Repository navigation
Don't build format string suggestions from concat! offsets - #163368
Merged
Merged
Conversation
When a format string does not come directly from a string literal in the source, e.g. when it is produced by `concat!`, the parser's inner offsets are relative to the expanded string rather than to the source. The primary error span and the `RemoveRawIdent` suggestion already check `is_source_literal` before calling `fmt_span.from_inner`, but the `UsePositional`, `ReorderFormatParameter` and `AddMissingColon` suggestions did not. As a result, these suggestions could point into the middle of a multibyte character and ICE when rendered, or suggest a bogus argument copied from unrelated source text. Only emit them when the format string is a source literal, like the other suggestions do. The crash test is moved to `tests/ui/fmt`, with cases covering each of these suggestions.
Collaborator
|
This PR changes a file inside |
Collaborator
|
Thanks for the pull request, and welcome! The Rust Project has assigned @Enselic (or someone else) to review your changes, you should hear from them (or someone else) within the next two weeks. Please see the contribution instructions and our LLM policy for more information. Why was this reviewer chosen?The reviewer was selected based on:
|
mejrs
approved these changes
Sep 30, 2026
Contributor
JonathanBrouwer
added a commit
to JonathanBrouwer/rust
that referenced
this pull request
Sep 30, 2026
Don't build format string suggestions from `concat!` offsets Fixes rust-lang#156101 When a format string does not come directly from a string literal in the source, e.g. when it is produced by `concat!`, the parser's inner offsets are relative to the expanded string rather than to the source. The primary error span and the `RemoveRawIdent` suggestion already check `is_source_literal` before calling `fmt_span.from_inner`, but the `UsePositional`, `ReorderFormatParameter` and `AddMissingColon` suggestions did not. As a result, these suggestions could point into the middle of a multibyte character and ICE when rendered, or suggest a bogus argument copied from unrelated source text. Only emit them when the format string is a source literal, like the other suggestions do. For example, before this change `UsePositional` took `at!` from the `concat!` invocation as the captured argument, replaced it with `0`, and suggested passing `at!` as an argument: ``` help: consider using a positional formatting argument instead | 2 - format_args!(concat!("{}{a.b}", "")); 2 + format_args!(conc0("{}{a.b}", ""), at!); ``` The crash test is moved to `tests/ui/fmt`, with cases covering each of these suggestions.
JonathanBrouwer
added a commit
to JonathanBrouwer/rust
that referenced
this pull request
Sep 30, 2026
Don't build format string suggestions from `concat!` offsets Fixes rust-lang#156101 When a format string does not come directly from a string literal in the source, e.g. when it is produced by `concat!`, the parser's inner offsets are relative to the expanded string rather than to the source. The primary error span and the `RemoveRawIdent` suggestion already check `is_source_literal` before calling `fmt_span.from_inner`, but the `UsePositional`, `ReorderFormatParameter` and `AddMissingColon` suggestions did not. As a result, these suggestions could point into the middle of a multibyte character and ICE when rendered, or suggest a bogus argument copied from unrelated source text. Only emit them when the format string is a source literal, like the other suggestions do. For example, before this change `UsePositional` took `at!` from the `concat!` invocation as the captured argument, replaced it with `0`, and suggested passing `at!` as an argument: ``` help: consider using a positional formatting argument instead | 2 - format_args!(concat!("{}{a.b}", "")); 2 + format_args!(conc0("{}{a.b}", ""), at!); ``` The crash test is moved to `tests/ui/fmt`, with cases covering each of these suggestions.
JonathanBrouwer
added a commit
to JonathanBrouwer/rust
that referenced
this pull request
Sep 30, 2026
Don't build format string suggestions from `concat!` offsets Fixes rust-lang#156101 When a format string does not come directly from a string literal in the source, e.g. when it is produced by `concat!`, the parser's inner offsets are relative to the expanded string rather than to the source. The primary error span and the `RemoveRawIdent` suggestion already check `is_source_literal` before calling `fmt_span.from_inner`, but the `UsePositional`, `ReorderFormatParameter` and `AddMissingColon` suggestions did not. As a result, these suggestions could point into the middle of a multibyte character and ICE when rendered, or suggest a bogus argument copied from unrelated source text. Only emit them when the format string is a source literal, like the other suggestions do. For example, before this change `UsePositional` took `at!` from the `concat!` invocation as the captured argument, replaced it with `0`, and suggested passing `at!` as an argument: ``` help: consider using a positional formatting argument instead | 2 - format_args!(concat!("{}{a.b}", "")); 2 + format_args!(conc0("{}{a.b}", ""), at!); ``` The crash test is moved to `tests/ui/fmt`, with cases covering each of these suggestions.
rust-bors Bot
pushed a commit
that referenced
this pull request
Sep 30, 2026
…uwer Rollup of 18 pull requests Successful merges: - #163532 (rustc_codegen_cranelift subtree update) - #163534 (miri subtree update) - #163279 (const and NonZero impl for clamp_magnitude()) - #162900 (Some refactorings around metadata encoding) - #163455 (Don't use the metadata based crate_hash for rustdoc runs) - #163483 (Bump bootstrap compiler to 1.100.0 beta) - #159798 (Attribute documentation for cfg_attr) - #163368 (Don't build format string suggestions from `concat!` offsets) - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance) - #163405 (Remove some #[linkage] options) - #163470 (Miscellaneous attr error stuff) - #163489 (expose Rc::is_unique) - #163492 (x86 and x86_64: cleanup some callconv code) - #163496 (cycle handling: mirror old solver) - #163509 (Use more default field values in `Resolver`) - #163519 (Forbid `Reborrow` impls for types with destructors) - #163520 (Cast cleanups) - #163524 (Document `Result` case for the `arena_cache` query modifier) Failed merges: - #163547 ([beta] rustfmt backport)
JonathanBrouwer
added a commit
to JonathanBrouwer/rust
that referenced
this pull request
Sep 30, 2026
Don't build format string suggestions from `concat!` offsets Fixes rust-lang#156101 When a format string does not come directly from a string literal in the source, e.g. when it is produced by `concat!`, the parser's inner offsets are relative to the expanded string rather than to the source. The primary error span and the `RemoveRawIdent` suggestion already check `is_source_literal` before calling `fmt_span.from_inner`, but the `UsePositional`, `ReorderFormatParameter` and `AddMissingColon` suggestions did not. As a result, these suggestions could point into the middle of a multibyte character and ICE when rendered, or suggest a bogus argument copied from unrelated source text. Only emit them when the format string is a source literal, like the other suggestions do. For example, before this change `UsePositional` took `at!` from the `concat!` invocation as the captured argument, replaced it with `0`, and suggested passing `at!` as an argument: ``` help: consider using a positional formatting argument instead | 2 - format_args!(concat!("{}{a.b}", "")); 2 + format_args!(conc0("{}{a.b}", ""), at!); ``` The crash test is moved to `tests/ui/fmt`, with cases covering each of these suggestions.
rust-bors Bot
pushed a commit
that referenced
this pull request
Sep 30, 2026
…uwer Rollup of 18 pull requests Successful merges: - #163532 (rustc_codegen_cranelift subtree update) - #163534 (miri subtree update) - #163279 (const and NonZero impl for clamp_magnitude()) - #162900 (Some refactorings around metadata encoding) - #163455 (Don't use the metadata based crate_hash for rustdoc runs) - #159798 (Attribute documentation for cfg_attr) - #162921 (make mips64 `Complex` GCC-compatible) - #163368 (Don't build format string suggestions from `concat!` offsets) - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance) - #163405 (Remove some #[linkage] options) - #163470 (Miscellaneous attr error stuff) - #163489 (expose Rc::is_unique) - #163492 (x86 and x86_64: cleanup some callconv code) - #163496 (cycle handling: mirror old solver) - #163509 (Use more default field values in `Resolver`) - #163519 (Forbid `Reborrow` impls for types with destructors) - #163520 (Cast cleanups) - #163524 (Document `Result` case for the `arena_cache` query modifier)
rust-bors Bot
pushed a commit
that referenced
this pull request
Sep 30, 2026
…uwer Rollup of 18 pull requests Successful merges: - #163532 (rustc_codegen_cranelift subtree update) - #163534 (miri subtree update) - #163279 (const and NonZero impl for clamp_magnitude()) - #162900 (Some refactorings around metadata encoding) - #163455 (Don't use the metadata based crate_hash for rustdoc runs) - #159798 (Attribute documentation for cfg_attr) - #162921 (make mips64 `Complex` GCC-compatible) - #163368 (Don't build format string suggestions from `concat!` offsets) - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance) - #163405 (Remove some #[linkage] options) - #163470 (Miscellaneous attr error stuff) - #163489 (expose Rc::is_unique) - #163492 (x86 and x86_64: cleanup some callconv code) - #163496 (cycle handling: mirror old solver) - #163509 (Use more default field values in `Resolver`) - #163519 (Forbid `Reborrow` impls for types with destructors) - #163520 (Cast cleanups) - #163524 (Document `Result` case for the `arena_cache` query modifier)
rust-bors Bot
pushed a commit
that referenced
this pull request
Oct 1, 2026
Rollup of 20 pull requests Successful merges: - #163279 (const and NonZero impl for clamp_magnitude()) - #163081 (Provide more context on "not general enough" error) - #163455 (Don't use the metadata based crate_hash for rustdoc runs) - #159798 (Attribute documentation for cfg_attr) - #162921 (make mips64 `Complex` GCC-compatible) - #163368 (Don't build format string suggestions from `concat!` offsets) - #163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance) - #163470 (Miscellaneous attr error stuff) - #163489 (expose Rc::is_unique) - #163492 (x86 and x86_64: cleanup some callconv code) - #163496 (cycle handling: mirror old solver) - #163509 (Use more default field values in `Resolver`) - #163519 (Forbid `Reborrow` impls for types with destructors) - #163520 (Cast cleanups) - #163524 (Document `Result` case for the `arena_cache` query modifier) - #163546 (PassWrapper: adapt for new PassPlugin load method) - #163551 (Add libs-nominated triagebot config) - #163559 (Suggest `#[unsafe(no_mangle)]` for entry points in `no_std` binaries) - #163564 (rustc-dev-guide subtree update) - #163568 (remove dead cfg_select! arm)
rust-bors Bot
pushed a commit
that referenced
this pull request
Oct 1, 2026
Rollup merge of #163368 - h-kurashina:fix-156101, r=mejrs Don't build format string suggestions from `concat!` offsets Fixes #156101 When a format string does not come directly from a string literal in the source, e.g. when it is produced by `concat!`, the parser's inner offsets are relative to the expanded string rather than to the source. The primary error span and the `RemoveRawIdent` suggestion already check `is_source_literal` before calling `fmt_span.from_inner`, but the `UsePositional`, `ReorderFormatParameter` and `AddMissingColon` suggestions did not. As a result, these suggestions could point into the middle of a multibyte character and ICE when rendered, or suggest a bogus argument copied from unrelated source text. Only emit them when the format string is a source literal, like the other suggestions do. For example, before this change `UsePositional` took `at!` from the `concat!` invocation as the captured argument, replaced it with `0`, and suggested passing `at!` as an argument: ``` help: consider using a positional formatting argument instead | 2 - format_args!(concat!("{}{a.b}", "")); 2 + format_args!(conc0("{}{a.b}", ""), at!); ``` The crash test is moved to `tests/ui/fmt`, with cases covering each of these suggestions.
RalfJung
pushed a commit
to RalfJung/miri
that referenced
this pull request
Oct 1, 2026
Rollup of 20 pull requests Successful merges: - rust-lang/rust#163279 (const and NonZero impl for clamp_magnitude()) - rust-lang/rust#163081 (Provide more context on "not general enough" error) - rust-lang/rust#163455 (Don't use the metadata based crate_hash for rustdoc runs) - rust-lang/rust#159798 (Attribute documentation for cfg_attr) - rust-lang/rust#162921 (make mips64 `Complex` GCC-compatible) - rust-lang/rust#163368 (Don't build format string suggestions from `concat!` offsets) - rust-lang/rust#163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance) - rust-lang/rust#163470 (Miscellaneous attr error stuff) - rust-lang/rust#163489 (expose Rc::is_unique) - rust-lang/rust#163492 (x86 and x86_64: cleanup some callconv code) - rust-lang/rust#163496 (cycle handling: mirror old solver) - rust-lang/rust#163509 (Use more default field values in `Resolver`) - rust-lang/rust#163519 (Forbid `Reborrow` impls for types with destructors) - rust-lang/rust#163520 (Cast cleanups) - rust-lang/rust#163524 (Document `Result` case for the `arena_cache` query modifier) - rust-lang/rust#163546 (PassWrapper: adapt for new PassPlugin load method) - rust-lang/rust#163551 (Add libs-nominated triagebot config) - rust-lang/rust#163559 (Suggest `#[unsafe(no_mangle)]` for entry points in `no_std` binaries) - rust-lang/rust#163564 (rustc-dev-guide subtree update) - rust-lang/rust#163568 (remove dead cfg_select! arm)
github-actions Bot
pushed a commit
to rust-lang/rustc-dev-guide
that referenced
this pull request
Oct 5, 2026
Rollup of 20 pull requests Successful merges: - rust-lang/rust#163279 (const and NonZero impl for clamp_magnitude()) - rust-lang/rust#163081 (Provide more context on "not general enough" error) - rust-lang/rust#163455 (Don't use the metadata based crate_hash for rustdoc runs) - rust-lang/rust#159798 (Attribute documentation for cfg_attr) - rust-lang/rust#162921 (make mips64 `Complex` GCC-compatible) - rust-lang/rust#163368 (Don't build format string suggestions from `concat!` offsets) - rust-lang/rust#163375 (Update expect messages in library/std/src/os/unix/net/ following Rust's `expect` guidance) - rust-lang/rust#163470 (Miscellaneous attr error stuff) - rust-lang/rust#163489 (expose Rc::is_unique) - rust-lang/rust#163492 (x86 and x86_64: cleanup some callconv code) - rust-lang/rust#163496 (cycle handling: mirror old solver) - rust-lang/rust#163509 (Use more default field values in `Resolver`) - rust-lang/rust#163519 (Forbid `Reborrow` impls for types with destructors) - rust-lang/rust#163520 (Cast cleanups) - rust-lang/rust#163524 (Document `Result` case for the `arena_cache` query modifier) - rust-lang/rust#163546 (PassWrapper: adapt for new PassPlugin load method) - rust-lang/rust#163551 (Add libs-nominated triagebot config) - rust-lang/rust#163559 (Suggest `#[unsafe(no_mangle)]` for entry points in `no_std` binaries) - rust-lang/rust#163564 (rustc-dev-guide subtree update) - rust-lang/rust#163568 (remove dead cfg_select! arm)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #156101
When a format string does not come directly from a string literal in
the source, e.g. when it is produced by
concat!, the parser's inneroffsets are relative to the expanded string rather than to the source.
The primary error span and the
RemoveRawIdentsuggestion alreadycheck
is_source_literalbefore callingfmt_span.from_inner, but theUsePositional,ReorderFormatParameterandAddMissingColonsuggestions did not.
As a result, these suggestions could point into the middle of a
multibyte character and ICE when rendered, or suggest a bogus argument
copied from unrelated source text. Only emit them when the format
string is a source literal, like the other suggestions do.
For example, before this change
UsePositionaltookat!from theconcat!invocation as the captured argument, replaced it with0,and suggested passing
at!as an argument:The crash test is moved to
tests/ui/fmt, with cases covering each ofthese suggestions.