Hacker News

Favorites Setup
Comment by tialaramex | original | C for Rust programmers
[−]tialaramex · 2026-10-10 Sat 16:07 UTC · link
They're not great analogs to any of the C types because C and C++ have a different relationship to pointers than Rust does but particularly they are not intptr_t / uintptr_t because those claim that we can intra-convert between these types and pointers.

On a typical PC that doesn't seem like a problem, and it will (at least kinda) work which might give you the false impression it's required to work, which it very much is not in Rust. On CHERI it's obvious why this can't work. CHERI's pointers are 128-bit. Rust does have 128-bit integers, but Rust's isize and usize on CHERI will be 64 bits. Because only half of CHERI's pointer bits are address bits, and Rust told you that isize and usize were big enough for the address not the whole pointer.

Many clever pointer tricks only want to fiddle with the address. For example hiding bit flags in an aligned pointer works, as does hiding the entire value inline in today's enormous pointers (64 bits! Luxury) and using a single bit to mark "not a real pointer". In Rust we do these with the actual raw pointer types, they have methods like any other type, but in C or C++ you need to convert to a pointer-sized integer and then do tricks with the integer or you will write UB.

[−]afdbcreid · 2026-10-11 Sun 00:01 UTC · link
That's not true. `usize` and `isize` are explicitly specified to roundtrip a pointer address. You are correct that this would imply they need to be 128-bit in CHERI which will be a major perf hit, and this is actually blocking Rust support on CHERI, and the solution might be to change the guarantees (but it is hard because code in the wild relies on it), but it is the current guarantee.
[−]tialaramex · 2026-10-11 Sun 09:14 UTC · link
I think what's going on is that you've half understood the situation with CHERI as of a few years ago and now you're trying to explain your half-understanding to me confidently as if you're correcting me.

As I said, these types are the same width as an address on the target but a CHERI pointer isn't just an address, that's why they are so wide.

Maybe start here: https://doc.rust-lang.org/std/ptr/index.html#strict-provenan...