Link: Safety in an unsafe { world }
On its own, Rust guarantees memory safety and thread safety. However, we can take safety to the next level using three steps.
- Define an object that the Rust type system can reason about, such as a struct. Also define a safety property that Rust can’t reason about and attach it to the object through an invariant.
- Enforce that the safety property is upheld. This responsibility is on us as the programmer.
- Consume the safety property as a precondition. This is where we benefit most from our efforts.
Using these steps, we can ensure safety for any property we’d like.