Converting A C++ Codebase To Rust

 

How RunSafe Migrated a 30,000-Line C++ Codebase to Rust

Memory-safe languages like Rust are often recommended for new development — but rewriting large, security-critical C++ systems is rarely straightforward.

In this S4x25 session, Mitch Souders, Senior Software Engineer at RunSafe Security, shares how his team converted a 30,000-line C++ codebase to Rust to address memory-safety risks while preserving performance and behavior. Driven by the prevalence of memory-safety vulnerabilities and RunSafe’s secure-by-design principles, the project focused on eliminating entire classes of bugs rather than fixing them piecemeal.

Mitch walks through the technical realities of the migration, including operating without the Rust standard library, avoiding libc dependencies, handling global mutable state, and isolating unsafe Rust behind safe abstractions. He also covers the team’s testing and verification strategy, using comparative testing to ensure the Rust implementation matched the original C++ behavior byte for byte.

The result was a successful conversion with performance on par with C++, reduced binary size, and only about 1.5% of the codebase requiring unsafe Rust — along with the discovery of several latent bugs in the original C++ implementation.

This talk offers practical guidance for engineers responsible for legacy C++ codebases, security software, and ICS/OT environments who are evaluating Rust as a path to stronger memory safety.

CRA Readiness: Build an SBOM You Can Act On

CRA Readiness: Build an SBOM You Can Act On

Under the Cyber Resilience Act, having an SBOM is only the beginning. Manufacturers need to know exactly what software is in each product release and be able to quickly determine which products are affected when a new vulnerability emerges. For embedded software, that...

read more
Operational Software Assurance

Operational Software Assurance

Security Cannot Stop When Software Ships Critical software can remain deployed for years or even decades. During that time, new vulnerabilities emerge, threats evolve, and AI is accelerating both vulnerability discovery and exploit development. But patching, testing,...

read more
6 Steps to CRA Readiness

6 Steps to CRA Readiness

The EU Cyber Resilience Act (CRA) is reshaping how connected and embedded products must be secured, maintained, and supported. Is your organization ready? Watch this short video to learn six practical steps that can help product manufacturers prepare: Test your...

read more