What does it take to ship Rust in safety-critical?

In a recent blog post, Pete LeVasseur explains that while Rust’s strong safety guarantees and growing use in real-world automotive, aerospace, and medical systems make it promising for safety-critical software, widespread shipping at high integrity levels still depends on maturing ecosystem support, stable toolchains, dependency management, and evidence-friendly development practices:

“When we set out on the Vision Doc work, one area we wanted to explore in depth was safety-critical systems: software where malfunction can result in injury, loss of life, or environmental harm. Think vehicles, airplanes, medical devices, industrial automation. We spoke with engineers at OEMs, integrators, and suppliers across automotive (mostly), industrial, aerospace, and medical contexts.

What we found surprised us a bit. The conversations kept circling back to a single tension: Rust’s compiler-enforced guarantees support much of what Functional Safety Engineers and Software Engineers in these spaces spend their time preventing, but once you move beyond prototyping into the higher-criticality parts of a system, the ecosystem support thins out fast. There is no MATLAB/Simulink Rust code generation. There is no OSEK or AUTOSAR Classic-compatible RTOS written in Rust or with first-class Rust support. The tooling for qualification and certification is still maturing.”

Read the entire post on the Rust blog.

More News

May 12, 2026 10:00 am

Eclipse S-CORE 0.7 is here!

Prototype SDV development board mounted on a stand, featuring multiple connected microcontroller modules, wiring, and a central display, with an Eclipse SDV logo visible on the panel in an office setting.

May 5, 2026 3:20 pm

Eclipse SDV Blueprints: E2E Demo Blueprint now available

banner promoting the sdv newsletter

May 5, 2026 12:00 am

Eclipse SDV Newsletter Q2, 2026