Skip to content

Emit a warning around thin &CStr interior mutability breaks #118513

Description

@tgross35

From @chorman0773 https://rust-lang.zulipchat.com/#narrow/stream/219381-t-libs/topic/CStr.20as.20thin.20pointer/near/405432566

Passing an &UnsafeCell<CStr> to size_of_val is currently sound because it just returns the length parameter of the fat pointer. After making CStr thin however, size_of_val will need to call strlen on the data. This is not ok in a &UnsafeCell because another context could be writing the data, e.g. temporarily overwriting the \0.

This seems like something we may be able to emit a warning for?

Thin cstr: #59905

@rustbot label +T-libs +T-compiler +A-diagnostics

Activity

  1. added
    needs-triageThis issue may need triage. Remove when done. See docs forge.rust-lang.org/release/issue-triaging
    A-diagnosticsArea: Messages for errors, warnings, and lints
    T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.
    T-libsRelevant to the library team, which will review and decide on the PR/issue.
    on Dec 1, 2023
  2. tgross35 commented on Dec 1, 2023

    @tgross35
    MemberAuthor
  3. chorman0773 commented on Dec 1, 2023

    @chorman0773
    Contributor

    Incidentally, I wonder if &UnsafeCell<ThinCStr> itself is sound. I wonder if T-opsem should weigh in on that question. A write could happen and change the size of the memory the reference refers to, and the tag won't be correctly sized - maybe it will be shorter than the memory the reference refers to.

    &mut ThinCStr might also have similar issues.

  4. jmillikin commented on Dec 2, 2023

    @jmillikin
    Contributor

    Related: my RFC 3536 for !Sized thin pointers had to introduce a new ?Trait to prevent such types from being used with size_of_val(). In general the C concept of DSTs (pointer + computed value size) seems to be incompatible with the Rust semantics of T: ?Sized and size_of_val().

  5. removed
    needs-triageThis issue may need triage. Remove when done. See docs forge.rust-lang.org/release/issue-triaging
    on Dec 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    A-diagnosticsArea: Messages for errors, warnings, and lintsT-compilerRelevant to the compiler team, which will review and decide on the PR/issue.T-libsRelevant to the library team, which will review and decide on the PR/issue.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions