> ... no static analysis on earth is going to stop you from actually needing tests to see if your code works.
Correct. However, the intent of Rust is that the code will not fail [1] due to some silly machine thing below your current level of abstraction.
As an example, I'd point to one thing that Rust does that solves a lot of problems: the Vector. This gives you:
- a buffer to load as needed
- bounded memory usage ( no more than 2x what's actually needed, and the ability to tailor it)
- automatic resizing as needed
IOW, eliminates 'C programmers disease' (eg: #define BUFFERSIZE 1024 // big enough for anything :-) )
I am sick and tired of writing either the tedious resizing stuff by hand, or using a linked list [2] (which in today's world isn't performant: a self-resizing array will deal with locality-of-reference issues much better).
Disclaimer: I've only peripherally used Rust professionally (ie., corporate innovation sessions, self-contained utilities). I have done enough 'fitness exercise' stuff that I'm confident to comment.
[1] "Fail" as in, do something random like start a cryptominer at root-level-privilege. "Fail to compile" is fine, "panic at runtime" is not fine but not worst case.
[2] Opinion: the reason why linked-lists are an example of something hard to do in Rust is because Vectors make them irrelevant, so why bother?