
Rust for DO-178C and ISO 26262
Until late 2025, Rust had a ceiling in avionics. Qualified Rust compilers existed, but only with support for certification efforts up to DO-178C DAL C. The highest software level, DAL A, requires Modified Condition/Decision Coverage (MC/DC), and no qualified MC/DC tooling existed for Rust.
AdaCore delivered GNATcoverage support for Rust in late 2025 to utilize the partial MC/DC instrumentation in the compiler behind the ‘unstable’ flag. AdaCore provided it as a supported feature of GNAT Pro for Rust 26, but the feature was removed from the mainline Rust compiler due to the maintenance burden.
AdaCore is now working with the Rust Foundation to build a robust, maintainable implementation of MC/DC support directly into the open-source Rust compiler. Combined with the qualification evidence and certified runtime libraries, this provides a practical solution for developing Rust for applications that require the highest level of functional safety per DO-178C and ISO 26262.
MC/DC matters
Code coverage is an important artifact for functional safety certification. It exists to document which source code was exercised by testing and which was not. Code coverage is described at different levels
- Statement coverage measures which lines of source code were executed.
- Decision coverage measures whether control structures are fully covered (for example, both the True and False sides of an if statement).
- Condition coverage requires that every sub-condition in a decision has been evaluated to both True and False.
- Modified Condition/Decision Coverage (MC/DC) is the most demanding: each condition must be shown to independently affect the overall decision outcome.
DO-178C requires statement coverage at DAL C, adds decision coverage at DAL B, and requires MC/DC at DAL A, the level applied to software whose failure would be catastrophic. In the automotive world, ISO 26262 does not require MC/DC. Still, it strongly recommends it at ASIL D. Without MC/DC tooling, a language is effectively excluded from the most critical software in automotive and aviation.
MC/DC in Rust
As mentioned, an experimental, partial MC/DC implementation was added to rustc in 2024 behind an unstable flag. In 2025, the Rust project removed it over valid maintainability concerns. That removal left the ecosystem without a path to MC/DC. AdaCore shipped a production-supported version in GNAT Pro for Rust 26.0, and is currently working with the Rust Foundation to reimplement the capability properly so it can live upstream as a standard, maintainable part of rustc in the open-source space.
Our goal is to have MC/DC available in the open-source Rust project, targeting the end of this year. GNAT Pro for Rust and GNAT DAS will include this new-and-improved capability with the long-term support and qualification evidence that certification projects require.
MC/DC and Rust's pattern matching: new ground
Rust poses a genuinely novel question for MC/DC. The established interpretations of MC/DC, as referenced in the DO 178C regulations, were written with languages like C and Ada in mind. Rust allows pattern matching at decision points, and a Rust match expression with or-patterns and guards does not cleanly map onto the classical notion of conditions and decisions.
Consider a pattern like if let (A | B, C(X | Y)) = value: which alternatives constitute independent conditions whose effect must be demonstrated? AdaCore's earlier work, together with the peer-reviewed paper Toward Modified Condition/Decision Coverage of Rust, provides a consistent interpretation of MC/DC for these constructs, giving certification authorities and verification analysts a defensible basis for coverage claims on Rust code.
Notably, the same body of work shows that the rustc-based coverage workflow only needs to reach the lowest tool qualification level (TQL-5) under DO-330, keeping the qualification effort within reasonable bounds. Rust at the DAL A is feasible.
Trusting the tools: qualification
A coverage result is only as trustworthy as the tool that produced it. Under DO-178C, verification tools such as coverage analyzers must be qualified per DO-330. AdaCore provides code coverage as part of the GNAT Dynamic Analysis Suite (DAS) and supplies the corresponding tool qualification material.
This also answers a fair question: if MC/DC lands in open-source rustc, what does AdaCore add on top of the open-source tooling? The answer is what open source alone cannot provide for a certification project: qualification evidence, long-term, sustained support for a frozen toolchain baseline, a qualified comprehensive analysis suite built on top of the open-source compiler, and customer support through engineers who build the technology.
The full stack: compiler and runtime, not just coverage
Coverage tooling is necessary but not sufficient. A certifiable Rust stack also needs a qualified compiler and certified runtime libraries. AdaCore's GNAT Pro for Rust is qualified for use in projects up to ASIL D, the highest level of ISO 26262, and, critically, this includes certification of the runtime libraries themselves, both libcore and liballoc. DO 178C qualification and certification are in progress and will be available soon; timelines are available through your AdaCore representatives.
The library point is important. Idiomatic Rust code needs at least bits of libcore and liballoc, and those bits need to be certified to the right level. Not all vendors provide certification to the highest level. For projects that need dynamic allocation or the full core library at the highest assurance levels, this is a real differentiator.
AdaCore also participates in the Safety-Critical Rust Consortium, contributing to the broader effort of making Rust viable for regulated industries.
Where AdaCore stands
AdaCore has decades of experience providing toolchains to projects that power our modern world, including projects that drive cars, fly airplanes, and manage other systems where functional safety against DO-178C, ISO 26262 or similar standards is mandatory. High-integrity software is our focus, whether in C, C++, Ada, SPARK, or now Rust. We support compilers for all these languages, help projects improve memory safety in C and C++ with our CodeSonar static analysis tools, and provide qualification and certification evidence where required, including certified language runtimes and a broad set of tools.
Rust offers compelling memory-safety properties, some enforced statically and others via runtime checks, and we've published a detailed comparison of the language designs of Rust, Ada, and SPARK. Rust has earned its place in the safety-critical conversation, and we're building and supporting the tooling to back that up.
Get involved
GNAT Pro for Rust and GNAT DAS will be ready to support Aerospace and Defense projects targeting DO-178C, ISO 26262, and other functional safety standards. We have real-world projects lined up and are excited to support them in bringing Rust into high-assurance functional safety projects.
FAQs
Reach out to your AdaCore representative for a sneak peek at the technology, book a chat with an expert here, or join our mailing list, and we'll keep you updated on our progress with code coverage for Rust.
Author
Mark Hermeling

Mark has over 25 years’ experience in software development tools for high-integrity, secure, embedded and real-time systems across automotive, aerospace, defence and industrial domains. As Head of Technical Marketing at AdaCore, he links technical capabilities to business value and is a regular author and speaker on on topics ranging from the software development lifecycle, DevSecOps to formal methods and software verification.
Latest Blog Posts

Claire Dross
From Raw Arrays to Typed Ownership: A Layered Allocator in SPARK

Olivier Henley
Ada-FPGA-Programmer: Configuring a Tang Nano 9K from Bare-Metal Ada, Built by Students

Kyriakos Georgiou, Paul Butcher


