Skip to content

Commit 74843d3

Browse files
committed
Auto merge of rust-lang#103957 - JakobDegen:drop-retag, r=RalfJung
Retag as FnEntry on `drop_in_place` This commit changes the mir drop shim to always retag its argument as if it were a `&mut`. cc rust-lang/unsafe-code-guidelines#373
2 parents e827c69 + adc3f44 commit 74843d3

File tree

6 files changed

+146
-0
lines changed

6 files changed

+146
-0
lines changed
Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
//! Test that drop_in_place retags the entire place,
2+
//! invalidating all aliases to it.
3+
4+
// A zero-sized drop type -- the retagging of `fn drop` itself won't
5+
// do anything (since it is zero-sized); we are entirely relying on the retagging
6+
// in `drop_in_place` here.
7+
#[repr(transparent)]
8+
struct HasDrop;
9+
impl Drop for HasDrop {
10+
fn drop(&mut self) {
11+
unsafe {
12+
let _val = *P;
13+
//~^ ERROR: /not granting access .* because that would remove .* which is strongly protected/
14+
}
15+
}
16+
}
17+
18+
static mut P: *mut u8 = core::ptr::null_mut();
19+
20+
fn main() {
21+
unsafe {
22+
let mut x = (HasDrop, 0u8);
23+
let x = core::ptr::addr_of_mut!(x);
24+
P = x.cast();
25+
core::ptr::drop_in_place(x);
26+
}
27+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
error: Undefined Behavior: not granting access to tag <TAG> because that would remove [Unique for <TAG>] which is strongly protected because it is an argument of call ID
2+
--> $DIR/drop_in_place_protector.rs:LL:CC
3+
|
4+
LL | let _val = *P;
5+
| ^^ not granting access to tag <TAG> because that would remove [Unique for <TAG>] which is strongly protected because it is an argument of call ID
6+
|
7+
= help: this indicates a potential bug in the program: it performed an invalid operation, but the Stacked Borrows rules it violated are still experimental
8+
= help: see https://github.com/rust-lang/unsafe-code-guidelines/blob/master/wip/stacked-borrows.md for further information
9+
help: <TAG> was created by a SharedReadWrite retag at offsets [0x0..0x1]
10+
--> $DIR/drop_in_place_protector.rs:LL:CC
11+
|
12+
LL | let x = core::ptr::addr_of_mut!(x);
13+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^
14+
help: <TAG> is this argument
15+
--> $DIR/drop_in_place_protector.rs:LL:CC
16+
|
17+
LL | core::ptr::drop_in_place(x);
18+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^
19+
= note: BACKTRACE:
20+
= note: inside `<HasDrop as std::ops::Drop>::drop` at $DIR/drop_in_place_protector.rs:LL:CC
21+
= note: inside `std::ptr::drop_in_place::<HasDrop> - shim(Some(HasDrop))` at RUSTLIB/core/src/ptr/mod.rs:LL:CC
22+
= note: inside `std::ptr::drop_in_place::<(HasDrop, u8)> - shim(Some((HasDrop, u8)))` at RUSTLIB/core/src/ptr/mod.rs:LL:CC
23+
note: inside `main`
24+
--> $DIR/drop_in_place_protector.rs:LL:CC
25+
|
26+
LL | core::ptr::drop_in_place(x);
27+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^
28+
= note: this error originates in the macro `core::ptr::addr_of_mut` (in Nightly builds, run with -Z macro-backtrace for more info)
29+
30+
note: some details are omitted, run with `MIRIFLAGS=-Zmiri-backtrace=full` for a verbose backtrace
31+
32+
error: aborting due to previous error
33+
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
//! Test that drop_in_place mutably retags the entire place, even for a type that does not need
2+
//! dropping, ensuring among other things that it is writeable
3+
4+
//@error-pattern: /retag .* for Unique permission .* only grants SharedReadOnly permission/
5+
6+
fn main() {
7+
unsafe {
8+
let x = 0u8;
9+
let x = core::ptr::addr_of!(x);
10+
core::ptr::drop_in_place(x.cast_mut());
11+
}
12+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
error: Undefined Behavior: trying to retag from <TAG> for Unique permission at ALLOC[0x0], but that tag only grants SharedReadOnly permission for this location
2+
--> RUSTLIB/core/src/ptr/mod.rs:LL:CC
3+
|
4+
LL | pub unsafe fn drop_in_place<T: ?Sized>(to_drop: *mut T) {
5+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
6+
| |
7+
| trying to retag from <TAG> for Unique permission at ALLOC[0x0], but that tag only grants SharedReadOnly permission for this location
8+
| this error occurs as part of retag at ALLOC[0x0..0x1]
9+
|
10+
= help: this indicates a potential bug in the program: it performed an invalid operation, but the Stacked Borrows rules it violated are still experimental
11+
= help: see https://github.com/rust-lang/unsafe-code-guidelines/blob/master/wip/stacked-borrows.md for further information
12+
help: <TAG> was created by a SharedReadOnly retag at offsets [0x0..0x1]
13+
--> $DIR/drop_in_place_retag.rs:LL:CC
14+
|
15+
LL | let x = core::ptr::addr_of!(x);
16+
| ^^^^^^^^^^^^^^^^^^^^^^
17+
= note: BACKTRACE:
18+
= note: inside `std::ptr::drop_in_place::<u8> - shim(None)` at RUSTLIB/core/src/ptr/mod.rs:LL:CC
19+
note: inside `main`
20+
--> $DIR/drop_in_place_retag.rs:LL:CC
21+
|
22+
LL | core::ptr::drop_in_place(x.cast_mut());
23+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
24+
= note: this error originates in the macro `core::ptr::addr_of` (in Nightly builds, run with -Z macro-backtrace for more info)
25+
26+
note: some details are omitted, run with `MIRIFLAGS=-Zmiri-backtrace=full` for a verbose backtrace
27+
28+
error: aborting due to previous error
29+
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
#[repr(transparent)]
2+
struct HasDrop(u8);
3+
4+
impl Drop for HasDrop {
5+
fn drop(&mut self) {}
6+
}
7+
8+
#[repr(C, align(2))]
9+
struct PartialDrop {
10+
a: HasDrop,
11+
b: u8,
12+
}
13+
14+
//@error-pattern: /alignment 2 is required/
15+
fn main() {
16+
unsafe {
17+
// Create an unaligned pointer
18+
let mut x = [0_u16; 2];
19+
let p = core::ptr::addr_of_mut!(x).cast::<u8>();
20+
let p = p.add(1);
21+
let p = p.cast::<PartialDrop>();
22+
23+
core::ptr::drop_in_place(p);
24+
}
25+
}
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
error: Undefined Behavior: accessing memory with alignment ALIGN, but alignment ALIGN is required
2+
--> RUSTLIB/core/src/ptr/mod.rs:LL:CC
3+
|
4+
LL | pub unsafe fn drop_in_place<T: ?Sized>(to_drop: *mut T) {
5+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ accessing memory with alignment ALIGN, but alignment ALIGN is required
6+
|
7+
= help: this indicates a bug in the program: it performed an invalid operation, and caused Undefined Behavior
8+
= help: see https://doc.rust-lang.org/nightly/reference/behavior-considered-undefined.html for further information
9+
= note: BACKTRACE:
10+
= note: inside `std::ptr::drop_in_place::<PartialDrop> - shim(Some(PartialDrop))` at RUSTLIB/core/src/ptr/mod.rs:LL:CC
11+
note: inside `main`
12+
--> $DIR/drop_in_place.rs:LL:CC
13+
|
14+
LL | core::ptr::drop_in_place(p);
15+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^
16+
17+
note: some details are omitted, run with `MIRIFLAGS=-Zmiri-backtrace=full` for a verbose backtrace
18+
19+
error: aborting due to previous error
20+

0 commit comments

Comments
 (0)