Skip to content

Allow UnsafeCell content access without get in invalid_reference_casting lint - #159960

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
Urgau:invalid_ref-safe-interior-mut
Jul 28, 2026
Merged

rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
Urgau:invalid_ref-safe-interior-mut

Conversation

@Urgau

@Urgau Urgau commented Jul 26, 2026

Copy link
Copy Markdown
Member

#159730 relaxed the rules so that it's no longer necessary to use UnsafeCell::raw_get or UnsafeCell::get to access the content of an unsafe cell.

As a consequence this means that code this like is no longer invalid:

use std::cell::UnsafeCell;

unsafe fn get_mut_unchecked<T>(ptr: &UnsafeCell<T>) -> &mut T {
    let t = ptr as *const UnsafeCell<T> as *mut T;
    unsafe { &mut *t }
}

Fixes #159915
cc @RalfJung

@rustbot rustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jul 26, 2026
@rustbot

rustbot commented Jul 26, 2026

Copy link
Copy Markdown
Collaborator

r? @mejrs

rustbot has assigned @mejrs.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 74 candidates
  • Random selection from 15 candidates

Comment on lines +289 to +323
// make sure we don't ICE on it when trying to
// determine if we should lint on it or not.
*((&std::cell::UnsafeCell::new(0)) as *const _ as *mut i32) = 5;

let cell = &std::cell::UnsafeCell::new(0);
let _num = &mut *(cell.get() as *mut i32);
let _num = &mut *(cell as *const _ as *mut i32);

fn safe_as_mut<T>(x: &std::cell::UnsafeCell<T>) -> &mut T {
unsafe fn get_mut_unchecked<T>(x: &std::cell::UnsafeCell<T>) -> &mut T {
unsafe { &mut *std::cell::UnsafeCell::raw_get(x as *const _ as *const _) }
}

fn cell_as_mut(x: &std::cell::Cell<i32>) -> &mut i32 {
unsafe fn get_mut_unchecked2<T>(ptr: &std::cell::UnsafeCell<T>) -> &mut T {
let t = ptr as *const std::cell::UnsafeCell<T> as *mut T;
unsafe { &mut *t }
}

unsafe fn cell_as_mut(x: &std::cell::Cell<i32>) -> &mut i32 {
unsafe { &mut *std::cell::UnsafeCell::raw_get(x as *const _ as *const _) }
}

unsafe fn cell_as_mut2(x: &std::cell::Cell<i32>) -> &mut i32 {
unsafe { &mut *(x as *const std::cell::Cell<i32> as *mut i32) }
}

#[repr(transparent)]
struct DoesContainUnsafeCell(std::cell::UnsafeCell<i32>);
fn safe_as_mut2(x: &DoesContainUnsafeCell) -> &mut DoesContainUnsafeCell {

unsafe fn get_mut_unchecked3(x: &DoesContainUnsafeCell) -> &mut DoesContainUnsafeCell {
unsafe { &mut *std::cell::UnsafeCell::raw_get(x as *const _ as *const _) }
}

unsafe fn get_mut_unchecked4(x: &DoesContainUnsafeCell) -> &mut DoesContainUnsafeCell {
unsafe { &mut *(x as *const DoesContainUnsafeCell as *mut _) }
}

@Urgau Urgau Jul 26, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@RalfJung could you double-check and confirm that all of those casts are now fine.

View changes since the review

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Depends on what you mean by "fine". ;)

They are not immediate UB. But getting a reference into a Cell is still incredibly dangerous. Just as dangerous as Cell::as_ptr though.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, by "fine" I mean no longer immediate UB, it can still be very UB. Thanks for checking.

@RalfJung

Copy link
Copy Markdown
Member

Wow that was fast ❤️

@Urgau
Urgau force-pushed the invalid_ref-safe-interior-mut branch from 714e85a to 3e3ab53 Compare July 26, 2026 11:33
@rustbot

rustbot commented Jul 26, 2026

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@mejrs

mejrs commented Jul 26, 2026

Copy link
Copy Markdown
Member

Are these casts valid? The lint, as implemented here, does not lint on them.

use std::cell::UnsafeCell;
use std::marker::PhantomData;

#[repr(transparent)]
struct MyUnsafeCell<T> {
    data: T,
    _p: PhantomData<UnsafeCell<T>>,
}

unsafe fn cast<T>(ptr: &MyUnsafeCell<T>) -> &mut T {
    let t = ptr as *const MyUnsafeCell<T> as *mut T;
    unsafe { &mut *t }
}

and

unsafe fn cast<T>(ptr: &UnsafeCell<T>) -> &mut UnsafeCell<T> {
    let t = ptr as *const _ as *mut _;
    unsafe { &mut *t }
}

@RalfJung

Copy link
Copy Markdown
Member

Those casts are both dangerous but not immediate UB.

@Morgane55440

Copy link
Copy Markdown

Those casts are both dangerous but not immediate UB.

@RalfJung are you sure ? the first one triggers miri instantaneously.

use std::cell::UnsafeCell;
use std::marker::PhantomData;

#[repr(transparent)]
struct MyUnsafeCell<T> {
    data: T,
    _p: PhantomData<UnsafeCell<T>>,
}

#[allow(invalid_reference_casting)]
unsafe fn cast<T>(ptr: &MyUnsafeCell<T>) -> &mut T {
    let t = ptr as *const MyUnsafeCell<T> as *mut T;
    unsafe { &mut *t }
}

fn main() {
    let mut c : MyUnsafeCell<u8> = MyUnsafeCell { data : 2, _p : PhantomData };
    unsafe {cast(&mut c) };
}
Undefined Behavior: trying to retag from <367> for Unique permission at alloc194[0x0], but that tag only grants SharedReadOnly permission for this location
  --> src/main.rs:19:14
   |
19 |     unsafe { &mut *t }
   |              ^^^^^^^ this error occurs as part of retag at alloc194[0x0..0x1]

@RalfJung

RalfJung commented Jul 27, 2026 •

Copy link
Copy Markdown
Member

Oh wait I didn't read the example properly. I thought you were asking about what cast does to an unsafe cell, not about a weird custom type. What is that MyUnsafeCell type doing? That indeed makes no sense.

Please always give context for questions like this to make it more likely I look at the right parts of the code. Dumping an uncommented piece of code with weird corner cases without even mentioning the thought process that lead to the example isn't a good way to ask a question. Unfortunately I am often in a rush so I only dig deeper when there's some clear indication where to dig. Sorry for that.

OTOH the lint is not expected to find all UB so not linting on these is not necessarily a problem.

@mejrs

mejrs commented Jul 27, 2026

Copy link
Copy Markdown
Member

Please always give context for questions like this

My apologies, I was also a bit in a rush myself 😅

Anyway, my mental model of interior mutability is that you always have to go through/pierce/peel/unwrap (what's the precise language for this?) UnsafeCell. Whether that is by using get or casting away the UnsafeCell, you must "peel away" a UnsafeCell wrapper.

But in the second example:

unsafe fn cast<T>(ptr: &UnsafeCell<T>) -> &mut UnsafeCell<T> {
    let t = ptr as *const _ as *mut _;
    unsafe { &mut *t }
}

...we cast the UnsafeCell itself, we don't peel it away Is that also OK?

OTOH the lint is not expected to find all UB so not linting on these is not necessarily a problem.

That's true, it doesn't have to be perfect. However what I see occasionally is:

  • a (often very inexperienced in Rust) programmer will trigger a ub related lint
  • they'll rationalize to themselves that their code is actually ok (this works in C, my program is single threaded, etc)
  • they'll reshape their code without changing the semantics but in a way that the lint no longer understands
  • they move on

It would be nice to make them jump a little bit higher.

@mejrs mejrs left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Regardless, the impl looks good to me so no need to block on anything.

@Urgau up to you if you want to make the lint smarter, either here or in a followup

r=me (after nits) if not

View changes since this review

Comment thread compiler/rustc_lint/src/reference_casting.rs Outdated
Comment thread compiler/rustc_lint/src/reference_casting.rs
@RalfJung

RalfJung commented Jul 27, 2026 •

Copy link
Copy Markdown
Member

Anyway, my mental model of interior mutability is that you always have to go through/pierce/peel/unwrap (what's the precise language for this?) UnsafeCell

That's not quite right. It's more that UnsafeCell "punches a hole" in the immutability requirement of &. So if you have &(i32, Cell<i32>, i32) (if we assume a linear layout) then & enforces immutability of bytes 0..4 and 8..12, but does not enforce anything for bytes 4..8. That's why you can mutate those bytes but not the others. It does not matter if you go "through" an UnsafeCell, you just have to ensure that all of the live shared references pointing to this memory have an UnsafeCell on the bytes you mutate.

That's why the 2nd example is okay.

@Urgau
Urgau force-pushed the invalid_ref-safe-interior-mut branch from 3e3ab53 to 6b0ea30 Compare July 27, 2026 19:23
@Urgau

Urgau commented Jul 27, 2026

Copy link
Copy Markdown
Member Author

@bors r=mejrs

@rust-bors

rust-bors Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

📌 Commit 6b0ea30 has been approved by mejrs

It is now in the queue for this repository.

🌲 The tree is currently closed for pull requests below priority 100. This pull request will be tested once the tree is reopened.

Reason for tree closure: spurious failures

@rust-bors rust-bors Bot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Jul 27, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Jul 28, 2026
…t, r=mejrs

Allow `UnsafeCell` content access without `get` in `invalid_reference_casting` lint

rust-lang#159730 relaxed the rules so that it's no longer necessary to use `UnsafeCell::raw_get` or `UnsafeCell::get` to access the content of an unsafe cell.

As a consequence this means that code this like is no longer invalid:
```rust
use std::cell::UnsafeCell;

unsafe fn get_mut_unchecked<T>(ptr: &UnsafeCell<T>) -> &mut T {
    let t = ptr as *const UnsafeCell<T> as *mut T;
    unsafe { &mut *t }
}
```

Fixes rust-lang#159915
cc @RalfJung
rust-bors Bot pushed a commit that referenced this pull request Jul 28, 2026
Rollup of 9 pull requests

Successful merges:

 - #153563 (Lint against iterator functions that panic when `N` is zero )
 - #159960 (Allow `UnsafeCell` content access without `get` in `invalid_reference_casting` lint)
 - #158893 (Clarify preconditions of raw size/align methods)
 - #159220 (Don't optimize across storage markers in SimplifyComparisonIntegral)
 - #159309 (Move tests batch 18)
 - #159450 (Add codegen test for enum clone)
 - #160017 (Make BorrowSet methods public again)
 - #160022 (Refactor rustc_hir re-exports)
 - #160041 (Correct tracking issue for `casefold` feature)
@rust-bors
rust-bors Bot merged commit 1b03eec into rust-lang:main Jul 28, 2026
13 checks passed
@rustbot rustbot added this to the 1.99.0 milestone Jul 28, 2026
rust-timer added a commit that referenced this pull request Jul 28, 2026
Rollup merge of #159960 - Urgau:invalid_ref-safe-interior-mut, r=mejrs

Allow `UnsafeCell` content access without `get` in `invalid_reference_casting` lint

#159730 relaxed the rules so that it's no longer necessary to use `UnsafeCell::raw_get` or `UnsafeCell::get` to access the content of an unsafe cell.

As a consequence this means that code this like is no longer invalid:
```rust
use std::cell::UnsafeCell;

unsafe fn get_mut_unchecked<T>(ptr: &UnsafeCell<T>) -> &mut T {
    let t = ptr as *const UnsafeCell<T> as *mut T;
    unsafe { &mut *t }
}
```

Fixes #159915
cc @RalfJung
@BoxyUwU BoxyUwU added the relnotes Marks issues that should be documented in the release notes of the next release. label Jul 31, 2026
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Jul 31, 2026
…l, r=mejrs

More accurately check for interior mutability in `invalid_reference_casting` lint

This PR replaces the `Freeze` trait check in the `invalid_reference_casting` lint by a recursive type check.

The check was not enough to determine if a type has "interior mutability", as `Freeze` is proxy for "has *some* interior mutability", not "fully covered by interior mutability".

As requested in rust-lang#159960 (comment)
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Jul 31, 2026
…l, r=mejrs

More accurately check for interior mutability in `invalid_reference_casting` lint

This PR replaces the `Freeze` trait check in the `invalid_reference_casting` lint by a recursive type check.

The check was not enough to determine if a type has "interior mutability", as `Freeze` is proxy for "has *some* interior mutability", not "fully covered by interior mutability".

As requested in rust-lang#159960 (comment)
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Jul 31, 2026
…l, r=mejrs

More accurately check for interior mutability in `invalid_reference_casting` lint

This PR replaces the `Freeze` trait check in the `invalid_reference_casting` lint by a recursive type check.

The check was not enough to determine if a type has "interior mutability", as `Freeze` is proxy for "has *some* interior mutability", not "fully covered by interior mutability".

As requested in rust-lang#159960 (comment)
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Jul 31, 2026
…l, r=mejrs

More accurately check for interior mutability in `invalid_reference_casting` lint

This PR replaces the `Freeze` trait check in the `invalid_reference_casting` lint by a recursive type check.

The check was not enough to determine if a type has "interior mutability", as `Freeze` is proxy for "has *some* interior mutability", not "fully covered by interior mutability".

As requested in rust-lang#159960 (comment)
rust-timer added a commit that referenced this pull request Jul 31, 2026
Rollup merge of #160159 - Urgau:invalid_ref_casts-unsafe-cell, r=mejrs

More accurately check for interior mutability in `invalid_reference_casting` lint

This PR replaces the `Freeze` trait check in the `invalid_reference_casting` lint by a recursive type check.

The check was not enough to determine if a type has "interior mutability", as `Freeze` is proxy for "has *some* interior mutability", not "fully covered by interior mutability".

As requested in #159960 (comment)
github-actions Bot pushed a commit to rust-lang/rustc-dev-guide that referenced this pull request Aug 3, 2026
More accurately check for interior mutability in `invalid_reference_casting` lint

This PR replaces the `Freeze` trait check in the `invalid_reference_casting` lint by a recursive type check.

The check was not enough to determine if a type has "interior mutability", as `Freeze` is proxy for "has *some* interior mutability", not "fully covered by interior mutability".

As requested in rust-lang/rust#159960 (comment)
flip1995 pushed a commit to flip1995/rust-clippy that referenced this pull request Aug 17, 2026
Rollup of 9 pull requests

Successful merges:

 - rust-lang/rust#153563 (Lint against iterator functions that panic when `N` is zero )
 - rust-lang/rust#159960 (Allow `UnsafeCell` content access without `get` in `invalid_reference_casting` lint)
 - rust-lang/rust#158893 (Clarify preconditions of raw size/align methods)
 - rust-lang/rust#159220 (Don't optimize across storage markers in SimplifyComparisonIntegral)
 - rust-lang/rust#159309 (Move tests batch 18)
 - rust-lang/rust#159450 (Add codegen test for enum clone)
 - rust-lang/rust#160017 (Make BorrowSet methods public again)
 - rust-lang/rust#160022 (Refactor rustc_hir re-exports)
 - rust-lang/rust#160041 (Correct tracking issue for `casefold` feature)
dressupgeekout pushed a commit to dressupgeekout/pkgsrc-wip that referenced this pull request Oct 2, 2026
Pkgsrc changes:
 * Adapt to changes in vendored crate versions.
 * Version & checksum changes.

Upstream changes:

Version 1.99.0 (2026-10-01)
==========================

Language
--------
- [Add allow-by-default `raw_borrows_via_references` lint that
  checks for references that decay immediately into raw
  borrows](rust-lang/rust#138230)
- [Extend `unconditional_panic` lint to function calls that panic
  when the chunks/windows size is zero]
  (rust-lang/rust#153563)
- [Stabilize C-variadic function definitions]
  (rust-lang/rust#155697)
- [Stabilize the ability to use `#[unsafe(naked)]` functions to
  define C-variadic functions (`#![feature(c_variadic_naked_functions)]`).]
  (rust-lang/rust#159746)
- [Trait methods are now resolved on an adjusted never type (producing a FCW)]
  (rust-lang/rust#156047)
- [Coerce from inference variables to trait objects if the inference
  variable is related via subtyping to a type that is known to be `Sized`]
  (rust-lang/rust#157820)
- [Stabilize `#[my_macro] mod foo;`]
  (rust-lang/rust#157857). This allows
  outlined modules (`mod foo;`) anywhere in the body of a custom
  attribute or derive macro.
- [Fix the `overflowing_literals` lint with repeated negation]
  (rust-lang/rust#158302). For instance,
  it will now no longer lint on `--128_i8`, which is already detected
  by the `arithmetic_overflow` lint.
- [Add POSIX symbols to the `invalid_runtime_symbol_definitions`
  and `suspicious_runtime_symbol_definitions` lints]
  (rust-lang/rust#158522)
- [Lint unused `#[path]` attributes on inline modules]
  (rust-lang/rust#158835)
- [Enable `unreachable_cfg_select_predicates` lint as part of
  `unused` lint group] (rust-lang/rust#159179)
- [Stabilize passing 128-bit integers via vector registers with `asm!` on x86]
  (rust-lang/rust#159525)
- [Explicitly document that some allocations are allowed to grow
  in-place (but none are allowed to shrink)]
  (rust-lang/rust#159729)
- We now [guarantee]
  (rust-lang/rust#159730) that the contents
  of an `UnsafeCell` can be accessed without going through `get`
  - [The `invalid_reference_casting` lint was adjusted accordingly]
  (rust-lang/rust#159960)
- [Account for globally enabled target features in `global_asm!`]
  (rust-lang/rust#160594)
- [Warn if an invalid `doc` attribute is used on a macro invocation]
  (rust-lang/rust#161003)

Compiler
--------
- [Convert `-Ctarget-cpu` into a target-modifier for AVR, AMDGCN and NVPTX]
  (rust-lang/rust#150732)
- [Enable `static_position_independent_executables` on all gnu and musl targets]
  (rust-lang/rust#158510)
- When providing a suggestion about a missing method, rustc now
  prefers an exactly matching name from a [doc alias attribute]
  (https://doc.rust-lang.org/rustdoc/advanced-features.html#add-aliases-for-an-item-in-documentation-search)
  over a similarity search from other method names. If your new
  users sometimes expect a method under a different name, adding
  a doc alias will now help them find it via rustc suggestions, in
  addition to helping them find it via rustdoc search: [When
  suggesting method names, prefer *exact* doc aliases over similar
  names](rust-lang/rust#160369)

Platform Support
----------------
- [Promote `riscv64-unknown-linux-musl` to Tier 2 with host tools]
  (rust-lang/rust#158766)

Refer to Rust's [platform support page][platform-support-doc]
for more information on Rust's tiered platform support.

[platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html

Libraries
---------
- Iteration on `RangeInclusive` (`a..=b` ranges) is now [optimized
  better in some circumstances]
  (rust-lang/rust#155114). As a side effect
  of this, the behavior of `RangeInclusive` values that has already
  been exhausted (as an iterator) has changed. For example, the
  return values of `start()` and `end()` on such ranges may return
  different values, and using such ranges as slice indexes may have
  different behavior. These behaviors were not guaranteed to be
  stable, so these changes are considered to not be breaking changes.
- [Relax `transmute_copy` to accept `?Sized` types]
  (rust-lang/rust#155989)
- [Update `transmute_copy` to use a non-unwinding panic]
  (rust-lang/rust#155989)
- [Don't escape U+FF9E and U+FF9F in `escape_debug_ext`]
  (rust-lang/rust#158057)
- [Re-export `core::fmt::NumBuffer` in `alloc` (and `std`)]
  (rust-lang/rust#161430)

Stabilized APIs
---------------

- [`IntoIterator` for `Box<[T; N]>`]
  (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-Box%3C%5BT;+N%5D,+A%3E)
- [`IntoIterator` for `&Box<[T; N]>`]
  (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-%26Box%3C%5BT;+N%5D,+A%3E)
- [`IntoIterator` for `&mut Box<[T; N]>`]
  (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-%26mut+Box%3C%5BT;+N%5D,+A%3E)
- [`VecDeque::retain_back`]
  (https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.retain_back)
- [`core::ffi::VaList`]
  (https://doc.rust-lang.org/stable/core/ffi/struct.VaList.html)
- [`Box::into_non_null`]
  (https://doc.rust-lang.org/stable/std/boxed/struct.Box.html#method.into_non_null)
- [`Box::from_non_null`]
  (https://doc.rust-lang.org/stable/std/boxed/struct.Box.html#method.from_non_null)
- [`Vec::into_parts`]
  (https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.into_parts)
- [`Vec::from_parts`]
  (https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.from_parts)
- [`core::mem::size_of_val_raw`]
  (https://doc.rust-lang.org/stable/core/mem/fn.size_of_val_raw.html)
- [`core::mem::align_of_val_raw`]
  (https://doc.rust-lang.org/stable/core/mem/fn.align_of_val_raw.html)
- [`core::alloc::Layout::for_value_raw`]
  (https://doc.rust-lang.org/stable/core/alloc/struct.Layout.html#method.for_value_raw)
- [`String::from_utf8_lossy_owned`]
  (https://doc.rust-lang.org/stable/std/string/struct.String.html#method.from_utf8_lossy_owned)
- [`string::FromUtf8Error::into_utf8_lossy`]
  (https://doc.rust-lang.org/stable/std/string/struct.FromUtf8Error.html#method.into_utf8_lossy)
- [`FusedIterator for StepBy<I>`]
  (https://doc.rust-lang.org/stable/std/iter/struct.StepBy.html#impl-FusedIterator-for-StepBy%3CI%3E)
- [`std::fs::set_times`]
  (https://doc.rust-lang.org/stable/std/fs/fn.set_times.html)
- [`std::fs::set_times_nofollow`]
  (https://doc.rust-lang.org/stable/std/fs/fn.set_times_nofollow.html)

Cargo
-----
- Add a new built-in profile `debug`. This is a preparation for
  transitioning the `dev` profile away from debugging to give a saner
  default for faster development iterations. Currently there is no
  difference between `dev` and `debug` profiles. [docs]
  (https://doc.rust-lang.org/nightly/cargo/reference/profiles.html#debug-1)
  [#17214] (rust-lang/cargo#17214)
- Workspace members on edition 2024 or later can now override an
  inherited workspace dependency's `default-features` field. For
  example, `serde = { workspace = true, default-features = false }`
  now turns off default features even when the workspace definition
  enables them. On earlier editions, `default-features = false` is
  ignored with a warning. ([RFC 3945]
  (rust-lang/rfcs#3945))
  [#17126](rust-lang/cargo#17126)
- Incremental compilation is now disabled by default when running
  in CI. CI is detected via the CI environment variable. [#17220]
  (rust-lang/cargo#17220)
  See also the [full Cargo changelog]
  (https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html#cargo-199-2026-10-01)

Rustdoc
-----
- [Add new `unused_footnote_definition` rustdoc lint]
  (rust-lang/rust#137858)
- Smarter filtering of trait impls yields performance improvements
  of 20% on average and up to 40% on some real-world crates. ([1]
  (rust-lang/rust#159623),
  [2](rust-lang/rust#159721),
  [3](rust-lang/rust#159779),
  [4](rust-lang/rust#159854),
  [5](rust-lang/rust#159091))

Compatibility Notes
-------------------
- [Fully deprecate the legacy integral modules]
  (rust-lang/rust#146882). For example,
  `std::i32::MAX` should be accessed via `i32::MAX` instead.
- [Upgrade `no_mangle_generic_items` into hard error]
  (rust-lang/rust#154585)
- [The `Pin::new_unchecked` has had its safety invariants changed slightly]
  (rust-lang/rust#156935)
- [Do not promote references to extern statics]
  (rust-lang/rust#157641)
- [Ensure that the inferred types of `let` patterns typecheck]
  (rust-lang/rust#157841)
- [hermit/fs: Return `unsupported()` instead of `from_raw_os_error(22)`]
  (rust-lang/rust#158247)
- [Fixed a bug where `#[repr(simd)]` was accidentally allowed on
  macro invocations on stable Rust]
  (rust-lang/rust#158523)
- [Abort const-eval when there are generics in the type of the
  value being produced]
  (rust-lang/rust#159504)
- [Attributes not applying to anything are now an error in code
  blocks in doc comments]
  (rust-lang/rust#159849)
- [`Box::leak`: tell people to avoid unleaking]
  (rust-lang/rust#160323)
- [PowerPC inline ASM: Fix scalar floats being in the wrong vector
  lane on little endian] (rust-lang/rust#160441)
- [Do not take `doc(cfg())` into account when filtering doctests]
  (rust-lang/rust#159014)
- [Infer anonymous lifetimes in the types of associated consts as `'static`]
  (rust-lang/rust#156508)
- Macros that expand to a semicolon now produce a warning lint
  (`semicolon_in_expressions_from_non_local_macros`) even when the
  macro comes from another crate. Previously, such warnings only
  appeared for macros from the same crate, to avoid showing warnings
  that can't be fixed locally; however, this masked problems, as
  integration tests from the crate providing the macro get compiled
  as a separate crate, so tests often wouldn't reveal this issue. If
  you encounter a lint like this, please make sure to report it to
  the crate providing the macro so they can fix it; don't just silence
  it in your own crate.
  - [`semicolon_in_expressions_from_macros`: Lint on non-local
    macros too] (rust-lang/rust#159222)
  - [Split non-local `semicolon_in_expressions_from_macros` into
    a separate lint] (rust-lang/rust#159700)

Internal Changes
----------------

These changes do not affect any public interfaces of Rust, but they represent
significant improvements to the performance or internals of rustc and related
tools.

- [Update to LLVM 23]
  (rust-lang/rust#158734)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

relnotes Marks issues that should be documented in the release notes of the next release. S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

invalid_reference_casting fires for correct usage of UnsafeCell

6 participants