Do not promote extern statics - #157641
Conversation
|
Some changes occurred to MIR optimizations cc @rust-lang/wg-mir-opt |
|
r? @oli-obk rustbot has assigned @oli-obk. Use Why was this reviewer chosen?The reviewer was selected based on:
|
This comment has been minimized.
This comment has been minimized.
6257168 to
80ac224
Compare
This comment has been minimized.
This comment has been minimized.
80ac224 to
8877f4c
Compare
This comment has been minimized.
This comment has been minimized.
|
Some changes occurred to the CTFE machinery Some changes occurred to constck cc @fee1-dead |
|
So... This is technically a breaking change, as we now have a new const check, which previously only errored if actually evaluated. So an associated const could now error, if it previously was unused in the current crate. A different oddity is that we don't check this in const fns, as those can be fine at runtime, as long as the extern static is never read at compile time. Thoughts @rust-lang/wg-const-eval? |
|
crater than FCP merge in that case? |
The PR changes const-checking, not promotion. Something seems wrong, what is this actually trying to fix? This looks like an ad-hoc special case in const checking; I am not sure what this buys us since it can be trivially bypassed (by creating a pointer and then deref'ing it). To fix #143174, I would have expected this to change promotion ( |
|
We already avoid promotion in this: fn main() { unsafe {
let f: &Foo = &Foo(BAR);
} }Why do we promote in the other case? |
|
This PR originally had a promotion time check. Preventing it in const check covers exactly the problematic use case, as everything else doesn't get promoted. |
|
I don't think we should fix a promotion bug by changing const-checking. That's a very non-local invariant relying on the subtle interplay of which exact code gets rejected where. Promotion on its own is supposed to only accept code that cannot fail to evaluate. It apparently does not do this job properly. |
The original version of this PR actually did modify promotion; the diff is available here: 8877f4c. We decided to change it because the original logic felt too messy: #157641 (comment), and I just forgot to change the PR description after making the change.
Promotion is gated behind fn main case never gets promoted, even though both desugar to "deref of a static addr."
|
|
That check already special-cases thread-local statics here: It is very common in the interpreter to treat thread-local statics and extern statics the same, so what I would have expected is that we add |
|
I actually did try that at first, just adding since For instance, in the non-problematic case, extern "C" {
static X: i32;
}
static mut FOO: *const &i32 = [unsafe { &X }].as_ptr();gets lowered to after promotion, and since extern "C" {
static BAR: i32;
}
static FOO: &(i32,) = unsafe { &(BAR,) };gets lowered to where the |
|
Yeah I think we should reject such promotion (unless crater disagrees). People can use |
|
Cool, let's try that then and crater it. Seems very niche |
168eebd to
3e8d36a
Compare
|
The final comment period, with a disposition to merge, as per the review above, is now complete. As the automated representative of the governance process, I would like to thank the author for their work and everyone else who contributed. |
Reference update for rust-lang/rust#157641: a borrow of an extern static is never eligible for constant promotion, even when the reference itself is never read from.
|
📋 This PR cannot be approved because it currently has the following labels: |
…promotion, r=oli-obk,traviscross Do not promote extern statics We already reject thread-local statics during promotion, so extend that check to extern statics as well. fixes rust-lang#143174
…uwer Rollup of 21 pull requests Successful merges: - #159784 (Hint that memchr returns an in-bounds index) - #150885 (Revive L4Re target) - #159643 (Add support for splatted function pointers) - #160433 (delegation: add support for wrapping of the return value with `From::from`) - #160530 (refactor handling of target features in Session) - #160606 (bootstrap: Store and use an explicit CheckKind in `check::Rustc`) - #160628 (fix ICE in `suggest_add_reference_to_arg` for non-callable items) - #160634 (miri subtree update) - #157641 (Do not promote extern statics) - #158904 (Fix FutureDropPoll shim for by-move async closures) - #160103 (Add regression test for GAT bound mismatched type error) - #160335 (dlopen offload) - #160445 (codegen: classify localized MSVC linker progress as linker_info) - #160499 (rustc_resolve: move diagnostic attribute linting to attr parsing) - #160504 (cleanup borrowck, improve c-variadic handling) - #160577 (expand: Feature gate AST-based attribute macros on expressions and statements) - #160587 (Add regression test for associated type outlives bound at call site) - #160625 (platform-support/netbsd.md: No longer mention 8.x, due to EoL.) - #160636 (derive(Diagnostic): link to proper docs) - #160644 (Clean up some manual debug impls) - #160649 (move naked function ui tests)
…promotion, r=oli-obk,traviscross Do not promote extern statics We already reject thread-local statics during promotion, so extend that check to extern statics as well. fixes rust-lang#143174
…uwer Rollup of 20 pull requests Successful merges: - #159784 (Hint that memchr returns an in-bounds index) - #150885 (Revive L4Re target) - #159643 (Add support for splatted function pointers) - #160433 (delegation: add support for wrapping of the return value with `From::from`) - #160530 (refactor handling of target features in Session) - #160606 (bootstrap: Store and use an explicit CheckKind in `check::Rustc`) - #160628 (fix ICE in `suggest_add_reference_to_arg` for non-callable items) - #160634 (miri subtree update) - #157641 (Do not promote extern statics) - #158904 (Fix FutureDropPoll shim for by-move async closures) - #160103 (Add regression test for GAT bound mismatched type error) - #160335 (dlopen offload) - #160445 (codegen: classify localized MSVC linker progress as linker_info) - #160499 (rustc_resolve: move diagnostic attribute linting to attr parsing) - #160504 (cleanup borrowck, improve c-variadic handling) - #160577 (expand: Feature gate AST-based attribute macros on expressions and statements) - #160587 (Add regression test for associated type outlives bound at call site) - #160625 (platform-support/netbsd.md: No longer mention 8.x, due to EoL.) - #160636 (derive(Diagnostic): link to proper docs) - #160644 (Clean up some manual debug impls)
…promotion, r=oli-obk,traviscross Do not promote extern statics We already reject thread-local statics during promotion, so extend that check to extern statics as well. fixes rust-lang#143174
…uwer Rollup of 28 pull requests Successful merges: - #159784 (Hint that memchr returns an in-bounds index) - #160673 (Improve `canonical_param_env_cache`) - #150885 (Revive L4Re target) - #159643 (Add support for splatted function pointers) - #160433 (delegation: add support for wrapping of the return value with `From::from`) - #160530 (refactor handling of target features in Session) - #160606 (bootstrap: Store and use an explicit CheckKind in `check::Rustc`) - #160628 (fix ICE in `suggest_add_reference_to_arg` for non-callable items) - #160683 (Add regression test for unknown feaeture name reported with other errors) - #157641 (Do not promote extern statics) - #158904 (Fix FutureDropPoll shim for by-move async closures) - #159816 (added note/help about iterator invalidation when mutating a collection inside a for loop) - #160103 (Add regression test for GAT bound mismatched type error) - #160335 (dlopen offload) - #160445 (codegen: classify localized MSVC linker progress as linker_info) - #160499 (rustc_resolve: move diagnostic attribute linting to attr parsing) - #160504 (cleanup borrowck, improve c-variadic handling) - #160577 (expand: Feature gate AST-based attribute macros on expressions and statements) - #160587 (Add regression test for associated type outlives bound at call site) - #160625 (platform-support/netbsd.md: No longer mention 8.x, due to EoL.) - #160633 (delegation: fix determining wrong `FnKind` when delegation is inside const arg) - #160636 (derive(Diagnostic): link to proper docs) - #160644 (Clean up some manual debug impls) - #160649 (move naked function ui tests) - #160672 (Improve `MaybeLiveLocals`) - #160693 (Add branch config for perf. unrolling in bors) - #160696 (rustc_codegen_llvm: handle sm_101* features being an alias) - #160706 (renovate: clarify that vulnerability PRs are opened automatically)
…uwer Rollup of 28 pull requests Successful merges: - rust-lang/rust#159784 (Hint that memchr returns an in-bounds index) - rust-lang/rust#160673 (Improve `canonical_param_env_cache`) - rust-lang/rust#150885 (Revive L4Re target) - rust-lang/rust#159643 (Add support for splatted function pointers) - rust-lang/rust#160433 (delegation: add support for wrapping of the return value with `From::from`) - rust-lang/rust#160530 (refactor handling of target features in Session) - rust-lang/rust#160606 (bootstrap: Store and use an explicit CheckKind in `check::Rustc`) - rust-lang/rust#160628 (fix ICE in `suggest_add_reference_to_arg` for non-callable items) - rust-lang/rust#160683 (Add regression test for unknown feaeture name reported with other errors) - rust-lang/rust#157641 (Do not promote extern statics) - rust-lang/rust#158904 (Fix FutureDropPoll shim for by-move async closures) - rust-lang/rust#159816 (added note/help about iterator invalidation when mutating a collection inside a for loop) - rust-lang/rust#160103 (Add regression test for GAT bound mismatched type error) - rust-lang/rust#160335 (dlopen offload) - rust-lang/rust#160445 (codegen: classify localized MSVC linker progress as linker_info) - rust-lang/rust#160499 (rustc_resolve: move diagnostic attribute linting to attr parsing) - rust-lang/rust#160504 (cleanup borrowck, improve c-variadic handling) - rust-lang/rust#160577 (expand: Feature gate AST-based attribute macros on expressions and statements) - rust-lang/rust#160587 (Add regression test for associated type outlives bound at call site) - rust-lang/rust#160625 (platform-support/netbsd.md: No longer mention 8.x, due to EoL.) - rust-lang/rust#160633 (delegation: fix determining wrong `FnKind` when delegation is inside const arg) - rust-lang/rust#160636 (derive(Diagnostic): link to proper docs) - rust-lang/rust#160644 (Clean up some manual debug impls) - rust-lang/rust#160649 (move naked function ui tests) - rust-lang/rust#160672 (Improve `MaybeLiveLocals`) - rust-lang/rust#160693 (Add branch config for perf. unrolling in bors) - rust-lang/rust#160696 (rustc_codegen_llvm: handle sm_101* features being an alias) - rust-lang/rust#160706 (renovate: clarify that vulnerability PRs are opened automatically)
Pkgsrc changes: * Adapt to changes in vendored crate versions. * Version & checksum changes. Upstream changes: Version 1.99.0 (2026-10-01) ========================== Language -------- - [Add allow-by-default `raw_borrows_via_references` lint that checks for references that decay immediately into raw borrows](rust-lang/rust#138230) - [Extend `unconditional_panic` lint to function calls that panic when the chunks/windows size is zero] (rust-lang/rust#153563) - [Stabilize C-variadic function definitions] (rust-lang/rust#155697) - [Stabilize the ability to use `#[unsafe(naked)]` functions to define C-variadic functions (`#![feature(c_variadic_naked_functions)]`).] (rust-lang/rust#159746) - [Trait methods are now resolved on an adjusted never type (producing a FCW)] (rust-lang/rust#156047) - [Coerce from inference variables to trait objects if the inference variable is related via subtyping to a type that is known to be `Sized`] (rust-lang/rust#157820) - [Stabilize `#[my_macro] mod foo;`] (rust-lang/rust#157857). This allows outlined modules (`mod foo;`) anywhere in the body of a custom attribute or derive macro. - [Fix the `overflowing_literals` lint with repeated negation] (rust-lang/rust#158302). For instance, it will now no longer lint on `--128_i8`, which is already detected by the `arithmetic_overflow` lint. - [Add POSIX symbols to the `invalid_runtime_symbol_definitions` and `suspicious_runtime_symbol_definitions` lints] (rust-lang/rust#158522) - [Lint unused `#[path]` attributes on inline modules] (rust-lang/rust#158835) - [Enable `unreachable_cfg_select_predicates` lint as part of `unused` lint group] (rust-lang/rust#159179) - [Stabilize passing 128-bit integers via vector registers with `asm!` on x86] (rust-lang/rust#159525) - [Explicitly document that some allocations are allowed to grow in-place (but none are allowed to shrink)] (rust-lang/rust#159729) - We now [guarantee] (rust-lang/rust#159730) that the contents of an `UnsafeCell` can be accessed without going through `get` - [The `invalid_reference_casting` lint was adjusted accordingly] (rust-lang/rust#159960) - [Account for globally enabled target features in `global_asm!`] (rust-lang/rust#160594) - [Warn if an invalid `doc` attribute is used on a macro invocation] (rust-lang/rust#161003) Compiler -------- - [Convert `-Ctarget-cpu` into a target-modifier for AVR, AMDGCN and NVPTX] (rust-lang/rust#150732) - [Enable `static_position_independent_executables` on all gnu and musl targets] (rust-lang/rust#158510) - When providing a suggestion about a missing method, rustc now prefers an exactly matching name from a [doc alias attribute] (https://doc.rust-lang.org/rustdoc/advanced-features.html#add-aliases-for-an-item-in-documentation-search) over a similarity search from other method names. If your new users sometimes expect a method under a different name, adding a doc alias will now help them find it via rustc suggestions, in addition to helping them find it via rustdoc search: [When suggesting method names, prefer *exact* doc aliases over similar names](rust-lang/rust#160369) Platform Support ---------------- - [Promote `riscv64-unknown-linux-musl` to Tier 2 with host tools] (rust-lang/rust#158766) Refer to Rust's [platform support page][platform-support-doc] for more information on Rust's tiered platform support. [platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html Libraries --------- - Iteration on `RangeInclusive` (`a..=b` ranges) is now [optimized better in some circumstances] (rust-lang/rust#155114). As a side effect of this, the behavior of `RangeInclusive` values that has already been exhausted (as an iterator) has changed. For example, the return values of `start()` and `end()` on such ranges may return different values, and using such ranges as slice indexes may have different behavior. These behaviors were not guaranteed to be stable, so these changes are considered to not be breaking changes. - [Relax `transmute_copy` to accept `?Sized` types] (rust-lang/rust#155989) - [Update `transmute_copy` to use a non-unwinding panic] (rust-lang/rust#155989) - [Don't escape U+FF9E and U+FF9F in `escape_debug_ext`] (rust-lang/rust#158057) - [Re-export `core::fmt::NumBuffer` in `alloc` (and `std`)] (rust-lang/rust#161430) Stabilized APIs --------------- - [`IntoIterator` for `Box<[T; N]>`] (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-Box%3C%5BT;+N%5D,+A%3E) - [`IntoIterator` for `&Box<[T; N]>`] (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-%26Box%3C%5BT;+N%5D,+A%3E) - [`IntoIterator` for `&mut Box<[T; N]>`] (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-%26mut+Box%3C%5BT;+N%5D,+A%3E) - [`VecDeque::retain_back`] (https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.retain_back) - [`core::ffi::VaList`] (https://doc.rust-lang.org/stable/core/ffi/struct.VaList.html) - [`Box::into_non_null`] (https://doc.rust-lang.org/stable/std/boxed/struct.Box.html#method.into_non_null) - [`Box::from_non_null`] (https://doc.rust-lang.org/stable/std/boxed/struct.Box.html#method.from_non_null) - [`Vec::into_parts`] (https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.into_parts) - [`Vec::from_parts`] (https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.from_parts) - [`core::mem::size_of_val_raw`] (https://doc.rust-lang.org/stable/core/mem/fn.size_of_val_raw.html) - [`core::mem::align_of_val_raw`] (https://doc.rust-lang.org/stable/core/mem/fn.align_of_val_raw.html) - [`core::alloc::Layout::for_value_raw`] (https://doc.rust-lang.org/stable/core/alloc/struct.Layout.html#method.for_value_raw) - [`String::from_utf8_lossy_owned`] (https://doc.rust-lang.org/stable/std/string/struct.String.html#method.from_utf8_lossy_owned) - [`string::FromUtf8Error::into_utf8_lossy`] (https://doc.rust-lang.org/stable/std/string/struct.FromUtf8Error.html#method.into_utf8_lossy) - [`FusedIterator for StepBy<I>`] (https://doc.rust-lang.org/stable/std/iter/struct.StepBy.html#impl-FusedIterator-for-StepBy%3CI%3E) - [`std::fs::set_times`] (https://doc.rust-lang.org/stable/std/fs/fn.set_times.html) - [`std::fs::set_times_nofollow`] (https://doc.rust-lang.org/stable/std/fs/fn.set_times_nofollow.html) Cargo ----- - Add a new built-in profile `debug`. This is a preparation for transitioning the `dev` profile away from debugging to give a saner default for faster development iterations. Currently there is no difference between `dev` and `debug` profiles. [docs] (https://doc.rust-lang.org/nightly/cargo/reference/profiles.html#debug-1) [#17214] (rust-lang/cargo#17214) - Workspace members on edition 2024 or later can now override an inherited workspace dependency's `default-features` field. For example, `serde = { workspace = true, default-features = false }` now turns off default features even when the workspace definition enables them. On earlier editions, `default-features = false` is ignored with a warning. ([RFC 3945] (rust-lang/rfcs#3945)) [#17126](rust-lang/cargo#17126) - Incremental compilation is now disabled by default when running in CI. CI is detected via the CI environment variable. [#17220] (rust-lang/cargo#17220) See also the [full Cargo changelog] (https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html#cargo-199-2026-10-01) Rustdoc ----- - [Add new `unused_footnote_definition` rustdoc lint] (rust-lang/rust#137858) - Smarter filtering of trait impls yields performance improvements of 20% on average and up to 40% on some real-world crates. ([1] (rust-lang/rust#159623), [2](rust-lang/rust#159721), [3](rust-lang/rust#159779), [4](rust-lang/rust#159854), [5](rust-lang/rust#159091)) Compatibility Notes ------------------- - [Fully deprecate the legacy integral modules] (rust-lang/rust#146882). For example, `std::i32::MAX` should be accessed via `i32::MAX` instead. - [Upgrade `no_mangle_generic_items` into hard error] (rust-lang/rust#154585) - [The `Pin::new_unchecked` has had its safety invariants changed slightly] (rust-lang/rust#156935) - [Do not promote references to extern statics] (rust-lang/rust#157641) - [Ensure that the inferred types of `let` patterns typecheck] (rust-lang/rust#157841) - [hermit/fs: Return `unsupported()` instead of `from_raw_os_error(22)`] (rust-lang/rust#158247) - [Fixed a bug where `#[repr(simd)]` was accidentally allowed on macro invocations on stable Rust] (rust-lang/rust#158523) - [Abort const-eval when there are generics in the type of the value being produced] (rust-lang/rust#159504) - [Attributes not applying to anything are now an error in code blocks in doc comments] (rust-lang/rust#159849) - [`Box::leak`: tell people to avoid unleaking] (rust-lang/rust#160323) - [PowerPC inline ASM: Fix scalar floats being in the wrong vector lane on little endian] (rust-lang/rust#160441) - [Do not take `doc(cfg())` into account when filtering doctests] (rust-lang/rust#159014) - [Infer anonymous lifetimes in the types of associated consts as `'static`] (rust-lang/rust#156508) - Macros that expand to a semicolon now produce a warning lint (`semicolon_in_expressions_from_non_local_macros`) even when the macro comes from another crate. Previously, such warnings only appeared for macros from the same crate, to avoid showing warnings that can't be fixed locally; however, this masked problems, as integration tests from the crate providing the macro get compiled as a separate crate, so tests often wouldn't reveal this issue. If you encounter a lint like this, please make sure to report it to the crate providing the macro so they can fix it; don't just silence it in your own crate. - [`semicolon_in_expressions_from_macros`: Lint on non-local macros too] (rust-lang/rust#159222) - [Split non-local `semicolon_in_expressions_from_macros` into a separate lint] (rust-lang/rust#159700) Internal Changes ---------------- These changes do not affect any public interfaces of Rust, but they represent significant improvements to the performance or internals of rustc and related tools. - [Update to LLVM 23] (rust-lang/rust#158734)
View all comments
Reference PR:
externstatics reference#2302We already reject thread-local statics during promotion, so extend that check to extern statics as well.
fixes #143174