For many uses this is already happening, but for writing an OS, there's no getting around the fact that you're going to need to, say, write to or read from a sp
by apendleton 9y ago
For many uses this is already happening, but for writing an OS, there's no getting around the fact that you're going to need to, say, write to or read from a specific hard-coded memory address that, for a given platform, is magically mapped to a hardware register. That's always going to be unsafe. Certainly, though, Rust lets you sequester that kind of code away and isolate it from things that can be expressed safely.
- nickpsecurity 9y agoI'll add that there's already tooling in Frama-C, SPARK Ada, and some proof assistants to prove safety of some of those operations. So, if they can't be safe, then a mock-up of them can be done in something that can prove their safety externally with proven component integrated into Rust. Eventually Rust itself might have such a capability but the external tools can work intermediate.