2 ms·
Complaining about the use of unsafe as a “gotcha” is a common canard used by people who often don’t understand what it means. On HN at least, it’s usually not a
by ffdjjjffjj 6y ago
Complaining about the use of unsafe as a “gotcha” is a common canard used by people who often don’t understand what it means. On HN at least, it’s usually not a substantial criticism.
- MaxBarraclough 6y agoMy comment was neither complaining nor criticising, it was asking. I made this perfectly clear in my edit. A program can qualify as pure Rust without making use of the safety advantages of the Rust language. It's not unreasonable to wonder how much unsafe code there is in a Rust codebase. It matters. Rust is better for having unsafe features, but it opens the door to their overuse, and this shouldn't be ignored. In the SPARK Ada world, there are 'assurance levels' that offer different levels of guarantees. [0] At the 'Silver' level and above, there is a guaranteed absence of runtime errors (such as divide-by-zero, or out-of-bounds array access). Rust doesn't have such a scheme. It seems reasonable to wonder about overuse of unsafe features (as fuzzy as that is), as a very rough approximation. [0] https://blog.adacore.com/from-ada-to-platinum-spark-a-case-study-for-reusable-bounded-stacks https://blog.adacore.com/from-ada-to-platinum-spark-a-case-s...