hn.today

Safe SIMD in Rust, even on the inside

shnatsel.github.io7 points0 comments
Screenshot of Safe SIMD in Rust, even on the inside

This explains a technique to provide safe, high-level SIMD in Rust by moving almost all unsafe work into a single, auditable boundary. Raw intrinsics require unsafe and platform-specific handling; Rust 1.87 improved tracking of instruction sets but still leaves unsafe scattered. The solution encodes runtime CPU feature detection as unforgeable, zero-sized tokens (e.g., Avx2) obtained only after a successful feature check. Functions that actually call intrinsics are written as target_feature-enabled inner functions and invoked through a safe wrapper or macro that unsafely calls the inner function only once, justified by possession of the token. Because tokens are zero-sized, passing them has no runtime cost, and the compiler will reject intrinsics not allowed by the target_feature on the inner function.

Generics are used to “smuggle” tokens into SIMD vector types (e.g., f32x8<L>), letting operator implementations (like Add) choose the correct level implementation and perform runtime instruction selection once at setup. This yields ergonomic a + b usage with minimal unsafe surface and one place to audit. The remaining practical limitation is ABI/inlining: target_feature annotations block normal inlining, so callers must be annotated or force inlining to avoid function-call overhead, meaning truly transparent a + b lowering to SIMD still has constraints. A production implementation exists as fearless_simd v0.5, exposing the macro and significantly reducing unsafe code compared to earlier crates.

Read on shnatsel.github.io0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Programming

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.