Rust in Ubuntu
In a Nutshell
Canonical, the company behind Ubuntu, has begun replacing core system utilities with Rust implementations—starting with uutils coreutils and sudo-rs in the 25.10 release—to improve memory safety and reduce the attack surface that drives their security patching revenue. The shift prioritizes resilience (the intersection of security and reliability) over perfect compatibility, with projects like NTPDRS for time synchronization and UPKI for browser-grade certificate handling demonstrating broader ambitions. Canonical funds upstream development and security audits rather than writing the code themselves, using their market position to drive ecosystem-wide adoption while addressing crates.io supply chain risks through vendoring and SBOM embedding.
These notes were generated by AI and may contain inaccuracies.
Orhun, Rust developer advocate at JetBrains and open-source maintainer, hosts a Rust Rover live stream discussing Ubuntu's adoption of Rust. Ubuntu is the most widely deployed Linux distribution with 15 million deployments worldwide. The 25.3 release marked the beginning of Rust's integration into Ubuntu's core tooling.
John Seager serves as VP of Engineering at Canonical. He joined Canonical over five years ago, initially focusing on cloud automation with the Guju control plane and operators. Two years ago, he took leadership of Ubuntu. His decision to adopt Rust was driven by a reflection on Ubuntu's 20-year history and what would ensure its success for the next 20 years.
Seager emphasized security and resilience as critical for all users, ranging from students to Fortune 500 companies. He views Rust as providing the most compelling tools for advancing this agenda, along with performance benefits and attracting developers interested in solving systems programming problems.
Memory safety is the primary driver for choosing Rust. While other memory-safe languages exist, Rust's borrow checker forces developers to think more carefully about code safety. Canonical generates most revenue from patching security vulnerabilities and support, making fewer vulnerabilities beneficial.
Seager defines resilience at the intersection of security and reliability. Memory safety provides better security but also better reliability, as panics can lead to both security vulnerabilities and system failures. This is particularly important for safety-critical systems including automotive and industrial applications where Ubuntu runs.
Sign in to read the full notes
Get access to AI-generated notes, topic timestamps, and more.