3 ms·
> The domain itself isn’t fundamentally unsafe This makes no sense to me, what you’re saying here. You pass raw pointers to the Windows API for one, for which
by dialamac 6y ago
> The domain itself isn’t fundamentally unsafe
This makes no sense to me, what you’re saying here. You pass raw pointers to the Windows API for one, for which it makes no safety guarantees. Short of rewriting Windows from scratch I don’t see how this isn’t a fundamentally unsafe domain. Sure you could put more and more wrappers up on top (it’s not an even an issue of one-to-one translation, but how resources such as memory are wrapped), but whatever binding there is pretty much must be unsafe.
That it’s possible to write a safe wrapper is kind of obvious.