The project, detailed by Google's bug hunters team, was carried out by software engineers Bastian Kersting and Max Hils. It follows a three-stage automated migration process designed around an autonomous feedback loop.
First, the team applied a single-shot prompt with Gemini to port the complete logic of the C library into Rust. Because the library needed to replace the existing shared object transparently without breaking downstream callers, the engineers retained the original exported symbols and struct definitions. Modelling the foreign function interface introduced unsound raw pointer semantics during initial iterations, requiring human experts to inspect and refine pointer ownership and lifetime invariants. Finally, automated differential testing engines detected behavioural discrepancies and fed the failure traces back to the model for iterative patch synthesis.
Memory corruption bugs represent roughly 70 per cent of severe security vulnerabilities in mature C and C++ stacks, according to Google. Rather than undertaking multi-year manual conversions or relying entirely on runtime bounds checking, the team demonstrated a novel pathway for eliminating legacy memory vulnerabilities at scale.
Deploying automatically generated code to mission-critical infrastructure required establishing semantic equivalence. The team delivered an ABI-compatible drop-in library written in Rust, neutralising the heap write zero-day prior to its public cataloguing.
Google framed the effort as a scalable alternative to the slow, manual rewrites that have characterised the industry's shift to memory-safe languages, suggesting AI-assisted translation could accelerate the elimination of entire classes of vulnerabilities across legacy infrastructure.