All skills
massimodeluisa avatar

/rust-best-practices

@d521b51

Write and review production Rust using the official API Guidelines, Style Guide, and this engineering standard: allocation contracts, ownership, Result vs panic, debug_assert, Clippy, tests, rustdoc, unsafe, and Cargo CI. Use when writing, reviewing, or refactoring Rust; choosing borrow vs clone; designing crate APIs; handling errors; bounding heap use; configuring clippy or rustfmt; or when the user runs /rust-best-practices. Do not use for other languages. Triggers: rust, rustc, cargo, clippy, rustfmt, ownership, clone, borrow, Result, unwrap, expect, panic, thiserror, anyhow, heapless, no_std, allocation, debug_assert, type-state, Send, Sync, unsafe, FFI, rustdoc, MSRV, rust-best-practices, rust style, rust guidelines

Use this Skill: https://skilld.dev/gh/massimodeluisa/rust-best-practices-skill/rust-best-practices

This session only. Nothing lands on disk.

referencesunsafe.md

≈836 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Pointers, sharing, concurrency, and unsafe

Prefer references for borrowing and slices for contiguous data. Reach for smart pointers only when their ownership semantics are required.

Type Owns heap? Send + Sync Use
&T no if T: Sync shared borrow
&mut T no if T: Send (not shared) exclusive borrow
Box<T> yes if T: Send / Sync single-owner heap, recursive types, large values
Rc<T> yes no single-thread shared ownership
Arc<T> yes if T: Send + Sync multi-thread shared ownership
Cell<T> no (wrapper) not Sync Copy interior mutability
RefCell<T> no (wrapper) not Sync runtime borrow checks; MAY panic
Mutex<T> no (wrapper) if T: Send exclusive interior mutability, threads
RwLock<T> no (wrapper) if T: Send + Sync many readers or one writer
OnceCell<T> no (wrapper) not Sync one-time init, one thread
LazyCell<T> no (wrapper) not Sync lazy OnceCell
OnceLock<T> no (wrapper) yes one-time init, threads / static
LazyLock<T> no (wrapper) yes lazy OnceLock
*const T / *mut T n/a manual FFI / raw memory; unsafe

Cloning Rc/Arc may not allocate; the value remains heap-backed and is not strict heapless. Interior mutability changes aliasing and synchronization reasoning.

Docs: std pointers, Nomicon.

Shared ownership is not the default

Frequent Arc<Mutex<T>> often means unclear ownership. Prefer: a single explicit owner; message passing with bounded queues; immutable shared data; scoped threads borrowing state; partitioned state; IDs or handles into a controlled store.

Use locks when they are the clearest correct design. Lock-free is not automatically faster or safer.

RefCell borrow conflicts panic at runtime. Do not use it to hide an ownership problem on a library hot path.

Send and Sync are commitments

Do not add unsafe Send or Sync implementations without a written proof covering all interior state, aliases, callbacks, and FFI. C-SEND-SYNC: implement them where they are actually true.

Forbid unsafe by default

#![forbid(unsafe_code)]

in crates that do not require unsafe Rust.

When unsafe is necessary:

  • isolate it in the smallest possible module
  • expose a safe API
  • document every unsafe block with SAFETY: covering pointer, alignment, initialization, aliasing, lifetime, and concurrency invariants
  • enforce preconditions in release-active code or types
  • add focused tests and Miri coverage where applicable
  • retain a safe reference implementation when optimizing
  • NEVER rely solely on debug_assert! for safety (errors.md)

FFI is a complete boundary

FFI docs MUST define: ownership transfer; who allocates and deallocates; allocator compatibility; pointer validity and alignment; buffer length and capacity; lifetime; thread affinity; panic behavior; error representation; callback reentrancy.

Rust panics MUST NOT unwind across an FFI boundary unless the ABI explicitly supports and documents it.

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill provides a comprehensive set of Rust engineering standards and best practices for writing and reviewing code. It covers memory allocation, API design, error handling, and performance optimization. No malicious behavior or security risks were identified.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at d521b51. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 weeks ago
Other metadata
metadata
{
  "author": "massimodeluisa",
  "version": "1.0.0",
  "website": "https://www.rust-lang.org/"
}

README badge

README badge for massimodeluisa/rust-best-practices-skill