3 ms·
That's well and good for safe Rust, but unsafe Rust is hard as hell to audit because nobody _really_ knows what the rules are. We're kind of still figuring out
by leshow 5y ago
That's well and good for safe Rust, but unsafe Rust is hard as hell to audit because nobody _really_ knows what the rules are. We're kind of still figuring out how to write unsafe Rust safely. Have a look at the "too many linked lists" book, which turns out to have had a fundamental error in it for years.
I think miri is a part of the answer to this, but it is not perfect. At the end of the day, you need unsafe at some level to do anything useful, and we need more explicit rules about how to do it properly.
- avgcorrection 5y agoWhat was the Rustonomicon error?
- steveklabnik 5y agoI think they're talking about https://github.com/rust-unofficial/too-many-lists/issues/213 https://github.com/rust-unofficial/too-many-lists/issues/213
- leshow 5y agonot rustonomicon, https://rust-unofficial.github.io/too-many-lists/fifth-layout.html https://rust-unofficial.github.io/too-many-lists/fifth-layou... there are new sections that were recently added to this
- zozbot234 5y agoIt should be at least no harder than modern C, where any undefined behavior is a license for the optimizer to outright ignore the code you actually wrote. The main practical difficulty stems from the fact that Safe Rust rules are fully in effect even in an unsafe block, so you need to assess where references can be used instead of general pointers etc.