# Disabling 'unsafe' by default

**URL:** <https://internals.rust-lang.org/t/disabling-unsafe-by-default/7988>\
**Category:** Unsafe Code Guidelines\
**Created:** [July 18, 2018, 11:36am UTC](https://internals.rust-lang.org/t/disabling-unsafe-by-default/7988 "2018-07-18T11:36:01Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![Tom-Phinney](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/tom-phinney/32/3299_2.png) [@Tom-Phinney](https://internals.rust-lang.org/u/Tom-Phinney)\
**Post date:** [July 18, 2018, 1:46pm UTC](https://internals.rust-lang.org/t/disabling-unsafe-by-default/7988/7 "2018-07-18T13:46:01Z")

</div>

> [@vitalyd](#):
>
> How would you address the fact that panics can be rampant in safe code? Or is the only concern memory

Great question! To me panic is a thread-local issue, whereas UB is completely pervasive. See Ralf Jung's [recent post in another thread](https://internals.rust-lang.org/t/what-does-unsafe-mean/6696/37) to this effect. Encapsulation and local recovery/restart can be applied to panics, but there is no recovery from UB because it's impossible to determine in advance what the compiler might do when it's API contract is broken by UB.

---

_[View the full topic](https://internals.rust-lang.org/t/disabling-unsafe-by-default/7988)._
