Skip to content

fix(rust): []const u8 in a const is owned, and the argument is thirty lines above (+1) - #3259

Merged
gHashTag merged 3 commits into
masterfrom
const-u8-is-borrowed
Sep 5, 2026
Merged

gHashTag merged 3 commits into
masterfrom
const-u8-is-borrowed

Conversation

@gHashTag

@gHashTag gHashTag commented Sep 5, 2026

Copy link
Copy Markdown
Owner

The argument for treating this spelling as borrowed is already written thirty lines
above
, on the str arm:

"neither []const u8 nor const char* owns its bytes"

That arm was given &'static str earlier today. The very next arm sends the literal
[]const u8 spelling down the owned path, so a const declared with it came out as

pub const SPDX_HEADER: Vec<u8> = "// SPDX-License-Identifier: Apache-2.0\n";

— expected Vec<u8>, found &str, and a Vec cannot be built in a const at all.

Seventh instance this pass of one shape: a rule that exists in one place and did not
travel. This one did not even have to travel between emitters — it is thirty lines.

Keyed on the qualifier, and a regression is what located the boundary

I probed the broad version earlier and declined it: mapping both []const u8 and
[]u8 measured +1 / −1. The regression was specs/igla/race/opcodes.t27, whose
chain: []u8 is indexed as chain[(idx) as usize] and cannot be a str.

[]u8 is a mutable byte buffer and keeps Vec<u8>. Only the const-qualified
spelling becomes borrowed. Verified in the output: opcodes.t27 still emits
chain: Vec<u8>.

Measured against master

master (49c11fc3c) 329
after 330
gain +1
regressions 0

The Zig backend already writes const SPDX_HEADER: []const u8 = "…" and zig build-obj accepts it; gen-c writes a #define, which erases the type rather than
answering it.

Provenance

Found by a nine-agent fan-out against a pinned binary (/tmp/t27c-pin2, sha
b6f3bf14a764722f), after an earlier run of the same audit was discarded because I
rebuilt the compiler underneath it. The agent rebuilt the 329/252/69 baseline itself
before trusting it, regression-tested the one-arm alternative across all 24 accepted
files containing Vec<u8> (0 broken), and reported the help: call Into::into
suggestion trap explicitly.

Refs #3239

Closes #3258

… lines above (+1)

The `str` arm was given the borrowed form today and its comment argues the case --
"neither `[]const u8` nor `const char*` owns its bytes". The very next arm sends
the literal `[]const u8` spelling down the owned path, so a const declared with it
came out as `pub const SPDX_HEADER: Vec<u8> = "..."`, which is
`expected Vec<u8>, found &str`, and a Vec cannot be built in a const at all.

Keyed on the `const` QUALIFIER, not the element type. I probed the broad version
earlier and declined it at +1/-1: the regression was opcodes.t27, whose
`chain: []u8` is indexed as `chain[(idx) as usize]` and cannot be a str. A plain
`[]u8` keeps Vec<u8>, verified in the output. A declined probe is not a dead end --
its regression measured where the rule ends.

Measured against master: 329 -> 330, +1, zero regressions. The Zig backend already
writes `const SPDX_HEADER: []const u8` and zig build-obj accepts it.

Found by a nine-agent fan-out against a pinned binary, after an earlier run of the
same audit was discarded because I rebuilt the compiler underneath it. The agent
rebuilt the 329/252/69 baseline itself before trusting it, and regression-tested
the one-arm alternative across all 24 accepted files containing Vec<u8>: 0 broken.

Closes #3258

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@gHashTag
gHashTag enabled auto-merge (squash) September 5, 2026 09:03
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-09-05 09:03:41 UTC

Summary

Status Count
Total Open PRs 12
PRs with Failing Checks 12
PRs with All Checks Green 0
READY 0
FAILING 12
PENDING 0

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=9b0b854d68ba != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

# Conflicts:
#	.trinity/seals/SDK.json
#	.trinity/seals/cli_gen_commands.json
#	.trinity/seals/gen_commands.json
#	.trinity/seals/vsa_SDK.json
#	bootstrap/stage0/FROZEN_HASH
…s DIRTY)

Control before pushing: the change is verified present in the rebuilt binary.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-09-05 09:14:43 UTC

Summary

Status Count
Total Open PRs 13
PRs with Failing Checks 12
PRs with All Checks Green 1
READY 0
FAILING 12
PENDING 0

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=ab7505edd6ab != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag
gHashTag merged commit 78b6a42 into master Sep 5, 2026
27 of 29 checks passed
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[]const u8 in a const is owned, and the argument for borrowing it is thirty lines above

1 participant