From 73d3b1c601d86778a9b0b85a0aebd8eceb2542a7 Mon Sep 17 00:00:00 2001 From: Ralf Jung Date: Sat, 15 Aug 2026 08:54:17 +0200 Subject: [PATCH] fix buggy MaybeDangling<&T> validation logic --- compiler/rustc_const_eval/src/interpret/validity.rs | 13 +++++++++---- .../miri/tests/pass/both_borrows/maybe_dangling.rs | 6 ++++++ 2 files changed, 15 insertions(+), 4 deletions(-) diff --git a/compiler/rustc_const_eval/src/interpret/validity.rs b/compiler/rustc_const_eval/src/interpret/validity.rs index d0bcc52fc9734..8c0bb1fcdd8a5 100644 --- a/compiler/rustc_const_eval/src/interpret/validity.rs +++ b/compiler/rustc_const_eval/src/interpret/validity.rs @@ -21,7 +21,8 @@ use rustc_data_structures::fx::FxHashSet; use rustc_hir as hir; use rustc_middle::bug; use rustc_middle::mir::interpret::{ - InterpErrorKind, InvalidMetaKind, Misalignment, Provenance, alloc_range, interp_ok, + InterpErrorKind, InvalidMetaKind, Misalignment, PointerArithmetic, Provenance, alloc_range, + interp_ok, }; use rustc_middle::ty::layout::{LayoutCx, TyAndLayout}; use rustc_middle::ty::{self, Ty}; @@ -653,9 +654,13 @@ impl<'rt, 'tcx, M: Machine<'tcx>> ValidityVisitor<'rt, 'tcx, M> { let scalar = Scalar::from_maybe_pointer(place.ptr(), self.ecx); // Skip this if we don't know the absolute address (during CTFE). if let Ok(addr) = scalar.try_to_scalar_int() { - // Try to compute the end address. - let addr = Size::from_bytes(addr.to_target_usize(*self.ecx.tcx)); - if addr.checked_add(size, self.ecx).is_none() { + // Try to compute the end address. Cannot use `Size` addition as that also applies + // the "max obj size" bound. + let addr = Size::from_bytes(addr.to_target_usize(*self.ecx.tcx)).bytes(); + if addr + .checked_add(size.bytes()) + .is_none_or(|result| result >= self.ecx.target_usize_max()) + { throw_validation_failure!( self.path, format!( diff --git a/src/tools/miri/tests/pass/both_borrows/maybe_dangling.rs b/src/tools/miri/tests/pass/both_borrows/maybe_dangling.rs index c3c290824acbe..028dcef8fa2d3 100644 --- a/src/tools/miri/tests/pass/both_borrows/maybe_dangling.rs +++ b/src/tools/miri/tests/pass/both_borrows/maybe_dangling.rs @@ -13,6 +13,7 @@ fn main() { boxy(); reference(); write_through_shared_ref(); + large(); } fn boxy() { @@ -58,3 +59,8 @@ fn write_through_shared_ref() { } } } + +fn large() { + // Used to be rejected due to faulty logic for the "does this fit the address space" check. + let _x: MaybeDangling<&i8> = unsafe { mem::transmute(usize::MAX - 127) }; +}