Refactoring the FreeBSD Kernel with Checked C [pdf]
cs.rochester.edu
cs.rochester.edu
> Microsoft has developed an extension to the C language named Checked C which provides new source language constructs that allow the compiler to prevent NULL pointer dereferences and spatial memory safety errors through static analysis and run-time check insertion.
I thought static analysis/fuzzing/unit tests were supposed to catch these kinds of things?
Static analysis plus run time checks where static analysis is inconclusive should mean if you overrun a buffer, you'll kernel panic rather than continue with an unsafe read/write. (If the whole kernel were refactored)
It's a bit of a chicken and egg thing with BSDs. Base system code should compile with a base system compiler. But there is no reason to bring a Rust (or Checked C) compiler into base if nothing uses it.
I'm pretty sure all of the I/O would be `unsafe` though, which begs the question... why write it in Rust in the first place?
How dare you criticise MICROS~1