-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add invalid null pointer usage lint. #6192
Closed
Closed
Changes from all commits
Commits
Show all changes
8 commits
Select commit
Hold shift + click to select a range
446acc7
Add invalid null pointer usage lint.
boxdot 8dcc446
Check also for std::ptr::{null, null_mut}.
boxdot b0844cf
Rename lint to invalid_null_ptr_usage.
boxdot d76f8e5
Add test for ptr::null_mut.
boxdot 8ef5a6d
Address review comments: remove dot (also in CMP_NULL).
boxdot e15d0ce
Address review comment: extend lint on std::slice::from_raw_parts_mut
boxdot 79ed1c7
Add remaining functions from std::ptr.
boxdot 4c56ef0
Make clippy happy.
boxdot File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,49 @@ | ||
// run-rustfix | ||
|
||
fn main() { | ||
unsafe { | ||
let _slice: &[usize] = std::slice::from_raw_parts(core::ptr::NonNull::dangling().as_ptr(), 0); | ||
let _slice: &[usize] = std::slice::from_raw_parts(core::ptr::NonNull::dangling().as_ptr(), 0); | ||
|
||
let _slice: &[usize] = std::slice::from_raw_parts_mut(core::ptr::NonNull::dangling().as_ptr(), 0); | ||
|
||
std::ptr::copy::<usize>(std::ptr::null(), std::ptr::NonNull::dangling().as_ptr(), 0); | ||
std::ptr::copy::<usize>(std::ptr::NonNull::dangling().as_ptr(), std::ptr::null_mut(), 0); | ||
|
||
std::ptr::copy_nonoverlapping::<usize>(std::ptr::null(), std::ptr::NonNull::dangling().as_ptr(), 0); | ||
std::ptr::copy_nonoverlapping::<usize>(std::ptr::NonNull::dangling().as_ptr(), std::ptr::null_mut(), 0); | ||
Comment on lines
+10
to
+14
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. These cases do not seem to be detected There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Resolved in #7023 |
||
|
||
struct A; // zero sized struct | ||
assert_eq!(std::mem::size_of::<A>(), 0); | ||
|
||
let _a: A = std::ptr::read(core::ptr::NonNull::dangling().as_ptr()); | ||
let _a: A = std::ptr::read(core::ptr::NonNull::dangling().as_ptr()); | ||
|
||
let _a: A = std::ptr::read_unaligned(core::ptr::NonNull::dangling().as_ptr()); | ||
let _a: A = std::ptr::read_unaligned(core::ptr::NonNull::dangling().as_ptr()); | ||
|
||
let _a: A = std::ptr::read_volatile(core::ptr::NonNull::dangling().as_ptr()); | ||
let _a: A = std::ptr::read_volatile(core::ptr::NonNull::dangling().as_ptr()); | ||
|
||
let _a: A = std::ptr::replace(core::ptr::NonNull::dangling().as_ptr(), A); | ||
|
||
let _slice: *const [usize] = std::ptr::slice_from_raw_parts(core::ptr::NonNull::dangling().as_ptr(), 0); | ||
let _slice: *const [usize] = std::ptr::slice_from_raw_parts(core::ptr::NonNull::dangling().as_ptr(), 0); | ||
|
||
let _slice: *const [usize] = std::ptr::slice_from_raw_parts_mut(core::ptr::NonNull::dangling().as_ptr(), 0); | ||
|
||
std::ptr::swap::<A>(core::ptr::NonNull::dangling().as_ptr(), &mut A); | ||
std::ptr::swap::<A>(&mut A, core::ptr::NonNull::dangling().as_ptr()); | ||
|
||
std::ptr::swap_nonoverlapping::<A>(core::ptr::NonNull::dangling().as_ptr(), &mut A, 0); | ||
std::ptr::swap_nonoverlapping::<A>(&mut A, core::ptr::NonNull::dangling().as_ptr(), 0); | ||
|
||
std::ptr::write(core::ptr::NonNull::dangling().as_ptr(), A); | ||
|
||
std::ptr::write_unaligned(core::ptr::NonNull::dangling().as_ptr(), A); | ||
|
||
std::ptr::write_volatile(core::ptr::NonNull::dangling().as_ptr(), A); | ||
|
||
std::ptr::write_bytes::<usize>(core::ptr::NonNull::dangling().as_ptr(), 42, 0); | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,49 @@ | ||
// run-rustfix | ||
|
||
fn main() { | ||
unsafe { | ||
let _slice: &[usize] = std::slice::from_raw_parts(std::ptr::null(), 0); | ||
let _slice: &[usize] = std::slice::from_raw_parts(std::ptr::null_mut(), 0); | ||
|
||
let _slice: &[usize] = std::slice::from_raw_parts_mut(std::ptr::null_mut(), 0); | ||
|
||
std::ptr::copy::<usize>(std::ptr::null(), std::ptr::NonNull::dangling().as_ptr(), 0); | ||
std::ptr::copy::<usize>(std::ptr::NonNull::dangling().as_ptr(), std::ptr::null_mut(), 0); | ||
|
||
std::ptr::copy_nonoverlapping::<usize>(std::ptr::null(), std::ptr::NonNull::dangling().as_ptr(), 0); | ||
std::ptr::copy_nonoverlapping::<usize>(std::ptr::NonNull::dangling().as_ptr(), std::ptr::null_mut(), 0); | ||
|
||
struct A; // zero sized struct | ||
assert_eq!(std::mem::size_of::<A>(), 0); | ||
|
||
let _a: A = std::ptr::read(std::ptr::null()); | ||
let _a: A = std::ptr::read(std::ptr::null_mut()); | ||
|
||
let _a: A = std::ptr::read_unaligned(std::ptr::null()); | ||
let _a: A = std::ptr::read_unaligned(std::ptr::null_mut()); | ||
|
||
let _a: A = std::ptr::read_volatile(std::ptr::null()); | ||
let _a: A = std::ptr::read_volatile(std::ptr::null_mut()); | ||
|
||
let _a: A = std::ptr::replace(std::ptr::null_mut(), A); | ||
|
||
let _slice: *const [usize] = std::ptr::slice_from_raw_parts(std::ptr::null(), 0); | ||
let _slice: *const [usize] = std::ptr::slice_from_raw_parts(std::ptr::null_mut(), 0); | ||
|
||
let _slice: *const [usize] = std::ptr::slice_from_raw_parts_mut(std::ptr::null_mut(), 0); | ||
|
||
std::ptr::swap::<A>(std::ptr::null_mut(), &mut A); | ||
std::ptr::swap::<A>(&mut A, std::ptr::null_mut()); | ||
|
||
std::ptr::swap_nonoverlapping::<A>(std::ptr::null_mut(), &mut A, 0); | ||
std::ptr::swap_nonoverlapping::<A>(&mut A, std::ptr::null_mut(), 0); | ||
|
||
std::ptr::write(std::ptr::null_mut(), A); | ||
|
||
std::ptr::write_unaligned(std::ptr::null_mut(), A); | ||
|
||
std::ptr::write_volatile(std::ptr::null_mut(), A); | ||
|
||
std::ptr::write_bytes::<usize>(std::ptr::null_mut(), 42, 0); | ||
} | ||
} |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Seems like this is a perfect lint for #5393. Should we try to add diagnostics to the functions instead of hardcoding them here? I would need some hints how to do this though. :)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think you are right. I'm not familiar with the process of adding diagnostic items, but looking at this commit it seems that just adding the attribute should be enough?
This should be done in the rust-lang/rust repo, and we can sync that change afterwards and finish the lint here. As a heads-up we may try to pin to a nightly soon in this repo, so the aforementioned sync process could change. I apologize in advance if that creates any problem, we still have to discover what the new way of working with the pinned nightly will look like :)
EDIT: GitHub inlined this comment in the review, but not the whole conversation. Take a look at the additional comment there. TL;DR this is not needed for merging.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
FYI, there are other lints being currently implemented that will add paths (e.g. #6394)
Even though the right thing to do would be probably to turn those into diagnostic items, I will not make a blocker out of this, so it's fine if you leave the paths here. I understand it would make merging this way longer, and it's not a problem introduced in your PR.
Ideally, you can address #5393 after this one if you want :)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You were right about first merging this and then adding diagnostic items to the compiler. I got stuck in the latter step.