4 ms·
I'd be interested in hearing from others on this, but typically the way that "inherently unsafe Thing" gets done in rust is that you have an unsafe layer wrappe
by staticassertion 5y ago
I'd be interested in hearing from others on this, but typically the way that "inherently unsafe Thing" gets done in rust is that you have an unsafe layer wrapped in a safe layer.
The problem is obviously building the safe layer. Sometimes that's really hard. There are obvious examples already in Rust - like creating a safe API over scoped threads, or io_uring, ghostcells, etc. Some things may not be representable using only safe code in Rust, with no overhead.
Another relevant thing you can't really safely express is FFI. That would be relevant here since there's this VM boundary.
And then you get JITs, which also have tons of security issues.
Idk, I'd be curious to read about this if there are any papers. Maybe the wasm people are thinking about this?
Certainly it's not unreasonable to say that a memory safe JIT'd VM is going to be tough make memory safe.