Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Researchers have demonstrated a route from a restricted subset of C to safe Rust, but it is not a general-purpose converter for arbitrary C programs. Their Mini-C approach first requires a program to fit a data-oriented subset, sometimes after source changes; for code that qualifies, the researchers say it can automatically produce valid, safe Rust.

The distinction matters: translating C into Rust syntax does not by itself make a program memory-safe. Other tools prioritize a close translation and leave unsafe Rust for later migration work, while newer research experiments with analysis, tests, and feedback to improve the result.

What the researchers built

Aymeric Fromherz of Inria and Jonathan Protzenko of Microsoft Azure Research developed Mini-C, a constrained, data-oriented subset of C intended to be translated automatically into safe Rust. Their work is described in the paper Compiling C to Safe Rust, Formalized. In a 2025 account of the paper, InfoWorld quotes the researchers: “Once in this subset, our approach then automatically produces valid, safe Rust code.”

The qualification “once in this subset” defines the approach’s boundary. Mini-C is not presented as a translator for every valid C program. A source program must fit the subset, and some programs may need edits before it does. The available account does not provide a complete language specification here, so it would be misleading to assume that a particular C feature is supported or that arbitrary projects can be converted unchanged.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the two reported examples show

InfoWorld’s 2025 account describes two projects in the researchers’ evaluation. They illustrate different amounts of preparation, not a guarantee that other C code will be as straightforward.

Project Reported source adjustment Reported result
HACL* cryptographic library “Minimal adjustments” to become Mini-C, according to InfoWorld’s 2025 account of the researchers’ evaluation. The account reports an 80,000-line verified cryptographic library in pure Rust with no use of unsafe. This is the reported outcome for this case, not a general scaling claim.
EverParse CBOR parser No changes were reported as necessary to become Mini-C, according to InfoWorld’s 2025 account. The account describes a 1,400-line C parser translated to Rust after fitting the subset.

The examples establish that the method was applied to those two projects with those reported adjustments. They do not establish that a large, unrelated C codebase will fit Mini-C, compile with its surrounding dependencies, or preserve all behavior after migration.

Does C2Rust make C code memory-safe?

Not on its own. C2Rust’s maintainers describe its transpiler as an initial migration step: it translates C99-compliant code into Rust that closely mirrors the input, with functionality preservation as its primary goal. They state that the output of c2rust transpile is “unsafe and unidiomatic” and that further work is needed to reach safe, idiomatic Rust.

That makes “translated to Rust” and “translated to safe Rust” different outcomes. Rust code can contain unsafe blocks, which let the programmer take responsibility for operations the compiler cannot verify under Rust’s usual safety rules. A mechanical translation may therefore be useful for getting code into the Rust ecosystem without eliminating the memory-safety risks that motivated the migration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the approaches differ

These projects address different stages and constraints in C-to-Rust migration. Their reported evaluations use different methods and programs, so the figures below should not be read as a head-to-head ranking.

Approach Source coverage and edits Safety target or result How translation is checked Reported evaluation
Mini-C, Fromherz and Protzenko; reported by InfoWorld in 2025 Restricted data-oriented C subset; the reported HACL* case needed minimal adjustments and EverParse needed none. Automatic production of valid, safe Rust for programs in the subset, as described in InfoWorld’s account of the paper. The account establishes the stated outcomes for the two examples; broader validation details are not stated in that account. HACL* and EverParse CBOR parser, according to InfoWorld’s 2025 account.
C2Rust; project maintainers’ README Translates C99-compliant code to Rust that closely mirrors the input; required edits for a particular project are not stated in the README excerpt. Initial translation; maintainers say the output is unsafe and unidiomatic, not the finished safe-Rust result. Its stated primary goal is functionality preservation, with test suites expected to continue passing; tests do not establish memory safety. Benchmark scope is not stated in the cited README statements.
C2SaferRust; authors’ 2025 arXiv abstract Starts with C2Rust output and uses an LLM to translate slices into safer Rust; source-language coverage beyond the reported benchmark is not stated. Reported reductions of up to 38% in raw pointers and up to 28% in unsafe code on a benchmark of seven real-world programs. Runs end-to-end tests; all resulting programs passed the provided test cases, according to the abstract. Seven real-world programs. The reported maxima are benchmark-specific.
RustMap; authors’ 2025 preprint Uses dependency analysis to divide projects into translation units; the supported C subset and required source edits are not stated here. Translation approach; an overall safe-Rust guarantee is not stated in the described evaluation. Feeds compiler errors and execution-state mismatches back into an LLM translation loop. 126 programs, including a bzip2 implementation of more than 7,000 lines, according to the preprint.
SmartC2Rust; authors’ ICSE 2026 proceedings paper Segments source code and incorporates context during iterative translation; language coverage and required source edits are not stated here. Authors report fewer unsafe statements and better security and semantic-equivalence outcomes than prior works in their evaluation; this is not a production guarantee. Iteratively incorporates compilation errors, segmentation context, semantic discrepancies, and unsafe statements. Evaluation-set size is not stated in the available account.

What later migration research adds

Using tests and LLMs to reduce unsafe code

C2SaferRust starts from C2Rust’s mechanically translated output, asks an LLM to translate code slices into safer Rust, and runs end-to-end tests. Its authors’ 2025 abstract reports that, on a benchmark of seven real-world programs, the resulting versions had up to 38% fewer raw pointers and up to 28% less unsafe code; all passed the provided test cases.

Those results are evidence about that benchmark and those tests. Passing tests supports the claim that tested cases still work; it is not a formal proof of equivalence for every input or a proof that every safety property holds. The “up to” figures are maxima, not expected reductions for every program.

Accounting for dependencies and build structure

RustMap focuses on a project-level difficulty: C programs are not just isolated source files. Dependencies, build structure, and translation across interacting components can make whole-project migration difficult. Its dependency-guided process divides a project into translation units and uses compiler errors and execution-state mismatches as feedback in an LLM translation loop. The authors report evaluating it on 126 programs, including a bzip2 implementation exceeding 7,000 lines.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Iterating on translation discrepancies

SmartC2Rust, published in the ICSE 2026 proceedings, segments source code and iteratively incorporates compilation errors, segmentation context, semantic discrepancies, and unsafe statements. Its authors report reduced unsafe statements and improved security and semantic-equivalence outcomes compared with prior work in their evaluation. Those findings describe the study’s evaluation, not a general guarantee for production migrations.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a C-to-Rust migration needs to establish

A migration decision should separate source compatibility, behavior, and safety. A project that compiles as Rust may still contain unsafe; code that passes a test suite may still behave differently on untested inputs; and a translator that handles a source file may not handle its build system or dependencies.

  • Subset fit: Determine whether the code fits the translator’s supported language or requires refactoring. Mini-C’s reported results concern programs brought into its restricted subset.
  • Project integration: Account for dependencies, build configuration, and interactions among translation units. RustMap’s authors identify these as complications in whole-project migration.
  • Behavioral equivalence: Decide what evidence is needed beyond compilation, such as relevant tests and checks for semantic discrepancies. Passing the supplied tests establishes results only for those cases.
  • Safety claims: Inspect whether generated code contains unsafe and what operations it covers. Rust syntax alone is not evidence that the original memory-safety risks have been removed.
  • Evidence scope: Tie a tool’s reported success to the evaluated programs, method, and validation. The studies described here are not directly comparable because their supported languages, techniques, and evaluation sets differ.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.