I don't think anything from the unsafe mental model should make it to Rust. If safety contracts are properly done (which I'm pretty sure they will in 5 to 10 years), they should be able to cover everything in the unsafe mental model (which is just a type system approach to the program logic approach of safety contracts).
I agree and we're not alone to believe so. I know other people and organizations who are also pondering writing learning materials around unsafe. That takes time: unsafe is a difficult and vast landscape. One of my hope is that some Unsafe Rust Working Group would come to life and host such information. (Note that this is different from the UCG, which goal is to figure out the Rust operational semantics. The Unsafe Rust WG would depend on the UCG.) I've been made aware of safer-rust · GitHub but they're too focused on their projects and tools to be useful to the whole Rust community.
There's a good reason for that. In Rust, all functions are robust, because unsafe code may rely on their correctness. This means that safe code can cause UB outside its dependencies, but that's by language design. Robust becomes useful only if you care about safety, and want to prevent safe code to cause UB. This means you work in a sub-ecosystem with different policies and must review third-party crates against your policies.
We came to the same conclusion in this thread right? That's the standard library being conservative.
I would be surprised if they're not. Those concepts usually become visible after some amount of exposure to unsafe, which they should have had.
I totally agree, but what do you suggest?