Skip to content

Don't build format string suggestions from concat! offsets - #163368

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
h-kurashina:fix-156101
Oct 1, 2026
Merged

rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
h-kurashina:fix-156101

Conversation

@h-kurashina

@h-kurashina h-kurashina commented Sep 26, 2026 •

Copy link
Copy Markdown

Fixes #156101

When a format string does not come directly from a string literal in
the source, e.g. when it is produced by concat!, the parser's inner
offsets are relative to the expanded string rather than to the source.
The primary error span and the RemoveRawIdent suggestion already
check is_source_literal before calling fmt_span.from_inner, but the
UsePositional, ReorderFormatParameter and AddMissingColon
suggestions did not.

As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.

For example, before this change UsePositional took at! from the
concat! invocation as the captured argument, replaced it with 0,
and suggested passing at! as an argument:

help: consider using a positional formatting argument instead
  |
2 -     format_args!(concat!("{}{a.b}", ""));
2 +     format_args!(conc0("{}{a.b}", ""), at!);

The crash test is moved to tests/ui/fmt, with cases covering each of
these suggestions.

When a format string does not come directly from a string literal in
the source, e.g. when it is produced by `concat!`, the parser's inner
offsets are relative to the expanded string rather than to the source.
The primary error span and the `RemoveRawIdent` suggestion already
check `is_source_literal` before calling `fmt_span.from_inner`, but the
`UsePositional`, `ReorderFormatParameter` and `AddMissingColon`
suggestions did not.

As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.

The crash test is moved to `tests/ui/fmt`, with cases covering each of
these suggestions.
@rustbot

rustbot commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot rustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Sep 26, 2026
@rustbot

rustbot commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator

Thanks for the pull request, and welcome! The Rust Project has assigned @Enselic (or someone else) to review your changes, you should hear from them (or someone else) within the next two weeks.

Please see the contribution instructions and our LLM policy for more information.

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 77 candidates
  • Random selection from 20 candidates

@mejrs mejrs left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-bors Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

📌 Commit 8c3ae60 has been approved by mejrs

It is now in the queue for this repository.

@rust-bors rust-bors Bot added the S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. label Sep 30, 2026
@rust-bors rust-bors Bot removed the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Sep 30, 2026
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Sep 30, 2026
Don't build format string suggestions from `concat!` offsets

Fixes rust-lang#156101

When a format string does not come directly from a string literal in
the source, e.g. when it is produced by `concat!`, the parser's inner
offsets are relative to the expanded string rather than to the source.
The primary error span and the `RemoveRawIdent` suggestion already
check `is_source_literal` before calling `fmt_span.from_inner`, but the
`UsePositional`, `ReorderFormatParameter` and `AddMissingColon`
suggestions did not.

As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.

For example, before this change `UsePositional` took `at!` from the
`concat!` invocation as the captured argument, replaced it with `0`,
and suggested passing `at!` as an argument:

```
help: consider using a positional formatting argument instead
  |
2 -     format_args!(concat!("{}{a.b}", ""));
2 +     format_args!(conc0("{}{a.b}", ""), at!);
```

The crash test is moved to `tests/ui/fmt`, with cases covering each of
these suggestions.
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Sep 30, 2026
Don't build format string suggestions from `concat!` offsets

Fixes rust-lang#156101

When a format string does not come directly from a string literal in
the source, e.g. when it is produced by `concat!`, the parser's inner
offsets are relative to the expanded string rather than to the source.
The primary error span and the `RemoveRawIdent` suggestion already
check `is_source_literal` before calling `fmt_span.from_inner`, but the
`UsePositional`, `ReorderFormatParameter` and `AddMissingColon`
suggestions did not.

As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.

For example, before this change `UsePositional` took `at!` from the
`concat!` invocation as the captured argument, replaced it with `0`,
and suggested passing `at!` as an argument:

```
help: consider using a positional formatting argument instead
  |
2 -     format_args!(concat!("{}{a.b}", ""));
2 +     format_args!(conc0("{}{a.b}", ""), at!);
```

The crash test is moved to `tests/ui/fmt`, with cases covering each of
these suggestions.
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Sep 30, 2026
Don't build format string suggestions from `concat!` offsets

Fixes rust-lang#156101

When a format string does not come directly from a string literal in
the source, e.g. when it is produced by `concat!`, the parser's inner
offsets are relative to the expanded string rather than to the source.
The primary error span and the `RemoveRawIdent` suggestion already
check `is_source_literal` before calling `fmt_span.from_inner`, but the
`UsePositional`, `ReorderFormatParameter` and `AddMissingColon`
suggestions did not.

As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.

For example, before this change `UsePositional` took `at!` from the
`concat!` invocation as the captured argument, replaced it with `0`,
and suggested passing `at!` as an argument:

```
help: consider using a positional formatting argument instead
  |
2 -     format_args!(concat!("{}{a.b}", ""));
2 +     format_args!(conc0("{}{a.b}", ""), at!);
```

The crash test is moved to `tests/ui/fmt`, with cases covering each of
these suggestions.
rust-bors Bot pushed a commit that referenced this pull request Sep 30, 2026
…uwer

Rollup of 18 pull requests

Successful merges:

 - #163532 (rustc_codegen_cranelift subtree update)
 - #163534 (miri subtree update)
 - #163279 (const and NonZero impl for clamp_magnitude())
 - #162900 (Some refactorings around metadata encoding)
 - #163455 (Don't use the metadata based crate_hash for rustdoc runs)
 - #163483 (Bump bootstrap compiler to 1.100.0 beta)
 - #159798 (Attribute documentation for cfg_attr)
 - #163368 (Don't build format string suggestions from `concat!` offsets)
 - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance)
 - #163405 (Remove some #[linkage] options)
 - #163470 (Miscellaneous attr error stuff)
 - #163489 (expose Rc::is_unique)
 - #163492 (x86 and x86_64: cleanup some callconv code)
 - #163496 (cycle handling: mirror old solver)
 - #163509 (Use more default field values in `Resolver`)
 - #163519 (Forbid  `Reborrow` impls for types with destructors)
 - #163520 (Cast cleanups)
 - #163524 (Document `Result` case for the `arena_cache` query modifier)

Failed merges:

 - #163547 ([beta] rustfmt backport)
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Sep 30, 2026
Don't build format string suggestions from `concat!` offsets

Fixes rust-lang#156101

When a format string does not come directly from a string literal in
the source, e.g. when it is produced by `concat!`, the parser's inner
offsets are relative to the expanded string rather than to the source.
The primary error span and the `RemoveRawIdent` suggestion already
check `is_source_literal` before calling `fmt_span.from_inner`, but the
`UsePositional`, `ReorderFormatParameter` and `AddMissingColon`
suggestions did not.

As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.

For example, before this change `UsePositional` took `at!` from the
`concat!` invocation as the captured argument, replaced it with `0`,
and suggested passing `at!` as an argument:

```
help: consider using a positional formatting argument instead
  |
2 -     format_args!(concat!("{}{a.b}", ""));
2 +     format_args!(conc0("{}{a.b}", ""), at!);
```

The crash test is moved to `tests/ui/fmt`, with cases covering each of
these suggestions.
rust-bors Bot pushed a commit that referenced this pull request Sep 30, 2026
…uwer

Rollup of 18 pull requests

Successful merges:

 - #163532 (rustc_codegen_cranelift subtree update)
 - #163534 (miri subtree update)
 - #163279 (const and NonZero impl for clamp_magnitude())
 - #162900 (Some refactorings around metadata encoding)
 - #163455 (Don't use the metadata based crate_hash for rustdoc runs)
 - #159798 (Attribute documentation for cfg_attr)
 - #162921 (make mips64 `Complex` GCC-compatible)
 - #163368 (Don't build format string suggestions from `concat!` offsets)
 - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance)
 - #163405 (Remove some #[linkage] options)
 - #163470 (Miscellaneous attr error stuff)
 - #163489 (expose Rc::is_unique)
 - #163492 (x86 and x86_64: cleanup some callconv code)
 - #163496 (cycle handling: mirror old solver)
 - #163509 (Use more default field values in `Resolver`)
 - #163519 (Forbid  `Reborrow` impls for types with destructors)
 - #163520 (Cast cleanups)
 - #163524 (Document `Result` case for the `arena_cache` query modifier)
rust-bors Bot pushed a commit that referenced this pull request Sep 30, 2026
…uwer

Rollup of 18 pull requests

Successful merges:

 - #163532 (rustc_codegen_cranelift subtree update)
 - #163534 (miri subtree update)
 - #163279 (const and NonZero impl for clamp_magnitude())
 - #162900 (Some refactorings around metadata encoding)
 - #163455 (Don't use the metadata based crate_hash for rustdoc runs)
 - #159798 (Attribute documentation for cfg_attr)
 - #162921 (make mips64 `Complex` GCC-compatible)
 - #163368 (Don't build format string suggestions from `concat!` offsets)
 - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance)
 - #163405 (Remove some #[linkage] options)
 - #163470 (Miscellaneous attr error stuff)
 - #163489 (expose Rc::is_unique)
 - #163492 (x86 and x86_64: cleanup some callconv code)
 - #163496 (cycle handling: mirror old solver)
 - #163509 (Use more default field values in `Resolver`)
 - #163519 (Forbid  `Reborrow` impls for types with destructors)
 - #163520 (Cast cleanups)
 - #163524 (Document `Result` case for the `arena_cache` query modifier)
rust-bors Bot pushed a commit that referenced this pull request Oct 1, 2026
Rollup of 20 pull requests

Successful merges:

 - #163279 (const and NonZero impl for clamp_magnitude())
 - #163081 (Provide more context on "not general enough" error)
 - #163455 (Don't use the metadata based crate_hash for rustdoc runs)
 - #159798 (Attribute documentation for cfg_attr)
 - #162921 (make mips64 `Complex` GCC-compatible)
 - #163368 (Don't build format string suggestions from `concat!` offsets)
 - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance)
 - #163470 (Miscellaneous attr error stuff)
 - #163489 (expose Rc::is_unique)
 - #163492 (x86 and x86_64: cleanup some callconv code)
 - #163496 (cycle handling: mirror old solver)
 - #163509 (Use more default field values in `Resolver`)
 - #163519 (Forbid  `Reborrow` impls for types with destructors)
 - #163520 (Cast cleanups)
 - #163524 (Document `Result` case for the `arena_cache` query modifier)
 - #163546 (PassWrapper: adapt for new PassPlugin load method)
 - #163551 (Add libs-nominated triagebot config)
 - #163559 (Suggest `#[unsafe(no_mangle)]` for entry points in `no_std` binaries)
 - #163564 (rustc-dev-guide subtree update)
 - #163568 (remove dead cfg_select! arm)
@rust-bors
rust-bors Bot merged commit 3ea0d1e into rust-lang:main Oct 1, 2026
13 checks passed
@rustbot rustbot added this to the 1.101.0 milestone Oct 1, 2026
rust-bors Bot pushed a commit that referenced this pull request Oct 1, 2026
Rollup merge of #163368 - h-kurashina:fix-156101, r=mejrs

Don't build format string suggestions from `concat!` offsets

Fixes #156101

When a format string does not come directly from a string literal in
the source, e.g. when it is produced by `concat!`, the parser's inner
offsets are relative to the expanded string rather than to the source.
The primary error span and the `RemoveRawIdent` suggestion already
check `is_source_literal` before calling `fmt_span.from_inner`, but the
`UsePositional`, `ReorderFormatParameter` and `AddMissingColon`
suggestions did not.

As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.

For example, before this change `UsePositional` took `at!` from the
`concat!` invocation as the captured argument, replaced it with `0`,
and suggested passing `at!` as an argument:

```
help: consider using a positional formatting argument instead
  |
2 -     format_args!(concat!("{}{a.b}", ""));
2 +     format_args!(conc0("{}{a.b}", ""), at!);
```

The crash test is moved to `tests/ui/fmt`, with cases covering each of
these suggestions.
RalfJung pushed a commit to RalfJung/miri that referenced this pull request Oct 1, 2026
Rollup of 20 pull requests

Successful merges:

 - rust-lang/rust#163279 (const and NonZero impl for clamp_magnitude())
 - rust-lang/rust#163081 (Provide more context on "not general enough" error)
 - rust-lang/rust#163455 (Don't use the metadata based crate_hash for rustdoc runs)
 - rust-lang/rust#159798 (Attribute documentation for cfg_attr)
 - rust-lang/rust#162921 (make mips64 `Complex` GCC-compatible)
 - rust-lang/rust#163368 (Don't build format string suggestions from `concat!` offsets)
 - rust-lang/rust#163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance)
 - rust-lang/rust#163470 (Miscellaneous attr error stuff)
 - rust-lang/rust#163489 (expose Rc::is_unique)
 - rust-lang/rust#163492 (x86 and x86_64: cleanup some callconv code)
 - rust-lang/rust#163496 (cycle handling: mirror old solver)
 - rust-lang/rust#163509 (Use more default field values in `Resolver`)
 - rust-lang/rust#163519 (Forbid  `Reborrow` impls for types with destructors)
 - rust-lang/rust#163520 (Cast cleanups)
 - rust-lang/rust#163524 (Document `Result` case for the `arena_cache` query modifier)
 - rust-lang/rust#163546 (PassWrapper: adapt for new PassPlugin load method)
 - rust-lang/rust#163551 (Add libs-nominated triagebot config)
 - rust-lang/rust#163559 (Suggest `#[unsafe(no_mangle)]` for entry points in `no_std` binaries)
 - rust-lang/rust#163564 (rustc-dev-guide subtree update)
 - rust-lang/rust#163568 (remove dead cfg_select! arm)
github-actions Bot pushed a commit to rust-lang/rustc-dev-guide that referenced this pull request Oct 5, 2026
Rollup of 20 pull requests

Successful merges:

 - rust-lang/rust#163279 (const and NonZero impl for clamp_magnitude())
 - rust-lang/rust#163081 (Provide more context on "not general enough" error)
 - rust-lang/rust#163455 (Don't use the metadata based crate_hash for rustdoc runs)
 - rust-lang/rust#159798 (Attribute documentation for cfg_attr)
 - rust-lang/rust#162921 (make mips64 `Complex` GCC-compatible)
 - rust-lang/rust#163368 (Don't build format string suggestions from `concat!` offsets)
 - rust-lang/rust#163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance)
 - rust-lang/rust#163470 (Miscellaneous attr error stuff)
 - rust-lang/rust#163489 (expose Rc::is_unique)
 - rust-lang/rust#163492 (x86 and x86_64: cleanup some callconv code)
 - rust-lang/rust#163496 (cycle handling: mirror old solver)
 - rust-lang/rust#163509 (Use more default field values in `Resolver`)
 - rust-lang/rust#163519 (Forbid  `Reborrow` impls for types with destructors)
 - rust-lang/rust#163520 (Cast cleanups)
 - rust-lang/rust#163524 (Document `Result` case for the `arena_cache` query modifier)
 - rust-lang/rust#163546 (PassWrapper: adapt for new PassPlugin load method)
 - rust-lang/rust#163551 (Add libs-nominated triagebot config)
 - rust-lang/rust#163559 (Suggest `#[unsafe(no_mangle)]` for entry points in `no_std` binaries)
 - rust-lang/rust#163564 (rustc-dev-guide subtree update)
 - rust-lang/rust#163568 (remove dead cfg_select! arm)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[ICE]: assertion failed: bpos.to_u32() >= mbc.pos.to_u32() + mbc.bytes as u32

5 participants