> All the constructs required for safety seem to obfuscate the control flow
A couple thoughts on this point, speaking as an admitted Rust fan:
- A lot of this has gotten better since "non-lexical lifetimes" were stabilized. In particular, it used to be somewhat common to need extra pairs of nested curly braces, to convince the borrow checker that some reference you'd taken really wasn't going to be used again. But today that is almost never necessary.
- In some cases, I find Rust's safety-oriented APIs clearer and nicer than their equivalents in other languages. For me, the big one is Mutex<T>. In Rust, a Mutex is a container, and you can only access its contents by locking it. It's impossible to forget to lock a Mutex when you access the thing it protects.