Scylla: Translating an Applicative Subset of C to Safe Rust
Aymeric Fromherz, Jonathan Protzenko
Abstract
The popularity of the Rust language continues to explode; yet, many critical codebases remain authored in C. Automatically translating C to Rust is thus an appealing course of action. Several works have gone down this path, handling an ever-increasing subset of C through a variety of Rust features, such as unsafe. While the prospect of automation is appealing, producing code that relies on unsafe negates the memory safety guarantees offered by Rust, and therefore the main advantages of porting existing codebases to memory-safe languages. We instead advocate for a different approach, where the programmer iterates on the original C, gradually making the code more structured until it becomes eligible for compilation to safe Rust. This means that redesigns and rewrites can be evaluated incrementally for performance and correctness against existing test suites and production environments.
Compiling structured C to safe Rust relies on the following contributions: a type-directed translation from (a subset of) C to safe Rust; a novel static analysis based on "split trees" which allows expressing C's pointer arithmetic using Rust's slices and splitting operations; an analysis that infers which borrows need to be mutable; and a compilation strategy for C pointer types that is compatible with Rust's distinction between non-owned and owned allocations. We evaluate our approach on real-world cryptographic libraries, binary parsers and serializers, and a file compression library. We show that these can be rewritten to Rust with small refactors of the original C code, and that the resulting Rust code exhibits similar performance characteristics as the original C code. As part of our translation process, we also identify and report undefined behaviors in the bzip2 compression library and in Microsoft's implementation of the FrodoKEM cryptographic primitive.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5bce066b-edbe-438d-8c48-56cd933736f6Cited by top-tier papers3
- Hayroll: A Modular Wrapper for Translating C Macros and Conditional Compilation to RustHaoran Peng, Baris Kasikci, Gilbert Louis Bernstein, Michael D. ErnstPLDI 2026 · 1 citation
- &inator: Correct, Precise C-to-Rust Interface TranslationVictor Chen, Ayden Coughlin, Michael D. BondPLDI 2026 · 1 citation
- Cpp2Rust: Automatic Translation of C++ to Safe RustLucian Popescu, Francisco Gouveia, Henrique Preto, João Silveira et al.PLDI 2026 · 1 citation
Builds on13
- Lost in Translation: A Study of Bugs Introduced by Large Language Models while Translating CodeRangeet Pan, Ali Reza Ibrahimzada, Rahul Krishna, Divya Sankar et al.ICSE 2024 · 96 citations
- EverParse: Verified Secure Zero-Copy Parsers for Authenticated Message FormatsTahina Ramananandro, Antoine Delignat-Lavaud, Cédric Fournet, Nikhil Swamy et al.USENIX Security 2019 · 70 citations
- Translating C to safer RustMehmet Emre, Ryan Schroeder, Kyle Dewey, Ben HardekopfOOPSLA 2021 · 60 citations
- Ownership Guided C to Rust TranslationHanliang Zhang, Cristina David, Yijun Yu, Meng WangCAV 2023 · 37 citations
- Aliasing Limits on Translating C to Safe RustMehmet Emre, Peter Boyland, Aesha Parekh, Ryan Schroeder et al.OOPSLA 2023 · 32 citations
Related papers
- To Tag, or Not to Tag: Translating C's Unions to Rust's Tagged UnionsJaemin Hong, Sukyoung RyuASE 2024 · 6 citations
- SmartC2Rust: Iterative, Feedback-Driven C-to-Rust Translation via Large Language Models for Safety and EquivalenceMomoko Shiraishi, Yinzhi Cao, Takahiro ShinagawaICSE 2026 · 4 citations
- Translating C To Rust: Lessons from a User StudyRuishi Li, Bo Wang, Tianyu Li, Prateek Saxena et al.NDSS 2025
- Is rust used safely by software developers?Ana Nora Evans, Bradford Campbell, Mary Lou SoffaICSE 2020 · 57 citations
- Concrat: An Automatic C-to-Rust Lock API Translator for Concurrent ProgramsJaemin Hong, Sukyoung RyuICSE 2023 · 17 citations
