Except this isn't guaranteed to be safe, because the implementation [1] just calls GTK in an
unsafe block:
fn add<P: IsA<Widget>>(&self, widget: &P) {
unsafe {
ffi::gtk_container_add(self.to_glib_none().0, widget.to_glib_none().0);
}
}
Oh, did you believe that Rust always does checks to ensure memory safety? Well that's too bad.
Unsafe blocks are for exactly those situations where the compiler can't prove safety at compile time, giving you an escape hatch to say "this really is safe, I know what I'm doing". There are some runtime-checked abstractions built on this, but they can't help you when interacting with non-Rust code.
[1] https://github.com/gtk-rs/gtk/blob/8949ac0304660f53e1fbe2850...