Skip to content

Box::leak: tell people to avoid unleaking - #160323

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
RalfJung:no-unleak
Aug 1, 2026
Merged

rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
RalfJung:no-unleak

Conversation

@RalfJung

@RalfJung RalfJung commented Aug 1, 2026

Copy link
Copy Markdown
Member

r? @nia-e
Cc @rust-lang/opsem

Note that this goes against the advice given by clippy in rust-lang/rust-clippy#17336. I think clippy should be adjusted to recommend Box::into_non_null instead. @ArhanChaudhary wold be great if you could make a clippy PR for that. :)

@rustbot rustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-libs Relevant to the library team, which will review and decide on the PR/issue. labels Aug 1, 2026
@ArhanChaudhary

Copy link
Copy Markdown
Contributor

Do you think the lint should match against both unsafe { NonNull::new_unchecked(Box::into_raw(..)) } and NonNull::from_mut(Box::leak(..))?

@RalfJung

RalfJung commented Aug 1, 2026

Copy link
Copy Markdown
Member Author

Yes I think that would be good.

@nia-e

nia-e commented Aug 1, 2026

Copy link
Copy Markdown
Member

Would it be useful to clarify under what conditions unleaking is acceptable? I can't think of any phrasing around allocators that doesn't sound overly long and confusing personally but maybe there is something. otherwise, lgtm

@RalfJung

RalfJung commented Aug 1, 2026 •

Copy link
Copy Markdown
Member Author

I think it would have to be something like

  • the pointer passed to Box::from_raw must be derived from this mutable reference without any intervening field/element projections, and
  • the allocator must be either Global or a NativeAllocator

Up to you if you want to document that, IMO we are better off telling people not to do this even if it is sometimes technically allowed.

@nia-e

nia-e commented Aug 1, 2026

Copy link
Copy Markdown
Member

I like the new wording, we can let people dig into docs if they want to do more. ty ^^

@bors r+ rollup

@rust-bors

rust-bors Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

📌 Commit bb24b38 has been approved by nia-e

It is now in the queue for this repository.

@rust-bors rust-bors Bot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@ArhanChaudhary

Copy link
Copy Markdown
Contributor

Hey, I have just opened rust-lang/rust-clippy#17485 :)

JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Aug 1, 2026
Box::leak: tell people to avoid unleaking

r? @nia-e
Cc @rust-lang/opsem

Note that this goes against the advice given by clippy in rust-lang/rust-clippy#17336. I think clippy should be adjusted to recommend `Box::into_non_null` instead. @ArhanChaudhary wold be great if you could make a clippy PR for that. :)
rust-bors Bot pushed a commit that referenced this pull request Aug 1, 2026
…uwer

Rollup of 10 pull requests

Successful merges:

 - #157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
 - #160012 (miri: ensure validity of references and pointers we dereference and cast)
 - #160294 (Update Enzyme to resolve one of the open bugs)
 - #159503 (allocations: document that they can be read-only)
 - #160250 (When issuing suggestions for missing trait items, label unstable items)
 - #160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
 - #160311 (Remove final use of sealed traits from stdlib)
 - #160313 (Make the noundef-on-Cast size guard explicit)
 - #160323 (Box::leak: tell people to avoid unleaking)
 - #160328 (Move `check_track_caller` into the attribute parser)
rust-bors Bot pushed a commit that referenced this pull request Aug 1, 2026
…uwer

Rollup of 12 pull requests

Successful merges:

 - #157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
 - #160012 (miri: ensure validity of references and pointers we dereference and cast)
 - #160294 (Update Enzyme to resolve one of the open bugs)
 - #159503 (allocations: document that they can be read-only)
 - #160179 (std: Update `wasip3` crate dependency)
 - #160250 (When issuing suggestions for missing trait items, label unstable items)
 - #160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
 - #160311 (Remove final use of sealed traits from stdlib)
 - #160313 (Make the noundef-on-Cast size guard explicit)
 - #160323 (Box::leak: tell people to avoid unleaking)
 - #160328 (Move `check_track_caller` into the attribute parser)
 - #160333 (Remove itertools dependency from `rustc_ast_pretty`)
@rust-bors
rust-bors Bot merged commit 878336c into rust-lang:main Aug 1, 2026
13 checks passed
@rustbot rustbot added this to the 1.99.0 milestone Aug 1, 2026
pull Bot pushed a commit to xtqqczze/rust-lang-miri that referenced this pull request Aug 2, 2026
…uwer

Rollup of 12 pull requests

Successful merges:

 - rust-lang/rust#157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
 - rust-lang/rust#160012 (miri: ensure validity of references and pointers we dereference and cast)
 - rust-lang/rust#160294 (Update Enzyme to resolve one of the open bugs)
 - rust-lang/rust#159503 (allocations: document that they can be read-only)
 - rust-lang/rust#160179 (std: Update `wasip3` crate dependency)
 - rust-lang/rust#160250 (When issuing suggestions for missing trait items, label unstable items)
 - rust-lang/rust#160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
 - rust-lang/rust#160311 (Remove final use of sealed traits from stdlib)
 - rust-lang/rust#160313 (Make the noundef-on-Cast size guard explicit)
 - rust-lang/rust#160323 (Box::leak: tell people to avoid unleaking)
 - rust-lang/rust#160328 (Move `check_track_caller` into the attribute parser)
 - rust-lang/rust#160333 (Remove itertools dependency from `rustc_ast_pretty`)
@RalfJung
RalfJung deleted the no-unleak branch August 2, 2026 16:46
@BoxyUwU BoxyUwU added the relnotes Marks issues that should be documented in the release notes of the next release. label Aug 6, 2026
flip1995 pushed a commit to flip1995/rust-clippy that referenced this pull request Aug 17, 2026
…uwer

Rollup of 12 pull requests

Successful merges:

 - rust-lang/rust#157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
 - rust-lang/rust#160012 (miri: ensure validity of references and pointers we dereference and cast)
 - rust-lang/rust#160294 (Update Enzyme to resolve one of the open bugs)
 - rust-lang/rust#159503 (allocations: document that they can be read-only)
 - rust-lang/rust#160179 (std: Update `wasip3` crate dependency)
 - rust-lang/rust#160250 (When issuing suggestions for missing trait items, label unstable items)
 - rust-lang/rust#160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
 - rust-lang/rust#160311 (Remove final use of sealed traits from stdlib)
 - rust-lang/rust#160313 (Make the noundef-on-Cast size guard explicit)
 - rust-lang/rust#160323 (Box::leak: tell people to avoid unleaking)
 - rust-lang/rust#160328 (Move `check_track_caller` into the attribute parser)
 - rust-lang/rust#160333 (Remove itertools dependency from `rustc_ast_pretty`)
@viliml

viliml commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

I think it would have to be something like

* the pointer passed to `Box::from_raw` must be derived from this mutable reference without any intervening field/element projections, and

* the allocator must be either `Global` or a `NativeAllocator`

Up to you if you want to document that, IMO we are better off telling people not to do this even if it is sometimes technically allowed.

Those conditions seem very easy to fulfill. What are the "many seemingly harmless ways of doing it (that) are undefined behavior"?

@RalfJung

RalfJung commented Sep 6, 2026

Copy link
Copy Markdown
Member Author

Doing a projection. (Or a reference of a different type, that should be added to the list.)

Also, if you are then freeing the Box while a function that took the &mut as argument still runs, you have UB.

nikola-kocic-jetbrains added a commit to JetBrains/kotlin-desktop-toolkit that referenced this pull request Sep 23, 2026
makai410 pushed a commit to makai410/rust that referenced this pull request Oct 1, 2026
…nathanBrouwer

Rollup of 12 pull requests

Successful merges:

 - rust-lang#157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
 - rust-lang#160012 (miri: ensure validity of references and pointers we dereference and cast)
 - rust-lang#160294 (Update Enzyme to resolve one of the open bugs)
 - rust-lang#159503 (allocations: document that they can be read-only)
 - rust-lang#160179 (std: Update `wasip3` crate dependency)
 - rust-lang#160250 (When issuing suggestions for missing trait items, label unstable items)
 - rust-lang#160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
 - rust-lang#160311 (Remove final use of sealed traits from stdlib)
 - rust-lang#160313 (Make the noundef-on-Cast size guard explicit)
 - rust-lang#160323 (Box::leak: tell people to avoid unleaking)
 - rust-lang#160328 (Move `check_track_caller` into the attribute parser)
 - rust-lang#160333 (Remove itertools dependency from `rustc_ast_pretty`)
makai410 pushed a commit to makai410/rustc_public that referenced this pull request Oct 1, 2026
…uwer

Rollup of 12 pull requests

Successful merges:

 - rust-lang/rust#157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
 - rust-lang/rust#160012 (miri: ensure validity of references and pointers we dereference and cast)
 - rust-lang/rust#160294 (Update Enzyme to resolve one of the open bugs)
 - rust-lang/rust#159503 (allocations: document that they can be read-only)
 - rust-lang/rust#160179 (std: Update `wasip3` crate dependency)
 - rust-lang/rust#160250 (When issuing suggestions for missing trait items, label unstable items)
 - rust-lang/rust#160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
 - rust-lang/rust#160311 (Remove final use of sealed traits from stdlib)
 - rust-lang/rust#160313 (Make the noundef-on-Cast size guard explicit)
 - rust-lang/rust#160323 (Box::leak: tell people to avoid unleaking)
 - rust-lang/rust#160328 (Move `check_track_caller` into the attribute parser)
 - rust-lang/rust#160333 (Remove itertools dependency from `rustc_ast_pretty`)
dressupgeekout pushed a commit to dressupgeekout/pkgsrc-wip that referenced this pull request Oct 2, 2026
Pkgsrc changes:
 * Adapt to changes in vendored crate versions.
 * Version & checksum changes.

Upstream changes:

Version 1.99.0 (2026-10-01)
==========================

Language
--------
- [Add allow-by-default `raw_borrows_via_references` lint that
  checks for references that decay immediately into raw
  borrows](rust-lang/rust#138230)
- [Extend `unconditional_panic` lint to function calls that panic
  when the chunks/windows size is zero]
  (rust-lang/rust#153563)
- [Stabilize C-variadic function definitions]
  (rust-lang/rust#155697)
- [Stabilize the ability to use `#[unsafe(naked)]` functions to
  define C-variadic functions (`#![feature(c_variadic_naked_functions)]`).]
  (rust-lang/rust#159746)
- [Trait methods are now resolved on an adjusted never type (producing a FCW)]
  (rust-lang/rust#156047)
- [Coerce from inference variables to trait objects if the inference
  variable is related via subtyping to a type that is known to be `Sized`]
  (rust-lang/rust#157820)
- [Stabilize `#[my_macro] mod foo;`]
  (rust-lang/rust#157857). This allows
  outlined modules (`mod foo;`) anywhere in the body of a custom
  attribute or derive macro.
- [Fix the `overflowing_literals` lint with repeated negation]
  (rust-lang/rust#158302). For instance,
  it will now no longer lint on `--128_i8`, which is already detected
  by the `arithmetic_overflow` lint.
- [Add POSIX symbols to the `invalid_runtime_symbol_definitions`
  and `suspicious_runtime_symbol_definitions` lints]
  (rust-lang/rust#158522)
- [Lint unused `#[path]` attributes on inline modules]
  (rust-lang/rust#158835)
- [Enable `unreachable_cfg_select_predicates` lint as part of
  `unused` lint group] (rust-lang/rust#159179)
- [Stabilize passing 128-bit integers via vector registers with `asm!` on x86]
  (rust-lang/rust#159525)
- [Explicitly document that some allocations are allowed to grow
  in-place (but none are allowed to shrink)]
  (rust-lang/rust#159729)
- We now [guarantee]
  (rust-lang/rust#159730) that the contents
  of an `UnsafeCell` can be accessed without going through `get`
  - [The `invalid_reference_casting` lint was adjusted accordingly]
  (rust-lang/rust#159960)
- [Account for globally enabled target features in `global_asm!`]
  (rust-lang/rust#160594)
- [Warn if an invalid `doc` attribute is used on a macro invocation]
  (rust-lang/rust#161003)

Compiler
--------
- [Convert `-Ctarget-cpu` into a target-modifier for AVR, AMDGCN and NVPTX]
  (rust-lang/rust#150732)
- [Enable `static_position_independent_executables` on all gnu and musl targets]
  (rust-lang/rust#158510)
- When providing a suggestion about a missing method, rustc now
  prefers an exactly matching name from a [doc alias attribute]
  (https://doc.rust-lang.org/rustdoc/advanced-features.html#add-aliases-for-an-item-in-documentation-search)
  over a similarity search from other method names. If your new
  users sometimes expect a method under a different name, adding
  a doc alias will now help them find it via rustc suggestions, in
  addition to helping them find it via rustdoc search: [When
  suggesting method names, prefer *exact* doc aliases over similar
  names](rust-lang/rust#160369)

Platform Support
----------------
- [Promote `riscv64-unknown-linux-musl` to Tier 2 with host tools]
  (rust-lang/rust#158766)

Refer to Rust's [platform support page][platform-support-doc]
for more information on Rust's tiered platform support.

[platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html

Libraries
---------
- Iteration on `RangeInclusive` (`a..=b` ranges) is now [optimized
  better in some circumstances]
  (rust-lang/rust#155114). As a side effect
  of this, the behavior of `RangeInclusive` values that has already
  been exhausted (as an iterator) has changed. For example, the
  return values of `start()` and `end()` on such ranges may return
  different values, and using such ranges as slice indexes may have
  different behavior. These behaviors were not guaranteed to be
  stable, so these changes are considered to not be breaking changes.
- [Relax `transmute_copy` to accept `?Sized` types]
  (rust-lang/rust#155989)
- [Update `transmute_copy` to use a non-unwinding panic]
  (rust-lang/rust#155989)
- [Don't escape U+FF9E and U+FF9F in `escape_debug_ext`]
  (rust-lang/rust#158057)
- [Re-export `core::fmt::NumBuffer` in `alloc` (and `std`)]
  (rust-lang/rust#161430)

Stabilized APIs
---------------

- [`IntoIterator` for `Box<[T; N]>`]
  (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-Box%3C%5BT;+N%5D,+A%3E)
- [`IntoIterator` for `&Box<[T; N]>`]
  (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-%26Box%3C%5BT;+N%5D,+A%3E)
- [`IntoIterator` for `&mut Box<[T; N]>`]
  (https://doc.rust-lang.org/stable/std/iter/trait.IntoIterator.html#impl-IntoIterator-for-%26mut+Box%3C%5BT;+N%5D,+A%3E)
- [`VecDeque::retain_back`]
  (https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.retain_back)
- [`core::ffi::VaList`]
  (https://doc.rust-lang.org/stable/core/ffi/struct.VaList.html)
- [`Box::into_non_null`]
  (https://doc.rust-lang.org/stable/std/boxed/struct.Box.html#method.into_non_null)
- [`Box::from_non_null`]
  (https://doc.rust-lang.org/stable/std/boxed/struct.Box.html#method.from_non_null)
- [`Vec::into_parts`]
  (https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.into_parts)
- [`Vec::from_parts`]
  (https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.from_parts)
- [`core::mem::size_of_val_raw`]
  (https://doc.rust-lang.org/stable/core/mem/fn.size_of_val_raw.html)
- [`core::mem::align_of_val_raw`]
  (https://doc.rust-lang.org/stable/core/mem/fn.align_of_val_raw.html)
- [`core::alloc::Layout::for_value_raw`]
  (https://doc.rust-lang.org/stable/core/alloc/struct.Layout.html#method.for_value_raw)
- [`String::from_utf8_lossy_owned`]
  (https://doc.rust-lang.org/stable/std/string/struct.String.html#method.from_utf8_lossy_owned)
- [`string::FromUtf8Error::into_utf8_lossy`]
  (https://doc.rust-lang.org/stable/std/string/struct.FromUtf8Error.html#method.into_utf8_lossy)
- [`FusedIterator for StepBy<I>`]
  (https://doc.rust-lang.org/stable/std/iter/struct.StepBy.html#impl-FusedIterator-for-StepBy%3CI%3E)
- [`std::fs::set_times`]
  (https://doc.rust-lang.org/stable/std/fs/fn.set_times.html)
- [`std::fs::set_times_nofollow`]
  (https://doc.rust-lang.org/stable/std/fs/fn.set_times_nofollow.html)

Cargo
-----
- Add a new built-in profile `debug`. This is a preparation for
  transitioning the `dev` profile away from debugging to give a saner
  default for faster development iterations. Currently there is no
  difference between `dev` and `debug` profiles. [docs]
  (https://doc.rust-lang.org/nightly/cargo/reference/profiles.html#debug-1)
  [#17214] (rust-lang/cargo#17214)
- Workspace members on edition 2024 or later can now override an
  inherited workspace dependency's `default-features` field. For
  example, `serde = { workspace = true, default-features = false }`
  now turns off default features even when the workspace definition
  enables them. On earlier editions, `default-features = false` is
  ignored with a warning. ([RFC 3945]
  (rust-lang/rfcs#3945))
  [#17126](rust-lang/cargo#17126)
- Incremental compilation is now disabled by default when running
  in CI. CI is detected via the CI environment variable. [#17220]
  (rust-lang/cargo#17220)
  See also the [full Cargo changelog]
  (https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html#cargo-199-2026-10-01)

Rustdoc
-----
- [Add new `unused_footnote_definition` rustdoc lint]
  (rust-lang/rust#137858)
- Smarter filtering of trait impls yields performance improvements
  of 20% on average and up to 40% on some real-world crates. ([1]
  (rust-lang/rust#159623),
  [2](rust-lang/rust#159721),
  [3](rust-lang/rust#159779),
  [4](rust-lang/rust#159854),
  [5](rust-lang/rust#159091))

Compatibility Notes
-------------------
- [Fully deprecate the legacy integral modules]
  (rust-lang/rust#146882). For example,
  `std::i32::MAX` should be accessed via `i32::MAX` instead.
- [Upgrade `no_mangle_generic_items` into hard error]
  (rust-lang/rust#154585)
- [The `Pin::new_unchecked` has had its safety invariants changed slightly]
  (rust-lang/rust#156935)
- [Do not promote references to extern statics]
  (rust-lang/rust#157641)
- [Ensure that the inferred types of `let` patterns typecheck]
  (rust-lang/rust#157841)
- [hermit/fs: Return `unsupported()` instead of `from_raw_os_error(22)`]
  (rust-lang/rust#158247)
- [Fixed a bug where `#[repr(simd)]` was accidentally allowed on
  macro invocations on stable Rust]
  (rust-lang/rust#158523)
- [Abort const-eval when there are generics in the type of the
  value being produced]
  (rust-lang/rust#159504)
- [Attributes not applying to anything are now an error in code
  blocks in doc comments]
  (rust-lang/rust#159849)
- [`Box::leak`: tell people to avoid unleaking]
  (rust-lang/rust#160323)
- [PowerPC inline ASM: Fix scalar floats being in the wrong vector
  lane on little endian] (rust-lang/rust#160441)
- [Do not take `doc(cfg())` into account when filtering doctests]
  (rust-lang/rust#159014)
- [Infer anonymous lifetimes in the types of associated consts as `'static`]
  (rust-lang/rust#156508)
- Macros that expand to a semicolon now produce a warning lint
  (`semicolon_in_expressions_from_non_local_macros`) even when the
  macro comes from another crate. Previously, such warnings only
  appeared for macros from the same crate, to avoid showing warnings
  that can't be fixed locally; however, this masked problems, as
  integration tests from the crate providing the macro get compiled
  as a separate crate, so tests often wouldn't reveal this issue. If
  you encounter a lint like this, please make sure to report it to
  the crate providing the macro so they can fix it; don't just silence
  it in your own crate.
  - [`semicolon_in_expressions_from_macros`: Lint on non-local
    macros too] (rust-lang/rust#159222)
  - [Split non-local `semicolon_in_expressions_from_macros` into
    a separate lint] (rust-lang/rust#159700)

Internal Changes
----------------

These changes do not affect any public interfaces of Rust, but they represent
significant improvements to the performance or internals of rustc and related
tools.

- [Update to LLVM 23]
  (rust-lang/rust#158734)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

relnotes Marks issues that should be documented in the release notes of the next release. S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. T-libs Relevant to the library team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants