Canonical funds AI-driven C-to-Rust rewrite of its AppArmor security tools

Canonical is funding University of Bristol researchers to test whether large language models can rewrite two of its security-critical C codebases, AppArmor's userspace tooling and snap-confine, into Rust without changing how they behave. The project, laid out in a proposal posted to Ubuntu's Discourse forum, treats code generation as the solved part of the problem and behavioral equivalence as the part still worth funding research on.
The Bristol team's system generates a Rust translation, then runs fuzzing alongside formal program analysis to catch cases where the new code compiles cleanly but handles an edge case differently than the original C did. When it finds a mismatch, the system attempts symbolic repair: tracing the exact failure and patching the generated code directly, rather than just flagging it for a human to redo.
AppArmor and snap-confine make a deliberately hard test case. Both parse and enforce security policy, so a translation that compiles but interprets a rule differently than the original C introduces a real vulnerability, not just a bug. The researchers also have to watch for the translator leaning on Rust's unsafe blocks to sidestep difficult C constructs, which would drag the same memory-safety risks into the rewritten code and defeat the point of moving to Rust at all.
Canonical isn't committing to ship either rewrite yet. The goal is narrower: find out what evidence would actually convince maintainers to trust an automated C-to-Rust translation at the scale of a real production codebase, hundreds of thousands of lines, not a benchmark.