Skip to content

Commit 5b20da8

Browse files
committed
interpret: debug-check ScalarPair layout information
1 parent f75d884 commit 5b20da8

File tree

5 files changed

+89
-46
lines changed

5 files changed

+89
-46
lines changed

compiler/rustc_const_eval/src/interpret/operand.rs

+47-24
Original file line numberDiff line numberDiff line change
@@ -84,14 +84,18 @@ impl<'tcx, Tag: Provenance> Immediate<Tag> {
8484
}
8585

8686
#[inline]
87-
pub fn to_scalar_pair(self) -> InterpResult<'tcx, (Scalar<Tag>, Scalar<Tag>)> {
87+
pub fn to_scalar_or_uninit_pair(self) -> (ScalarMaybeUninit<Tag>, ScalarMaybeUninit<Tag>) {
8888
match self {
89-
Immediate::ScalarPair(val1, val2) => Ok((val1.check_init()?, val2.check_init()?)),
90-
Immediate::Scalar(..) => {
91-
bug!("Got a scalar where a scalar pair was expected")
92-
}
89+
Immediate::ScalarPair(val1, val2) => (val1, val2),
90+
Immediate::Scalar(..) => bug!("Got a scalar where a scalar pair was expected"),
9391
}
9492
}
93+
94+
#[inline]
95+
pub fn to_scalar_pair(self) -> InterpResult<'tcx, (Scalar<Tag>, Scalar<Tag>)> {
96+
let (val1, val2) = self.to_scalar_or_uninit_pair();
97+
Ok((val1.check_init()?, val2.check_init()?))
98+
}
9599
}
96100

97101
// ScalarPair needs a type to interpret, so we often have an immediate and a type together
@@ -251,6 +255,7 @@ impl<'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> InterpCx<'mir, 'tcx, M> {
251255
fn try_read_immediate_from_mplace(
252256
&self,
253257
mplace: &MPlaceTy<'tcx, M::PointerTag>,
258+
force: bool,
254259
) -> InterpResult<'tcx, Option<ImmTy<'tcx, M::PointerTag>>> {
255260
if mplace.layout.is_unsized() {
256261
// Don't touch unsized
@@ -271,27 +276,40 @@ impl<'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> InterpCx<'mir, 'tcx, M> {
271276
// case where some of the bytes are initialized and others are not. So, we need an extra
272277
// check that walks over the type of `mplace` to make sure it is truly correct to treat this
273278
// like a `Scalar` (or `ScalarPair`).
274-
match mplace.layout.abi {
275-
Abi::Scalar(abi::Scalar::Initialized { .. }) => {
276-
let scalar = alloc.read_scalar(alloc_range(Size::ZERO, mplace.layout.size))?;
277-
Ok(Some(ImmTy { imm: scalar.into(), layout: mplace.layout }))
278-
}
279+
let scalar_layout = match mplace.layout.abi {
280+
// `if` does not work nested inside patterns, making this a bit awkward to express.
281+
Abi::Scalar(abi::Scalar::Initialized { value: s, .. }) => Some(s),
282+
Abi::Scalar(s) if force => Some(s.primitive()),
283+
_ => None,
284+
};
285+
if let Some(_) = scalar_layout {
286+
let scalar = alloc.read_scalar(alloc_range(Size::ZERO, mplace.layout.size))?;
287+
return Ok(Some(ImmTy { imm: scalar.into(), layout: mplace.layout }));
288+
}
289+
let scalar_pair_layout = match mplace.layout.abi {
279290
Abi::ScalarPair(
280291
abi::Scalar::Initialized { value: a, .. },
281292
abi::Scalar::Initialized { value: b, .. },
282-
) => {
283-
// We checked `ptr_align` above, so all fields will have the alignment they need.
284-
// We would anyway check against `ptr_align.restrict_for_offset(b_offset)`,
285-
// which `ptr.offset(b_offset)` cannot possibly fail to satisfy.
286-
let (a_size, b_size) = (a.size(self), b.size(self));
287-
let b_offset = a_size.align_to(b.align(self).abi);
288-
assert!(b_offset.bytes() > 0); // we later use the offset to tell apart the fields
289-
let a_val = alloc.read_scalar(alloc_range(Size::ZERO, a_size))?;
290-
let b_val = alloc.read_scalar(alloc_range(b_offset, b_size))?;
291-
Ok(Some(ImmTy { imm: Immediate::ScalarPair(a_val, b_val), layout: mplace.layout }))
292-
}
293-
_ => Ok(None),
293+
) => Some((a, b)),
294+
Abi::ScalarPair(a, b) if force => Some((a.primitive(), b.primitive())),
295+
_ => None,
296+
};
297+
if let Some((a, b)) = scalar_pair_layout {
298+
// We checked `ptr_align` above, so all fields will have the alignment they need.
299+
// We would anyway check against `ptr_align.restrict_for_offset(b_offset)`,
300+
// which `ptr.offset(b_offset)` cannot possibly fail to satisfy.
301+
let (a_size, b_size) = (a.size(self), b.size(self));
302+
let b_offset = a_size.align_to(b.align(self).abi);
303+
assert!(b_offset.bytes() > 0); // we later use the offset to tell apart the fields
304+
let a_val = alloc.read_scalar(alloc_range(Size::ZERO, a_size))?;
305+
let b_val = alloc.read_scalar(alloc_range(b_offset, b_size))?;
306+
return Ok(Some(ImmTy {
307+
imm: Immediate::ScalarPair(a_val, b_val),
308+
layout: mplace.layout,
309+
}));
294310
}
311+
// Neither a scalar nor scalar pair.
312+
return Ok(None);
295313
}
296314

297315
/// Try returning an immediate for the operand.
@@ -300,13 +318,18 @@ impl<'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> InterpCx<'mir, 'tcx, M> {
300318
/// Note that for a given layout, this operation will either always fail or always
301319
/// succeed! Whether it succeeds depends on whether the layout can be represented
302320
/// in an `Immediate`, not on which data is stored there currently.
321+
///
322+
/// If `force` is `true`, then even scalars with fields that can be ununit will be
323+
/// read. This means the load is lossy and should not be written back!
324+
/// This flag exists only for validity checking.
303325
pub fn try_read_immediate(
304326
&self,
305327
src: &OpTy<'tcx, M::PointerTag>,
328+
force: bool,
306329
) -> InterpResult<'tcx, Result<ImmTy<'tcx, M::PointerTag>, MPlaceTy<'tcx, M::PointerTag>>> {
307330
Ok(match src.try_as_mplace() {
308331
Ok(ref mplace) => {
309-
if let Some(val) = self.try_read_immediate_from_mplace(mplace)? {
332+
if let Some(val) = self.try_read_immediate_from_mplace(mplace, force)? {
310333
Ok(val)
311334
} else {
312335
Err(*mplace)
@@ -322,7 +345,7 @@ impl<'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> InterpCx<'mir, 'tcx, M> {
322345
&self,
323346
op: &OpTy<'tcx, M::PointerTag>,
324347
) -> InterpResult<'tcx, ImmTy<'tcx, M::PointerTag>> {
325-
if let Ok(imm) = self.try_read_immediate(op)? {
348+
if let Ok(imm) = self.try_read_immediate(op, /*force*/ false)? {
326349
Ok(imm)
327350
} else {
328351
span_bug!(self.cur_span(), "primitive read failed for type: {:?}", op.layout.ty);

compiler/rustc_const_eval/src/interpret/place.rs

+1-1
Original file line numberDiff line numberDiff line change
@@ -879,7 +879,7 @@ where
879879
}
880880

881881
// Let us see if the layout is simple so we take a shortcut, avoid force_allocation.
882-
let src = match self.try_read_immediate(src)? {
882+
let src = match self.try_read_immediate(src, /*force*/ false)? {
883883
Ok(src_val) => {
884884
assert!(!src.layout.is_unsized(), "cannot have unsized immediates");
885885
// Yay, we got a value that we can write directly.

compiler/rustc_const_eval/src/interpret/validity.rs

+38-18
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@ use rustc_target::abi::{Abi, Scalar as ScalarAbi, Size, VariantIdx, Variants, Wr
2020
use std::hash::Hash;
2121

2222
use super::{
23-
alloc_range, CheckInAllocMsg, GlobalAlloc, InterpCx, InterpResult, MPlaceTy, Machine,
24-
MemPlaceMeta, OpTy, Scalar, ScalarMaybeUninit, ValueVisitor,
23+
alloc_range, CheckInAllocMsg, GlobalAlloc, Immediate, InterpCx, InterpResult, MPlaceTy,
24+
Machine, MemPlaceMeta, OpTy, Scalar, ScalarMaybeUninit, ValueVisitor,
2525
};
2626

2727
macro_rules! throw_validation_failure {
@@ -487,6 +487,17 @@ impl<'rt, 'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> ValidityVisitor<'rt, 'mir, '
487487
))
488488
}
489489

490+
fn read_immediate_forced(
491+
&self,
492+
op: &OpTy<'tcx, M::PointerTag>,
493+
) -> InterpResult<'tcx, Immediate<M::PointerTag>> {
494+
Ok(*try_validation!(
495+
self.ecx.try_read_immediate(op, /*force*/ true),
496+
self.path,
497+
err_unsup!(ReadPointerAsBytes) => { "(potentially part of) a pointer" } expected { "plain (non-pointer) bytes" },
498+
).unwrap())
499+
}
500+
490501
/// Check if this is a value of primitive type, and if yes check the validity of the value
491502
/// at that type. Return `true` if the type is indeed primitive.
492503
fn try_visit_primitive(
@@ -626,18 +637,19 @@ impl<'rt, 'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> ValidityVisitor<'rt, 'mir, '
626637

627638
fn visit_scalar(
628639
&mut self,
629-
op: &OpTy<'tcx, M::PointerTag>,
640+
scalar: ScalarMaybeUninit<M::PointerTag>,
630641
scalar_layout: ScalarAbi,
631642
) -> InterpResult<'tcx> {
632643
// We check `is_full_range` in a slightly complicated way because *if* we are checking
633644
// number validity, then we want to ensure that `Scalar::Initialized` is indeed initialized,
634645
// i.e. that we go over the `check_init` below.
646+
let size = scalar_layout.size(self.ecx);
635647
let is_full_range = match scalar_layout {
636648
ScalarAbi::Initialized { valid_range, .. } => {
637649
if M::enforce_number_validity(self.ecx) {
638650
false // not "full" since uninit is not accepted
639651
} else {
640-
valid_range.is_full_for(op.layout.size)
652+
valid_range.is_full_for(size)
641653
}
642654
}
643655
ScalarAbi::Union { .. } => true,
@@ -646,21 +658,19 @@ impl<'rt, 'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> ValidityVisitor<'rt, 'mir, '
646658
// Nothing to check
647659
return Ok(());
648660
}
649-
// We have something to check.
661+
// We have something to check: it must at least be initialized.
650662
let valid_range = scalar_layout.valid_range(self.ecx);
651663
let WrappingRange { start, end } = valid_range;
652-
let max_value = op.layout.size.unsigned_int_max();
664+
let max_value = size.unsigned_int_max();
653665
assert!(end <= max_value);
654-
// Determine the allowed range
655-
let value = self.read_scalar(op)?;
656666
let value = try_validation!(
657-
value.check_init(),
667+
scalar.check_init(),
658668
self.path,
659-
err_ub!(InvalidUninitBytes(None)) => { "{:x}", value }
669+
err_ub!(InvalidUninitBytes(None)) => { "{:x}", scalar }
660670
expected { "something {}", wrapping_range_format(valid_range, max_value) },
661671
);
662672
let bits = match value.try_to_int() {
663-
Ok(int) => int.assert_bits(op.layout.size),
673+
Ok(int) => int.assert_bits(size),
664674
Err(_) => {
665675
// So this is a pointer then, and casting to an int failed.
666676
// Can only happen during CTFE.
@@ -678,7 +688,7 @@ impl<'rt, 'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> ValidityVisitor<'rt, 'mir, '
678688
} else {
679689
return Ok(());
680690
}
681-
} else if scalar_layout.valid_range(self.ecx).is_full_for(op.layout.size) {
691+
} else if scalar_layout.valid_range(self.ecx).is_full_for(size) {
682692
// Easy. (This is reachable if `enforce_number_validity` is set.)
683693
return Ok(());
684694
} else {
@@ -817,13 +827,23 @@ impl<'rt, 'mir, 'tcx: 'mir, M: Machine<'mir, 'tcx>> ValueVisitor<'mir, 'tcx, M>
817827
);
818828
}
819829
Abi::Scalar(scalar_layout) => {
820-
self.visit_scalar(op, scalar_layout)?;
830+
let scalar = self.read_immediate_forced(op)?.to_scalar_or_uninit();
831+
self.visit_scalar(scalar, scalar_layout)?;
832+
}
833+
Abi::ScalarPair(a_layout, b_layout) => {
834+
// We would validate these things as we descend into the fields,
835+
// but that can miss bugs in layout computation. Layout computation
836+
// is subtle due to enums having ScalarPair layout, where one field
837+
// is the discriminant.
838+
if cfg!(debug_assertions) {
839+
let (a, b) = self.read_immediate_forced(op)?.to_scalar_or_uninit_pair();
840+
self.visit_scalar(a, a_layout)?;
841+
self.visit_scalar(b, b_layout)?;
842+
}
821843
}
822-
Abi::ScalarPair { .. } | Abi::Vector { .. } => {
823-
// These have fields that we already visited above, so we already checked
824-
// all their scalar-level restrictions.
825-
// There is also no equivalent to `rustc_layout_scalar_valid_range_start`
826-
// that would make skipping them here an issue.
844+
Abi::Vector { .. } => {
845+
// No checks here, we assume layout computation gets this right.
846+
// (This is harder to check since Miri does not represent these as `Immediate`.)
827847
}
828848
Abi::Aggregate { .. } => {
829849
// Nothing to do.

compiler/rustc_mir_transform/src/const_prop.rs

+2-2
Original file line numberDiff line numberDiff line change
@@ -415,7 +415,7 @@ impl<'mir, 'tcx> ConstPropagator<'mir, 'tcx> {
415415

416416
// Try to read the local as an immediate so that if it is representable as a scalar, we can
417417
// handle it as such, but otherwise, just return the value as is.
418-
Some(match self.ecx.try_read_immediate(&op) {
418+
Some(match self.ecx.try_read_immediate(&op, /*force*/ false) {
419419
Ok(Ok(imm)) => imm.into(),
420420
_ => op,
421421
})
@@ -710,7 +710,7 @@ impl<'mir, 'tcx> ConstPropagator<'mir, 'tcx> {
710710
}
711711

712712
// FIXME> figure out what to do when try_read_immediate fails
713-
let imm = self.use_ecx(|this| this.ecx.try_read_immediate(value));
713+
let imm = self.use_ecx(|this| this.ecx.try_read_immediate(value, /*force*/ false));
714714

715715
if let Some(Ok(imm)) = imm {
716716
match *imm {

compiler/rustc_mir_transform/src/const_prop_lint.rs

+1-1
Original file line numberDiff line numberDiff line change
@@ -412,7 +412,7 @@ impl<'mir, 'tcx> ConstPropagator<'mir, 'tcx> {
412412

413413
// Try to read the local as an immediate so that if it is representable as a scalar, we can
414414
// handle it as such, but otherwise, just return the value as is.
415-
Some(match self.ecx.try_read_immediate(&op) {
415+
Some(match self.ecx.try_read_immediate(&op, /*force*/ false) {
416416
Ok(Ok(imm)) => imm.into(),
417417
_ => op,
418418
})

0 commit comments

Comments
 (0)