Memory safety is Rust's headline feature - but spacecraft don't fail from buffer overflows. They fail from ambiguity: mismatched assumptions, undocumented contracts, state machines with unintended transitions.
At #Oxidize2026, David de Rosier (Onyx) looks at what decades of safety-critical engineering have learned about these failure modes, and where Rust helps encode those lessons โ and where it simply can't.
๐ https://oxidizeconf.com/sessions/software_ate_my_spacecraft








