35 ms·
That’s not an attack. I think they are just trying to make the point that once you enter unsafe rust, you can use any unsafe language since the biggest benefit
by 3a2d29 4y ago
That’s not an attack. I think they are just trying to make the point that once you enter unsafe rust, you can use any unsafe language since the biggest benefit of rust is gone.
Unsafe rust is not used often, they never argued that.
- oconnor663 4y ago> since the biggest benefit of rust is gone I think it's more of a spectrum than this makes it sound. For example, an unsafe function that takes a &[u8] argument can still assume that that argument isn't null, isn't dangling, etc. Just because a function is unsafe, or uses unsafe, doesn't mean other functions are allowed to feed it garbage. (Other unsafe code could do that, but that's per se UB, and the other code is unambiguously at fault.) All the "safe types" are still there in the mix, and the compiler is still catching the usual mistakes you make with the usual safe APIs, even in an unsafe block. (Though this has downsides as well as upsides, because there are more ways that producing garbage/invalid values with unsafe code can lead to UB.)