Comment by Ygg2
8 days ago
> True, but unsafe let's you conjure up any lifetime you want
The only thing unsafe does is let you have an unbounded lifetime. As I said, it doesn't check those:
fn get_str<'a>(s: *const String) -> &'a str {
unsafe { &*s }
}
https://doc.rust-lang.org/nomicon/unbounded-lifetimes.html
> if you generously sprinkle pointer dereferences in unsafe code, you effectively disable the protection provided by the borrow checker
You don't disable anything. You wrote a "trust me compiler" block, and compiler trusted you.
Rust won't ever protect from all possible problems, just the ones the compiler handles.
> You don't disable anything. You wrote a "trust me compiler" block, and compiler trusted you.
That’s the same thing.
What's the point of using Rust in the first place when you disable the compiler feature that protects you the most?
Because it lets you constrain the parts that the compiler can’t check and has to trust you on. The alternative is either a langue that can’t do necessary things, or a language that can’t check what could be checked.
With unsafe, you’re telling the compiler “I’ve taken extra care to make sure that what I’m doing is safe and doesn’t break your rules” and the compiler can go ahead and assume that you don’t, in fact, break the rules, and therefore can verify everything else as if the rules never got broken.
In less safe languages, the entire program is “trust me, it’s safe”, while in rust only the parts flagged as unsafe are.
The point is that you should only use unsafe when 1. It’s absolutely necessary for functionality or performance and 2. You have verified and are very certain that the code is correct.
That’s a very useful property to have.
Yes, when a human does it. With an LLM, the "trust me, I took extra care" is extremely doubtful. If LLMs could do that, they might as well use unsafe languages.
1 reply →
Well, Rust has things like miri that can help you write your unsafe code and it's just a command line invocation away.
Obviously you should try to avoid writing unsafe Rust to begin with.
Mu. Invalid question. Rust doesn't disable compiler features. It gives you extra set of footguns when you ask for it.
As for the actual unloaded question, "What's the point of unsafe in Rust?" it is to contain and make it easier to identify sources of UB.
The whole point of the rust rewrite is that bun is now thought to rely on rust’s memory safety features, but that assumption doesn’t hold if everything’s inside an unsafe block.
1 reply →
> The only thing unsafe does is let you have an unbounded lifetime.
No, you're wrong: You can create any lifetime. Proof:
This will take a reference and return it with any lifetime specified by the caller.
> You don't disable anything.
I said "effectively disable". For example:
fn trust_me_bro<'a>(x: mut u32) -> &'a mut u32 { unsafe { &mut x } }
After the call to trust_me_bro, two aliasing, mutable references exist simultaneously. This would usually be prevented by the borrow checker, but the unsafe code has effectively disabled it.
> Proof:
You just listed examples of unbounded lifetimes.
> I said "effectively disable". For example:
Not sure what you meant by this example since it doesn't compile. It seems the borrow checker caught your mischief. So much for effectively disabling stuff :P
You haven't effectively disabled anything; you just (tried to) wrote unsound code that washes one mutable ref as another. This stuff is allowed provided shared refs are never accessed at the same time (for example, panicking upon reading reference_b).
What you probably meant is https://play.rust-lang.org/?version=stable&mode=debug&editio...
But you know what? If you're dabbling in unsafe, you have this big button called Tools in the playground. Choose Miri, then run your code; it will display large Undefined behavior. It even highlights the `trust_me_bro` function.
Hell, run this with UBSAN, ASAN, and other C tools. They will probably catch any such behavior.
> You just listed examples of unbounded lifetimes.
You're just splitting hairs and trying to weasel around the fact that yes, you really can create any lifetime you want using unsafe.
> Not sure what you meant by this example since it doesn't compile.
That's because the crappy HN formatting ate some of the characters. Here's the original version:
https://play.rust-lang.org/?version=stable&mode=debug&editio...
> What you probably meant is […]
If you know what I meant, then what's up with your snarky comment about "So much for effectively disabling stuff"? In your playground link, you did effectively disable the borrow checker in safe parts of the code. Next thing you're moving the goalpost, now it's not about external, static analysis tools: "run this with UBSAN, ASAN, and other C tools". I don't think you're arguing in good faith here. Goodbye.
1 reply →