Skip to content

Commit ece1397

Browse files
committed
interpret: fix in-place return place semantics when the return place expression is a local variable
1 parent 2c1ac85 commit ece1397

13 files changed

+53
-40
lines changed

compiler/rustc_const_eval/src/interpret/call.rs

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,9 @@ use crate::{enter_trace_span, fluent_generated as fluent};
2727
pub enum FnArg<'tcx, Prov: Provenance = CtfeProvenance> {
2828
/// Pass a copy of the given operand.
2929
Copy(OpTy<'tcx, Prov>),
30-
/// Allow for the argument to be passed in-place: destroy the value originally stored at that place and
31-
/// make the place inaccessible for the duration of the function call.
30+
/// Allow for the argument to be passed in-place: destroy the value originally stored at that
31+
/// place and make the place inaccessible for the duration of the function call. This *must* be
32+
/// an in-memory place so that we can do the proper alias checks.
3233
InPlace(MPlaceTy<'tcx, Prov>),
3334
}
3435

@@ -379,6 +380,11 @@ impl<'tcx, M: Machine<'tcx>> InterpCx<'tcx, M> {
379380
}
380381
}
381382

383+
// *Before* pushing the new frame, determine whether the return destination is in memory.
384+
// Need to use `place_to_op` to be *sure* we get the mplace if there is one.
385+
let destination_mplace = self.place_to_op(destination)?.as_mplace_or_imm().left();
386+
387+
// Push the "raw" frame -- this leaves locals uninitialized.
382388
self.push_stack_frame_raw(instance, body, destination, cont)?;
383389

384390
// If an error is raised here, pop the frame again to get an accurate backtrace.
@@ -496,7 +502,7 @@ impl<'tcx, M: Machine<'tcx>> InterpCx<'tcx, M> {
496502

497503
// Protect return place for in-place return value passing.
498504
// We only need to protect anything if this is actually an in-memory place.
499-
if let Left(mplace) = destination.as_mplace_or_local() {
505+
if let Some(mplace) = destination_mplace {
500506
M::protect_in_place_function_argument(self, &mplace)?;
501507
}
502508

compiler/rustc_const_eval/src/interpret/place.rs

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -234,6 +234,12 @@ impl<'tcx, Prov: Provenance> PlaceTy<'tcx, Prov> {
234234
}
235235

236236
/// A place is either an mplace or some local.
237+
///
238+
/// Note that the return value can be different even for logically identical places!
239+
/// Specifically, if a local is stored in-memory, this may return `Local` or `MPlaceTy`
240+
/// depending on how the place was constructed. In other words, seeing `Local` here does *not*
241+
/// imply that this place does not point to memory. Every caller must therefore always handle
242+
/// both cases.
237243
#[inline(always)]
238244
pub fn as_mplace_or_local(
239245
&self,

compiler/rustc_const_eval/src/interpret/step.rs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -415,6 +415,7 @@ impl<'tcx, M: Machine<'tcx>> InterpCx<'tcx, M> {
415415
// caller directly access this local!
416416
// This is also crucial for tail calls, where we want the `FnArg` to
417417
// stay valid when the old stack frame gets popped.
418+
// FIXME: How can this be right for aliasing arguments?
418419
FnArg::Copy(op)
419420
}
420421
}

src/tools/miri/tests/fail/function_calls/return_pointer_aliasing_read.none.stderr

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ LL | unsafe { ptr.read() };
1111
note: inside `main`
1212
--> tests/fail/function_calls/return_pointer_aliasing_read.rs:LL:CC
1313
|
14-
LL | Call(*ptr = myfun(ptr), ReturnTo(after_call), UnwindContinue())
15-
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
14+
LL | Call(_x = myfun(ptr), ReturnTo(after_call), UnwindContinue())
15+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1616

1717
Uninitialized memory occurred at ALLOC[0x0..0x4], in this allocation:
1818
ALLOC (stack variable, size: 4, align: 4) {

src/tools/miri/tests/fail/function_calls/return_pointer_aliasing_read.rs

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,11 +10,11 @@ use std::intrinsics::mir::*;
1010
pub fn main() {
1111
mir! {
1212
{
13-
let x = 0;
14-
let ptr = &raw mut x;
13+
let _x = 0;
14+
let ptr = &raw mut _x;
1515
// We arrange for `myfun` to have a pointer that aliases
1616
// its return place. Even just reading from that pointer is UB.
17-
Call(*ptr = myfun(ptr), ReturnTo(after_call), UnwindContinue())
17+
Call(_x = myfun(ptr), ReturnTo(after_call), UnwindContinue())
1818
}
1919

2020
after_call = {
@@ -25,7 +25,7 @@ pub fn main() {
2525

2626
fn myfun(ptr: *mut i32) -> i32 {
2727
unsafe { ptr.read() };
28-
//~[stack]^ ERROR: not granting access
28+
//~[stack]^ ERROR: does not exist in the borrow stack
2929
//~[tree]| ERROR: /read access .* forbidden/
3030
//~[none]| ERROR: uninitialized
3131
// Without an aliasing model, reads are "fine" but at least they return uninit data.

src/tools/miri/tests/fail/function_calls/return_pointer_aliasing_read.stack.stderr

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
1-
error: Undefined Behavior: not granting access to tag <TAG> because that would remove [Unique for <TAG>] which is strongly protected
1+
error: Undefined Behavior: attempting a read access using <TAG> at ALLOC[0x0], but that tag does not exist in the borrow stack for this location
22
--> tests/fail/function_calls/return_pointer_aliasing_read.rs:LL:CC
33
|
44
LL | unsafe { ptr.read() };
5-
| ^^^^^^^^^^ Undefined Behavior occurred here
5+
| ^^^^^^^^^^ this error occurs as part of an access at ALLOC[0x0..0x4]
66
|
77
= help: this indicates a potential bug in the program: it performed an invalid operation, but the Stacked Borrows rules it violated are still experimental
88
= help: see https://github.com/rust-lang/unsafe-code-guidelines/blob/master/wip/stacked-borrows.md for further information
@@ -11,12 +11,12 @@ help: <TAG> was created by a SharedReadWrite retag at offsets [0x0..0x4]
1111
|
1212
LL | / mir! {
1313
LL | | {
14-
LL | | let x = 0;
15-
LL | | let ptr = &raw mut x;
14+
LL | | let _x = 0;
15+
LL | | let ptr = &raw mut _x;
1616
... |
1717
LL | | }
1818
| |_____^
19-
help: <TAG> is this argument
19+
help: <TAG> was later invalidated at offsets [0x0..0x4] by a Unique in-place function argument/return passing protection
2020
--> tests/fail/function_calls/return_pointer_aliasing_read.rs:LL:CC
2121
|
2222
LL | unsafe { ptr.read() };
@@ -26,8 +26,8 @@ LL | unsafe { ptr.read() };
2626
note: inside `main`
2727
--> tests/fail/function_calls/return_pointer_aliasing_read.rs:LL:CC
2828
|
29-
LL | Call(*ptr = myfun(ptr), ReturnTo(after_call), UnwindContinue())
30-
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
29+
LL | Call(_x = myfun(ptr), ReturnTo(after_call), UnwindContinue())
30+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3131
= note: this error originates in the macro `::core::intrinsics::mir::__internal_remove_let` which comes from the expansion of the macro `mir` (in Nightly builds, run with -Z macro-backtrace for more info)
3232

3333
note: some details are omitted, run with `MIRIFLAGS=-Zmiri-backtrace=full` for a verbose backtrace

src/tools/miri/tests/fail/function_calls/return_pointer_aliasing_read.tree.stderr

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,8 @@ help: the accessed tag <TAG> was created here
1313
|
1414
LL | / mir! {
1515
LL | | {
16-
LL | | let x = 0;
17-
LL | | let ptr = &raw mut x;
16+
LL | | let _x = 0;
17+
LL | | let ptr = &raw mut _x;
1818
... |
1919
LL | | }
2020
| |_____^
@@ -34,8 +34,8 @@ LL | unsafe { ptr.read() };
3434
note: inside `main`
3535
--> tests/fail/function_calls/return_pointer_aliasing_read.rs:LL:CC
3636
|
37-
LL | Call(*ptr = myfun(ptr), ReturnTo(after_call), UnwindContinue())
38-
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
37+
LL | Call(_x = myfun(ptr), ReturnTo(after_call), UnwindContinue())
38+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3939
= note: this error originates in the macro `::core::intrinsics::mir::__internal_remove_let` which comes from the expansion of the macro `mir` (in Nightly builds, run with -Z macro-backtrace for more info)
4040

4141
note: some details are omitted, run with `MIRIFLAGS=-Zmiri-backtrace=full` for a verbose backtrace

src/tools/miri/tests/fail/function_calls/return_pointer_aliasing_write.rs

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ pub fn main() {
1414
let ptr = &raw mut _x;
1515
// We arrange for `myfun` to have a pointer that aliases
1616
// its return place. Writing to that pointer is UB.
17-
Call(*ptr = myfun(ptr), ReturnTo(after_call), UnwindContinue())
17+
Call(_x = myfun(ptr), ReturnTo(after_call), UnwindContinue())
1818
}
1919

2020
after_call = {
@@ -26,7 +26,7 @@ pub fn main() {
2626
fn myfun(ptr: *mut i32) -> i32 {
2727
// This overwrites the return place, which shouldn't be possible through another pointer.
2828
unsafe { ptr.write(0) };
29-
//~[stack]^ ERROR: strongly protected
29+
//~[stack]^ ERROR: does not exist in the borrow stack
3030
//~[tree]| ERROR: /write access .* forbidden/
3131
13
3232
}

src/tools/miri/tests/fail/function_calls/return_pointer_aliasing_write.stack.stderr

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
1-
error: Undefined Behavior: not granting access to tag <TAG> because that would remove [Unique for <TAG>] which is strongly protected
1+
error: Undefined Behavior: attempting a write access using <TAG> at ALLOC[0x0], but that tag does not exist in the borrow stack for this location
22
--> tests/fail/function_calls/return_pointer_aliasing_write.rs:LL:CC
33
|
44
LL | unsafe { ptr.write(0) };
5-
| ^^^^^^^^^^^^ Undefined Behavior occurred here
5+
| ^^^^^^^^^^^^ this error occurs as part of an access at ALLOC[0x0..0x4]
66
|
77
= help: this indicates a potential bug in the program: it performed an invalid operation, but the Stacked Borrows rules it violated are still experimental
88
= help: see https://github.com/rust-lang/unsafe-code-guidelines/blob/master/wip/stacked-borrows.md for further information
@@ -16,7 +16,7 @@ LL | | let ptr = &raw mut _x;
1616
... |
1717
LL | | }
1818
| |_____^
19-
help: <TAG> is this argument
19+
help: <TAG> was later invalidated at offsets [0x0..0x4] by a Unique in-place function argument/return passing protection
2020
--> tests/fail/function_calls/return_pointer_aliasing_write.rs:LL:CC
2121
|
2222
LL | unsafe { ptr.write(0) };
@@ -26,8 +26,8 @@ LL | unsafe { ptr.write(0) };
2626
note: inside `main`
2727
--> tests/fail/function_calls/return_pointer_aliasing_write.rs:LL:CC
2828
|
29-
LL | Call(*ptr = myfun(ptr), ReturnTo(after_call), UnwindContinue())
30-
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
29+
LL | Call(_x = myfun(ptr), ReturnTo(after_call), UnwindContinue())
30+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3131
= note: this error originates in the macro `::core::intrinsics::mir::__internal_remove_let` which comes from the expansion of the macro `mir` (in Nightly builds, run with -Z macro-backtrace for more info)
3232

3333
note: some details are omitted, run with `MIRIFLAGS=-Zmiri-backtrace=full` for a verbose backtrace

src/tools/miri/tests/fail/function_calls/return_pointer_aliasing_write.tree.stderr

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,8 +34,8 @@ LL | unsafe { ptr.write(0) };
3434
note: inside `main`
3535
--> tests/fail/function_calls/return_pointer_aliasing_write.rs:LL:CC
3636
|
37-
LL | Call(*ptr = myfun(ptr), ReturnTo(after_call), UnwindContinue())
38-
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
37+
LL | Call(_x = myfun(ptr), ReturnTo(after_call), UnwindContinue())
38+
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
3939
= note: this error originates in the macro `::core::intrinsics::mir::__internal_remove_let` which comes from the expansion of the macro `mir` (in Nightly builds, run with -Z macro-backtrace for more info)
4040

4141
note: some details are omitted, run with `MIRIFLAGS=-Zmiri-backtrace=full` for a verbose backtrace

0 commit comments

Comments
 (0)