As an experienced C programmer learning Rust, my frustration is less "oh it prevented a bug I would have made" and more "no but its fine in this context leave me alone" :-)
As an experienced C programmer learning Rust, my frustration is less "oh it prevented a bug I would have made" and more "no but its fine in this context leave me alone" :-)
There is this belief "I know C so I know what's fast here", and, while that's sometimes true, I think it's wrong often enough re: Rust to try doing things a different way at a relatively high level. I think when you're starting off with Rust your goal should be to implement virtually everything in the dumbest/most obvious/Python-ic way possible, and then to experiment with optimization/rewrites. And while you should try the thing "You know to be fast because you know C" you should also spend that time reading how the std lib implemented a feature and leaning on the std lib, benchmarking as you go. One reason is because the paradigm is obviously different. Another is because the std lib has lots of features for common uses which are optimized very carefully, which C just doesn't have, and one shouldn't ignore/forget that.
That's a very overused argument and IMHO wrong way to sell Rust. The reality is, even if 100% of C bugs were memory safety related, that still does not mean every C program is riddled with bugs. If that were the case, nobody would write C programs in the first place.
There is a strong selection bias in play here. You only see times where memory safety caused an issue because you get a segfault/overflow/etc but just have invisible correct behavior at all other places.
Maybe I was lucky with the people and companies I worked at, but memory safety overall has never been a big issue with our C softwares. Sure it happens from time to time, but it's definitely not any kind of plague.
Still I'm learning Rust, so why?
For me, it has to do with the library ecosystem. It's very hard to find good quality, easily pluggable, performant C libraries. You always end up having to re implement half of the data structures you need, or use sub par configuration formats just because you don't have readily available libraries.
I think this is a much more compelling, and frankly true, argument for C programmers to use Rust.
Go look at the linux kernel. Arguably the most important C program on the planet. Absolutely enormous incentive to get it correct. It is... full of bugs. Including a large number of memory safety bugs.
Writing low-level systems code often that involves pointer arithmetic or type punning. The whole point of Rust is to be able to write such code with the iffy parts clearly delimited.
Yeah it was kind of unfortunate, and I think resolved by now?
As a saying goes (in some locations), “Now we probably can’t boil more soup from those bones”.