Skip to content

Fix incorrect use of MaybeUninit::assume_init_mut in flt2dec #76092

Description

@Dylan-DPC-zz

Creating this issue to track this FIXME note in float formatting:

This is calling get_mut on an uninitialized
MaybeUninit (here and elsewhere in this file). Revisit this once
we decided whether that is valid or not.
We can do this only because we are libstd and coupled to the compiler.
(FWIW, using freeze would not be enough; flt2dec::Part is an enum!)

The issue being mentioned when the fixme was closed without addressing this concern, and the new tracking issue doesn't raise it, so created this so that we can discuss it here and link it to the tracking issue

cc @RalfJung

Activity

  1. changed the title [-]Validity of get_mut on MaybeUninit[/-] [+]Validity of get_mut/assume_init_mut on MaybeUninit[/+] on Aug 30, 2020
  2. RalfJung commented on Aug 30, 2020

    @RalfJung
    Member

    Besides the float code, there's also the Read code doing something similar for allowing reads into uninitialized buffers. However, rust-lang/rfcs#2930 should resolve that I think.

  3. danielhenrymantilla commented on Aug 30, 2020

    @danielhenrymantilla
    Contributor

    Could we rename it to validity of .assume_init_mut() on uninitialized float(s)? or &mut on uninitialized floats?


    Regarding the issue at hand, obviously only libstd and other internal crates can rely on the internals of the rustc it is released with, so technically, we could go ahead with #76047 and "ignore" the FIXME, as long as we have this issue to remind us of fixing that.

    Doing so is not that bad as when I attempted to tackle #66174, since by now we have initiatives such as the one I suggested there having been implemented in a library crate, using a library version of out references, and we also have the aforementioned RFC getting some progress. So this time, letting the FIXME without fixing it yet is not just a "useless procrastination of the problem", it is a meaningful "wait for the required language feature", I'd say 🙂

  4. RalfJung commented on Aug 30, 2020

    @RalfJung
    Member

    The issue is not really specific to floats, it is tight to whether references are allowed to refer to uninitialized data.

    So this is basically the rustc side of (a part of) rust-lang/unsafe-code-guidelines#77.

  5. changed the title [-]Validity of get_mut/assume_init_mut on MaybeUninit[/-] [+]Validity of MaybeUninit::get_mut/assume_init_mut on invalid data[/+] on Aug 30, 2020
  6. RalfJung commented on Aug 30, 2020

    @RalfJung
    Member

    So this time, letting the FIXME without fixing it yet is not just a "useless procrastination of the problem", it is a meaningful "wait for the required language feature", I'd say slightly_smiling_face

    Agreed for the Read side. For the float usage, really that code should be converted to raw pointers.

  7. changed the title [-]Validity of MaybeUninit::get_mut/assume_init_mut on invalid data[/-] [+]Fix incorrect use of MaybeUninit::assume_init_mut in standard library[/+] on Sep 2, 2020
  8. changed the title [-]Fix incorrect use of MaybeUninit::assume_init_mut in standard library[/-] [+]Fix incorrect use of MaybeUninit::assume_init_mut in flt2dec[/+] on Sep 2, 2020
  9. RalfJung commented on Sep 2, 2020

    @RalfJung
    Member

    Actually, let's use #42788 for the Read part (there's another FIXME in the code referencing that already).

    This is just for flt2dec, and will be fixed by #76241.

  10. added
    C-bugCategory: This is a bug.
    T-libsRelevant to the library team, which will review and decide on the PR/issue.
    on Sep 2, 2020
  11. added a commit that references this issue on Sep 2, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    C-bugCategory: This is a bug.T-libsRelevant to the library team, which will review and decide on the PR/issue.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions