>So there will of course be some unsafe. In a well implemented driver it will also be very limited in scope and relatively easy to check.
I'm sure that is what the C developer thought as well...I'm not trying to be snarky, but that same arguments that are made against C code holds equally true for unsafe code...
I don't think it is a reasonable position to suggest that unsafe Rust code is somehow safer than C code...