A quick analysis I did showed that half of the critical security vulnerabilities in Gecko would have been prevented by writing content and layout code in Rust. The other half were mostly JS issues, often having to do with built-in APIs that would also be safe if appropriately written in Rust (or self-hosted).
> For a “systems programming language”, Rust doesn’t let you do anything i’d expect, like let you specify whether a signed integer is 2s compliment, and how it behaves when it wraps.
Well, this definition of a systems programming language excludes C.
> Instead the programmer is at the whim of the compiler writer, same as in C, and its “undefined behaviour” which is a source of real, hard to track bugs.
Nope. Rust defines signed overflow. http://huonw.github.io/blog/2016/04/myths-and-legends-about-...
> Rust doesn’t even have support for modern features like wide registers
What is a "wide register"? Do you mean SIMD? If so, it sure does [1].
> or any features that help you deal with raw memory, it just marks it as “unsafe”.
Sure it does. Rust helps you deal with raw memory by freeing you from the need to deal with raw memory in the vast majority of occasions. For example, in C you have to mess around with char pointers to operate on strings. In Rust you don't.
> There aren’t even any basic meta programming features like struct introspection.
That's what custom derive is for.