hraness
Theme
Appearance

rust where it earns its place: memory-critical cores

rust where a memory bug corrupts state, typescript where the risk is logic

by hraness · drafted with ai assistance

the rest of this lesson is free: add your email to keep reading.

Hraness writes a component in Rust when a memory bug or a garbage-collection pause there would corrupt state or break a guarantee, and in TypeScript otherwise. Rust offers memory safety without a garbage collector, explicit ownership, and a type system strict enough to rule out many invalid states on its own. It costs slower iteration, a smaller hiring pool, and more ceremony per feature. So the choice is made one component at a time, by asking where that trade pays.

the rule for choosing rust

The places that qualify are few and named: kernels that must not crash while holding other people's state, evaluators that run input the program does not fully trust, and paths where deterministic output has to hold up in a hostile environment.

Everything else stays in TypeScript. Bun's toolchain is fast, the type system covers most of the same modeling, and a crash there costs a failed request rather than a corrupted vault. Rust appears in the portfolio where its guarantees carry weight, and nowhere else.

three places rust pays

vhalla is the largest example: a peer-to-peer workspace whose crates hold cryptographic material, durable journals, and wire state for rooms that persist across restarts. Its cores are no_std and ban unsafe, and the deterministic-core lesson is drawn from this codebase. The ban matters because Rust's safety argument holds only where every unsafe block can be audited, and in the cores there are none to audit.

ALGAL's kernel is the second. Its expression evaluator and its run-record engine must produce identical output on every platform, indefinitely. Writing the kernel in Rust, with the TypeScript runtime as the parity oracle described in its own lesson, is what makes verify a credible offline check. The evaluator compiles to wasm for the Bun side from the same source, so the same rules run in both places.

Oh's memory kernel is the third, and its plan records the reasoning. Other tools build views from this store, so it needs Rust's predictability: no garbage-collection pauses and no memory surprises. Its parity suite covers the port the way ALGAL's covers the runtime.

why the rest stays typescript

The rest of the portfolio is TypeScript by choice: GhostGet's provider orchestration, PeopleBlade's contact graph, the sites, the queues, and the release promotion workflows. These layers mostly wait on network and disk. Rewriting them in Rust would buy memory safety the work does not need and cost iteration speed it does. Their typical failures, such as a wrong API call, a bad parse, or retries in the wrong order, are better handled by parsing outside values from unknown and by keeping a claims ledger.

The line falls between memory risk and logic risk. xcb's Rust core and ALGAL's unsafe bans sit on the memory side; GhostGet and the product sites sit on the logic side. Each repository records its own choice.

what rust leaves to other tools

The borrow checker prevents memory bugs. It does nothing about a wrong invariant, a badly tuned retry, or a faulty parser. The Rust crates in the portfolio carry the same property tests, Hegel sequences, and Kani proofs as the rest of the code for that reason.

The unsafe ban removes the keyword from the cores, not the risk. A dependency with internal unsafe, a C library called through FFI, or a wasm boundary can still bring memory errors in. The ban shrinks the code that can do so, which is why the crates at the edges get extra defenses: size-limited frames, deny_unknown_fields, and fault-injection stores.

Two languages also mean two toolchains, two sets of dependencies, and reviewers who read both. The portfolio accepts that cost by keeping the Rust code small enough for a few people to know it well. This is the pillar lesson's rule applied to language choice: spend the strongest guarantees where a failure would do the most damage, and use cheaper tools everywhere else.

keep reading: free for subscribers

the rest of this lesson is free. enter your email to subscribe, and every subscriber lesson unlocks in this browser.

already subscribed? enter the same email to unlock.