Sign in

Predrag Gruevski

@predr.ag
1.9K followers 387 following 661 posts

Querying (Almost) Everything // Frontier Systems @ OpenAI // Author of cargo-semver-checks & Trustfall // predr.ag/blog // ex Kensho // MIT alum // hachyderm.io/@predrag // not from around here 🇲🇰 // he-him

PostsRepliesMedia
Reposted by Predrag Gruevski
Marco Ieni @ieni.dev · 11h
I’m now team leader of the Rust Infrastructure team! I’ll keep shipping, but I’ll also pay more attention to the load, health, and overall direction of the team.
https://rust-lang.org/governance/teams/infra/
3707
Reposted by Predrag Gruevski
The Rust Foundation @rustfoundation.org · 28/09/2026
Join Symposium Co-Creators @nikomatsakis.com & Jack Huey and @orhun.dev of @jetbrains.com on Oct 1 to talk about coding agents that write reliable, idiomatic Rust! Register: info.jetbrains.com/rustrover-li... Read more: rustfoundation.org/event/livest...
info.jetbrains.com
Live Webinar - Smarter Coding Agents for Rust with Symposium
Discover how Rust and AI can make each other better and how Symposium gives coding agents the crate-aware skills, tools and workflows they need to write more reliable Rust.
072
Reposted by Predrag Gruevski
rev. howard arson @theophite.bsky.social · 27/09/2026
yes, i am saying this. literally this. i am saying that you should not care about water for 16,000 people when "growing alfalfa for export in deserts with approximately zero precipitation" is literally orders of magnitude more water and vastly more pointless.
3198492
Predrag Gruevski @predr.ag · 21/09/2026
GitHub Actions + Rust's Miri can leak your secrets in CI 🧵 If you run Miri in CI: - upgrade to the 2026-09-22 nightly - clear caches - rotate any secrets that the `cargo miri` CI job had access to GPT-6 Astra helped find this 🦀
GitHub Actions makes it possible to cache directories between runs. Typical setups allow CI runs on main (and other branches) to write to cache, and PRs can only read from cache (preventing cache poisoning). Rust projects tend to speed up CI by caching binaries built by cargo install and sometimes the contents of target/.

PR CI can be triggered by anyone who can open PRs on your repository. GitHub requires maintainer approval for the first PR, but future PRs will rerun CI on every push. Anyone who has previously landed a change can trigger a CI run extracting information from cached target/ and then cover their tracks by pushing a second commit to the PR.

GitHub sometimes hides overwritten commits in its UI, making this kind of attack harder to detect. CI run logs and overwritten commits are also deleted after a few months.

When cargo miri is invoked, Miri needs to retain build-relevant environment variables between runs. The current code to do so achieves this by storing all environment variables to target/. This, of course, persists when target/ is cached.

If your environment contained secrets, these can now be accessed by PRs via the cache.
1389
Predrag Gruevski @predr.ag · 13/09/2026
AI loops 101 in two posts: When CI fails with on a flaky test, send this to your agent: "a test failed in a flaky fashion, please figure out why and propose a pragmatic path forward: <CI link>"
220
Predrag Gruevski @predr.ag · 12/09/2026
RustConf was great 🎉 Now Rust ➡️ Rest, at least for 36h or so. Then, Rust again 🦀
1150
Predrag Gruevski @predr.ag · 01/09/2026
New programming book arrived in the mail 👀 There's never been a better time to think deeply about the structure behind the code we cause to exist.
Logic for Programmers, a book by Hillel Wayne
1446
Predrag Gruevski @predr.ag · 28/08/2026
This change by Noah Lev will probably save a zillion dollars in docs\.rs and CI jobs everywhere. Really nice work! noahlev.org/blog/2026/08...
noahlev.org
How I made Rustdoc 25% faster in one week - Noah Lev Bartell-Mangel
From a "weird bug" to massive speedups
1354
Predrag Gruevski @predr.ag · 27/08/2026
More good news: Jess Izen is stepping into an Engineer in Residence role with the Rust Foundation! She's done so much good work for the ecosystem already (see the post!) and I can't think of a better person to wear this hat 🦀 rustfoundation.org/media/welcom...
rustfoundation.org
Welcoming Jess Izen as Engineer in Residence at the Rust Foundation
The Rust Foundation is pleased to welcome Jess Izen (@jlizen) as our new Engineer in Residence. For the next year, Jess will work full time as part of the Foundation’s engineering team, taking directi...
0213
Predrag Gruevski @predr.ag · 26/08/2026
The first batch of Rust maintainers in residence has been announced! A lot of Rust will get even more love and attention: clippy, rustup, rustdoc, Windows support, standard library, and compiler internals 💖🦀
0171
Reposted by Predrag Gruevski
The Rust Foundation @rustfoundation.org · 26/08/2026
Announcing the 1st cohort of Rust Maintainers in Residence! Thanks to contributions from Google, AWS, & OpenAI, the Rust Foundation and Rust Project have raised $350K to fund 6 contributors on Rustup, Clippy, compiler, stdlib, & rustdoc 🦀 Read announcement: rustfoundation.org/media/rust-p...
rustfoundation.org
Rust Project and Rust Foundation Announce First Maintainers in Residence
New program directs $350,000 toward maintainers supporting critical Rust infrastructure DOVER, Delaware, USA – August 26, 2026 – The Rust Project and Rust Foundation today announced the inaugural coho...
1286
Reposted by Predrag Gruevski
waffle .-. @waffle.pet · 25/08/2026
blog.ihatereality.space/0C-never-type/
blog.ihatereality.space
I stabilized never type | I hate reality
yeah
2122737
Predrag Gruevski @predr.ag · 23/08/2026
I'm updating my Rust projects to harden them against supply chain attacks: - explicit allowlist of hashes for build scripts in the project - `min-publish-age` of 7 days for deps updates, using the nightly cargo feature - ensure no jobs that could run a build script have GH tokens
2430
Reposted by Predrag Gruevski
Pete 🙆‍♂️ @petelevasseur.com · 16/08/2026
super duper cool to have @nia.is.fckn.gay of Hexcat to the @sdv.eclipse.org's @rust-lang.org special interest group this tuesday! chattin bout "Stable allocators, one unsoundness at a time" it's at 7am PDT / 10am EDT / 6pm CEST / 11pm JST =) wanna join? `.ics` is below
screenshot showing Nia Deckers' chat this on August 18, 2026 for "Stable allocators, one unsoundness at a time"
1153
Predrag Gruevski @predr.ag · 16/08/2026
Rust CI now runs cargo-semver-checks to prevent accidental breakage in the standard library 🦀 If you're wondering why that's important and why it took 15kLoC+, this post is for you. predr.ag/blog/protect...
predr.ag
Protecting the Rust standard library from accidental breakage
How & why we're running cargo-semver-checks in Rust's CI
06011
Reposted by Predrag Gruevski
Steve Klabnik @steveklabnik.com · 14/08/2026
I am very happy to announce that I have gotten a paper accepted to PLSS 2026: LLMs as Collaborators in Language Specification and Design conf.researchr.org/details/spla...
conf.researchr.org
LLMs as Collaborators in Language Specification and Design (PLSS 2026) - SPLASH/ISSTA 2026
Workshop on Programming Language Standardization and Specification This workshop aims to foster cross-pollination between researchers and industry professionals with experience in programming language...
161979
Predrag Gruevski @predr.ag · 08/08/2026
"You fixed something — your change made a program compile when it shouldn't have — and that's proof your API has a major breaking change" @lorilorusso.bsky.social interviewed me to understand how cargo-semver-checks will catch breakage in your traits and types www.youtube.com/watch?v=38h2...
youtube.com
RustWeek Interview: Predrag Gruevski, Maintainer of cargo-semver-checks
YouTube video by Rust Programming Language
050
Reposted by Predrag Gruevski
Michal Piotrowski 🦀 @practicalrs.bsky.social · 04/08/2026
blog.rust-lang.org/2026/08/04/e...
blog.rust-lang.org
Enabling the next iteration of the borrow checker on nightly | Rust Blog
Empowering everyone to build reliable and efficient software.
0144
Predrag Gruevski @predr.ag · 01/08/2026
With any luck, this is the cargo-semver-checks release that will start scanning the Rust standard library for breakage. Enjoy v0.50.0! What a fitting moment for a nice round number 🎉 Expect a blog post soon!
cargo-semver-checks v0.50.0 release notes.

- Support for rustdoc JSON v61 for the latest nightly Rust
- One new lint: `auto_trait_impl_added`
- Bugfix in `constructible_struct_adds_field` to properly account for existing `pub` but `#[doc(hidden)]` fields.
- Support for parsing rustdocflags from `.cargo/config.toml` and some minor bugfixes
- Thanks to @taiki-e for accepting our upstream patches and promptly releasing them in `cargo-config2` so we can use them!
0453
Predrag Gruevski @predr.ag · 01/08/2026
Every year, RustWeek and the All Hands meeting of the Rust Project are the most productive few days Rust ever gets. An unbelievable amount of stuff gets done. And now you can read all about it! blog.rust-lang.org/inside-rust/...
blog.rust-lang.org
All Hands 2026 retrospective | Inside Rust Blog
Want to follow along with Rust development? Curious how you might get involved? Take a look!
070
Predrag Gruevski @predr.ag · 31/07/2026
If you use the Trustfall query engine via Python, please upgrade to v0.3.2. In v0.1.6 - 0.3.1, using the exposed APIs in a sufficiently contrived manner could trigger use-after-free. Your code *probably didn't do this*, but I yanked the affected versions to be safe. github.com/obi1kenobi/t...
github.com
Fix unsound `Opaque` in Python bindings. by obi1kenobi · Pull Request #960 · obi1kenobi/trustfall
Python adapters that broke the API contract in copying contexts and returning them more than once could cause a use-after-free / double-free bug. With this fix, this is explicitly checked for and w...
050
Predrag Gruevski @predr.ag · 28/07/2026
Tenth circle of Dante's Inferno discovered
162
Predrag Gruevski @predr.ag · 27/07/2026
"If your rules aren't checkable with a tool, they are just entertainment. They aren't being followed." - Gerard Holzmann #systemsdistributed
Slide saying "rules are most useful if they are sparse, clear, demonstrably correlate with risk, and are checkable with code."
0123
Reposted by Predrag Gruevski
Chris Krycho @chriskrycho.com · 27/07/2026
As I just told a colleague: it’s a shame how little traction this has ever gotten, but part of it is probably tooling. If I had a few months of dedicated funding, I’d build a TS version of cargo-semver-checks – @predr.ag and I have talked about how the underlying infra would Just Work™. If only!
051
Predrag Gruevski @predr.ag · 18/07/2026
Happy cargo-semver-checks release day 🎉 After 30+ PRs and 15kLoC, we can now lint the Rust standard library for accidental breakage! I'll work with Rust maintainers to get that plugged in, then it's blog post time to tell you how it works! Stay tuned 🦀 github.com/obi1kenobi/c...
github.com
Release v0.49.0 · obi1kenobi/cargo-semver-checks
In this release Unstable --stability-aware mode for detecting breakage in the Rust standard library. False-positive fix: correctly propagate #[doc(hidden)] through glob re-exports when determining...
1351
Reposted by Predrag Gruevski
imperio @imperioworld.bsky.social · 14/07/2026
Hi everyone. I need your help! I recently added support to get system GPU usage in the Rust sysinfo crate. Next step was to get this info per-process. However, I'm now facing a very annoying Apple issue: undocumented API changing each version. So I can only test my own macOS version: 12.6. 1/4
1127
Reposted by Predrag Gruevski
Ethan Mollick @emollick.bsky.social · 15/07/2026
Fable: "Pitch Odysseus as a management consultant, arguing that he has found product-market fit, and he should just stick with Trojan Horse making as opposed to going home to Ithaca in a powerpoint" I like the 1 star review from Cassandra where "0 of 10,000 readers found this helpful." Pretty funny
4716
Reposted by Predrag Gruevski
Predrag Gruevski @predr.ag · 03/07/2026
Day 5, a picture worth a thousand words 👇 I put an API-breaking `#[doc(hidden)]` in my local build of the Rust standard library, and asked cargo-semver-checks to find it. See for yourself!
cargo-semver-checks output where the "function now doc hidden" lint is triggered, warning that the "black_box" function in library/core/src/hint.rs is now #[doc(hidden)] and no longer public API. The run took 6.7s total.
251
Reposted by Predrag Gruevski
RustConf @rustconf.com · 03/07/2026
🔦 #rustconf 2026 Speaker Spotlight "Compiling the Linux Kernel with gccrs" by Arthur Cohen & Pierre-Emmanuel Patry (Compiler Engineers at Embecosm) ➡️ On the schedule: rustconf2026.sched.com/event/2KHyD 🎟️ Book before prices rise: bit.ly/43QwYsZ #rustconf26 #rustlang
071
Reposted by Predrag Gruevski
Predrag Gruevski @predr.ag · 02/07/2026
It's Thursday, day 4. Today's haul so far is ~2500 LoC. First, making use of default-value stability which we previously exposed in rustdoc JSON. Codex caught a subtle edge case that affects which traits are considered sealed. Copious test cases are standard, of course. github.com/obi1kenobi/t...
github.com
Support default-value stability in rustdoc JSON v60. by obi1kenobi · Pull Request #1087 · obi1kenobi/trustfall-rustdoc-adapter
Unstable default values, such as provided function bodies in trait definitions, associated type defaults, and default values for associated constants, are treated as not present when indexing rustd...
111
Reposted by Predrag Gruevski
Predrag Gruevski @predr.ag · 01/07/2026
I had to take a brief detour to triage a surprising new class of SemVer breakage. It's always *a time* when the net result is "8 issues across 5 repos" 😅 The net result is the same: even more lints! github.com/obi1kenobi/c...
github.com
Breakage in items of reachable but not nameable supertrait · Issue #1658 · obi1kenobi/cargo-semver-checks
Example minified from time-rs/time#793 mod sealed { pub trait Sealed { fn example(&self) { ... } } } pub trait Visible: sealed::Sealed {} Now modify: mod sealed { pub trait Sealed { - fn example(&s...
152
Predrag Gruevski @predr.ag · 30/06/2026
Day 2 of trying to scan the Rust standard library for accidental breakage with cargo-semver-checks 👇
0120
Predrag Gruevski @predr.ag · 29/06/2026
I'm taking a few days off from work, let's see how far I can get with having cargo-semver-checks scan the Rust standard library for accidental breakage... Idea courtesy of a random hallway conversation with @amanieu.bsky.social at the Rust All Hands part of @rustnl.bsky.social this year.
1220
Reposted by Predrag Gruevski
RustNL @rustnl.bsky.social · 24/06/2026
'Writing a top-10 chess engine in Rust' by Cosmo Bobak and Kora at RustWeek 2026! www.youtube.com/watch?v=Gx21... #rustlang #RustWeek
youtube.com
Writing a top-10 chess engine in Rust (Kora & Cosmo Bobak at RustWeek)
Writing a top-10 chess engine in Rust by Cosmo Bobak and Kora. We’ll cover some of the most interesting or unique problems we encounter writing competitive chess engines and how Rust is excellently…
1132
Reposted by Predrag Gruevski
Peter Clines @peterclines.com · 23/06/2026
Okay, yes it's PRIME DAY. We're all very excited, but let's take a moment to make sure we're getting the most out of it. We don't want to waste this opportunity. 1/4
213532
Predrag Gruevski @predr.ag · 22/06/2026
"Safer `unsafe` with Codex and miri" is my walkthrough of shipping a real-world #rustlang performance optimization at OpenAI. AI lets us subject our work to 100x more scrutiny than before. We ship faster, because *we catch more bugs sooner.* www.youtube.com/watch?v=3Bcg...
youtube.com
Safer unsafe with Codex and miri (2026) - Predrag Gruevski
YouTube video by Rust East Coast
180
Predrag Gruevski @predr.ag · 21/06/2026
The parallels between the rise of CNC and AI are astonishing. We went from "this will de-skill machinists" to the modern marvels of engineering that we all take for granted, like the one I'm typing on. Another excellent video from @asianometry.bsky.social www.youtube.com/watch?v=OgXm...
youtube.com
Fanuc and the Numerical Control Revolution
YouTube video by Asianometry
121
Predrag Gruevski @predr.ag · 17/06/2026
I wear many hats in the #rustlang community — today I get another one. OpenAI is contributing $600,000 to the Rust Foundation, to become a Platinum Member and support both Rust development and the broader ecosystem. As part of this, I'll have the honor of joining the Foundation board 🙇‍♂️
9836
Reposted by Predrag Gruevski
The Rust Foundation @rustfoundation.org · 16/06/2026
Read the latest blog post by @joelmarcey.com (Rust Foundation Director of Technology) to learn more about new AI Security Engineer in Residence, Jacob Finkelman. This role was made possible for the #rustlang ecosystem with support from Alpha-Omega. rustfoundation.org/media/an-ai-...
rustfoundation.org
An AI Security Engineer in Residence for the Rust Ecosystem
Read Alpha-Omega's blog post about this exciting news here: https://alpha-omega.dev/blog/an-ai-security-engineer-in-residence-for-the-rust-ecosystem/ Since 2022, the Rust Foundation has run a…
061
Reposted by Predrag Gruevski
rain 🌦️ @sunshowers.io · 16/06/2026
Update: iddqd is now formally verified*! * with limitations that are fundamental to this kind of formal verification, making it a complement to the existing layers of validation For more, see: oxide.computer/blog/iddqd-u...
Update 2026-06-16: Since publication, we’ve used Soteria to verify that iddqd's no-duplicate-index invariant holds under arbitrarily adversarial Hash and Ord implementations. Soteria is similar to Kani in spirit, though with different internals that make it more compatible with iddqd. Soteria is implemented as a symbolic execution engine that lets you declare points of nondeterminism in your code. (For example, within iddqd, we represent an adversarial Hash or Ord return value as nondeterministic, since we want to model adversarially bad user code.) Then, it:

Compiles the Rust program into a form suitable for formal verification.
Interprets this form until it reaches a point of nondeterminism, treating each such point as a symbol rather than a concrete value.
Branches at each point where control flow depends on a symbol, validating that there is no UB and that the invariants specified by the program are upheld. A lot of the cleverness lies in how the possibility space is collapsed down to something manageable. For example, Soteria doesn’t have to enumerate every possible Hash value; rather, it only has to fork in places where control flow depends on the Hash value.
310312
Predrag Gruevski @predr.ag · 15/06/2026
You use AI to write more code. I use it to make my code more correct. We are not the same.
1284
Reposted by Predrag Gruevski
cosmo. @asteri.sm · 14/06/2026
there’s now a publicly-available recording of our RustWeek talk. it went extremely well, and I’m very proud of our work on it. talk is viewable @ youtu.be/Gx21yYLwn10 slides are hosted @ asteri.sm/assets/pdfs/...
youtu.be
Writing a top-10 chess engine in Rust (Kora & Cosmo Bobak at RustWeek)
YouTube video by RustNL
1257
Reposted by Predrag Gruevski
Tobias Bieniek @tobias.bieniek.cloud · 09/06/2026
🦀 🙄 😆 #rustlang
1231
Reposted by Predrag Gruevski
Mara Bos @mara.bsky.social · 04/06/2026
Since RustWeek took place in a cinema, we ended the closing session properly with a cinematic credits roll. ✨ If you missed it or want to see it again: 2026.rustweek.org/credits/
Still of the credits roll, displaying:

Organized by RustNL

Director
    Erik Jonkers 
    Mara Bos 
Volunteer organizer
    Laura Pircalaboiu 
    Jana Dönszelmann 
    Terts Diepraam 
Consultant
    Josine Kamperman (ONlive) 

Speakers
in order of appeareance

Main track
    Taylor Cramer 
    Waffle 
    Stefan Baumgartner 
    Rose Peck 
    Andreea Costea 
    Cliff L. Biffle

the last line is only partially visible, the rest is cut off.
2465
Predrag Gruevski @predr.ag · 04/06/2026
I am so mad about this. AI coding tools can be put to *great* use, and THIS ISN'T IT. Great AI use case: "help me find my bugs before my users find them" Not great AI use case: "half-ass my job for me"
2172
Reposted by Predrag Gruevski
Hillel @hillelwayne.com · 04/06/2026
The exploit: 1. Change your IP address to the target's geolocation and tell the support you've been hacked, asking them to send a reset to attacker email 2. No step 2. Meta's CISO immediately resigned. Gergely had inside contacts: the code was written by AI, reviewed by AI, while tokenmaxxing
125982
Predrag Gruevski @predr.ag · 01/06/2026
New cargo-semver-checks release 🦀 I'm hard at work on solving type checking lints, so this one is just a maintenance release — one new lint plus some bug fixes. Enjoy! github.com/obi1kenobi/c...
github.com
Release v0.48.0 · obi1kenobi/cargo-semver-checks
In this release One new lint: union_field_marked_deprecated False positive fix: do not report supertrait changes if switching between where and trait Name: Super syntaxes Bugfix: avoid erroneous c...
090
Reposted by Predrag Gruevski
S🦀sha @scrabsha.dev · 30/05/2026
i talked about view types with a lot of cool people last week - here are a few notes :3 scrabsha.dev/articles/one...
scrabsha.dev
One RustWeek of view_types | S🦀sha's blog
4375
Predrag Gruevski @predr.ag · 29/05/2026
Built-in `assert_matches!()` and more in Rust 1.96 🎉 blog.rust-lang.org/2026/05/28/R...
blog.rust-lang.org
Announcing Rust 1.96.0 | Rust Blog
Empowering everyone to build reliable and efficient software.
0131
Predrag Gruevski @predr.ag · 25/05/2026
Reflecting after the Rust All Hands: cargo-semver-checks is in a fascinating spot. We've never simultaneously had: - so many hard problems that must be solved at once - so many "this is hard but we're confident it'll work" solutions in flight at once Thrilling, but exhausting. But THRILLING 🦀
1251