> I am writing a single abstract declaration (I suppose I should have used `extern "C" {...}` to be clear) that one can only use safely.
Your abstract declaration still wouldn't be safe. Remaining unsafety includes:
• possible dangling pointers
• possible incorrect lengths
• possible libc bugs with ZST elements
• undefined behavior if the sort fn misbehaves - (recently reported as a security issue against glibc because that being UB is dumb even if allowed by the standard: https://news.ycombinator.com/item?id=39264396 )
This is why I call it a "half measure".
I also fail to see how your proposed abstract declaration would simplify either my wrapper, or other code that would actually bother to use the raw FFI definition in any significant way. This is why I further call it "unnecessary". It also fails to specify which underlying FFI parameter size_of::<T>() would actually be passed into.
> You are writing some unsafe code with safe wrapper.
My wrapper remains `unsafe` as well, but it ameliorates everything it reasonably can.
> These are not the same.
No, but my wrapper demonstrates an actual use case of your raw FFI definition... and shows the actual concerns of surrounding code that aren't significantly helped by your declaration.