• Sources: Fil-C repository, talk recording, Software Should Work, HN 49026933, r/rust
  • Summary: A recording of Filip Pizlo's talk on Fil-C from the Software Should Work conference, held 2026-07-16 and 17 in Columbia, Missouri, reached 149 points and a long comment thread on 2026-07-23 and was also posted to r/rust. Fil-C is Pizlo's Clang and LLVM fork that makes C and C++ memory safe through concurrent garbage collection and invisible capabilities, where every pointer in memory carries a capability the C address space cannot see. The conference page lists it as one of two recordings published so far.
  • Comments: HN commenters concentrated on the difference between enforcing safety at runtime and proving it at compile time, arguing that a violation caught only during execution is a weaker guarantee than one rejected by a compiler. Others disputed the claim that wrapping libc makes syscalls safe, saying mmap is the hard case and that Rust's standard library already provides comparable abstractions. One thread raised that under a data race a capability and an address can desynchronize, which would allow access to an unintended object.
  • Why it matters: Fil-C is the credible path to memory safety for C and C++ code nobody is going to rewrite, and the trade it makes is a runtime panic and a garbage collector in exchange for compatibility.

send feedback on this story