Skip to content

std: improve safety documentation in UNIX stack overflow code - #162132

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
joboet:safe_stack_overflow
Sep 3, 2026
Merged

std: improve safety documentation in UNIX stack overflow code#162132
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
joboet:safe_stack_overflow

Conversation

@joboet

@joboet joboet commented Sep 1, 2026

Copy link
Copy Markdown
Member

The UNIX stack overflow handling code was only partially documented, and applied #![forbid(unsafe_op_in_unsafe_fn)] inconsistently. Also, the existing safety documentation wasn't very clear on the assumptions made by std and the reasoning behind those assumptions. I've tried to rectify all that here by adding some unsafe, removing some unsafe and writing a lot of comments. There are no functional changes however, I'll get started on those once this is merged.

@rustbot rustbot added O-unix Operating system: Unix-like S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-libs Relevant to the library team, which will review and decide on the PR/issue. labels Sep 1, 2026
@rustbot

rustbot commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

r? @ChrisDenton

rustbot has assigned @ChrisDenton.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: @ChrisDenton, libs
  • @ChrisDenton, libs expanded to 13 candidates
  • Random selection from ChrisDenton, JohnTitor, Mark-Simulacrum, clarfonthey

@rust-log-analyzer

This comment has been minimized.

@joboet
joboet force-pushed the safe_stack_overflow branch from 0340a0f to 7394cc6 Compare September 1, 2026 18:08

@ChrisDenton ChrisDenton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is much clearer to read, thanks.

I do wonder if it'd be worth creating small wrappers for some of the trivially safe functions if they're used more than a couple of times.

View changes since this review

Comment thread library/std/src/sys/pal/unix/stack_overflow.rs
Comment thread library/std/src/sys/pal/unix/stack_overflow.rs
@joboet

joboet commented Sep 2, 2026

Copy link
Copy Markdown
Member Author

I do wonder if it'd be worth creating small wrappers for some of the trivially safe functions if they're used more than a couple of times.

That sounds like a good idea. I think I'll defer that to a follow-up PR though, unless you think otherwise?

@ChrisDenton

Copy link
Copy Markdown
Member

This is definitely an improvement on its own so I'm happy to accept this as-is

@bors r+

@rust-bors

rust-bors Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

📌 Commit 7394cc6 has been approved by ChrisDenton

It is now in the queue for this repository.

@rust-bors rust-bors Bot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Sep 3, 2026
Zalathar added a commit to Zalathar/rust that referenced this pull request Sep 3, 2026
…sDenton

std: improve safety documentation in UNIX stack overflow code

The UNIX stack overflow handling code was only partially documented, and applied `#![forbid(unsafe_op_in_unsafe_fn)]` inconsistently. Also, the existing safety documentation wasn't very clear on the assumptions made by `std` and the reasoning behind those assumptions. I've tried to rectify all that here by adding some `unsafe`, removing some `unsafe` and writing a lot of comments. There are no functional changes however, I'll get started on those once this is merged.
rust-bors Bot pushed a commit that referenced this pull request Sep 3, 2026
Rollup of 29 pull requests

Successful merges:

 - #161694 (add `Complex` ABI run-make test)
 - #162014 (Move more `rustdoc-html` tests using `--test` into the right folder)
 - #162164 (Revert "Implement Debug for C-like enums with a concatenated string")
 - #160564 (volatile: allow accesses to non-AM memory to trap)
 - #161579 (suggest calling a fn item used as the iterator of a `for` loop)
 - #162044 (coverage: Resolve spans to file-coordinates in a separate step)
 - #162120 (Introduce `PerOwnerLoweringState`)
 - #162132 (std: improve safety documentation in UNIX stack overflow code)
 - #162151 (Test itanium mangling of `f16` and `f128`)
 - #162162 (Don't special-case `!` in stability checks anymore)
 - #162181 (Remove wrong UnusedBraces lint for iterator loop in edition 2024 )
 - #162187 (Rename `thir::ExprKind::Use` to `ValueExpr`)
 - #158401 (mgca: Don't ICE when evaluating ValTrees that contain error constants)
 - #159873 (fuchsia: Add safestack as a supported sanitizer for x86_64 fuchsia)
 - #161847 (Preserve visibility in nested macro import suggestions)
 - #161951 (Windows: add fallback if `canonicalize` fails)
 - #161972 (Improve tests for `#[track_caller]` in async)
 - #162008 (Render the `box` pattern removal diagnostic more actionable & remove `box` expression recovery)
 - #162065 (std: don't reference `libc::O_NOFOLLOW` on VxWorks in `set_perm_nofollow`)
 - #162076 (docs(num): clarify conditions under which error occurs in `impl TryFrom<int> for int`)
 - #162152 (Revert "retrieve supported GCC targets from the sysroot")
 - #162153 (Prefer `LLVMGetVersion` for runtime info)
 - #162168 (fix ICE in project_goals/inherent)
 - #162171 (Explain LoongArch f16 NaN-boxing in inline asm)
 - #162173 (fix supposedly unreachable `bug!` being reachable)
 - #162180 (remove outdated next-solver FIXMEs)
 - #162191 (core: mark float `ClampBounds` methods as `#[inline]`)
 - #162195 (docs(time): clarify exact seconds for week and day)
 - #162199 (docs(time): clarify exact seconds for hour and minute)
rust-bors Bot pushed a commit that referenced this pull request Sep 3, 2026
…uwer

Rollup of 25 pull requests

Successful merges:

 - #161694 (add `Complex` ABI run-make test)
 - #162014 (Move more `rustdoc-html` tests using `--test` into the right folder)
 - #162164 (Revert "Implement Debug for C-like enums with a concatenated string")
 - #160564 (volatile: allow accesses to non-AM memory to trap)
 - #161579 (suggest calling a fn item used as the iterator of a `for` loop)
 - #162044 (coverage: Resolve spans to file-coordinates in a separate step)
 - #162120 (Introduce `PerOwnerLoweringState`)
 - #162132 (std: improve safety documentation in UNIX stack overflow code)
 - #162151 (Test itanium mangling of `f16` and `f128`)
 - #162162 (Don't special-case `!` in stability checks anymore)
 - #162181 (Remove wrong UnusedBraces lint for iterator loop in edition 2024 )
 - #162187 (Rename `thir::ExprKind::Use` to `ValueExpr`)
 - #158401 (mgca: Don't ICE when evaluating ValTrees that contain error constants)
 - #159873 (fuchsia: Add safestack as a supported sanitizer for x86_64 fuchsia)
 - #161135 (Add `f16` and `f128` inline ASM support for PowerPC)
 - #161847 (Preserve visibility in nested macro import suggestions)
 - #161972 (Improve tests for `#[track_caller]` in async)
 - #162008 (Render the `box` pattern removal diagnostic more actionable & remove `box` expression recovery)
 - #162065 (std: don't reference `libc::O_NOFOLLOW` on VxWorks in `set_perm_nofollow`)
 - #162076 (docs(num): clarify conditions under which error occurs in `impl TryFrom<int> for int`)
 - #162111 (Update mailmap for Will Crichton and Petr Hosek)
 - #162152 (Revert "retrieve supported GCC targets from the sysroot")
 - #162153 (Prefer `LLVMGetVersion` for runtime info)
 - #162168 (fix ICE in project_goals/inherent)
 - #162171 (Explain LoongArch f16 NaN-boxing in inline asm)
@rust-bors
rust-bors Bot merged commit 92e0f00 into rust-lang:main Sep 3, 2026
13 checks passed
@rustbot rustbot added this to the 1.100.0 milestone Sep 3, 2026
rust-bors Bot pushed a commit that referenced this pull request Sep 3, 2026
Rollup merge of #162132 - joboet:safe_stack_overflow, r=ChrisDenton

std: improve safety documentation in UNIX stack overflow code

The UNIX stack overflow handling code was only partially documented, and applied `#![forbid(unsafe_op_in_unsafe_fn)]` inconsistently. Also, the existing safety documentation wasn't very clear on the assumptions made by `std` and the reasoning behind those assumptions. I've tried to rectify all that here by adding some `unsafe`, removing some `unsafe` and writing a lot of comments. There are no functional changes however, I'll get started on those once this is merged.
@rust-timer

Copy link
Copy Markdown
Collaborator

Note

This PR was benchmarked as part of triage of its containing rollup: triage URL.

Finished benchmarking commit (6d17148): comparison URL.

Overall result: no relevant changes - no action needed

@rustbot label: -perf-regression

Instruction count

This perf run didn't have relevant results for this metric.

Max RSS (memory usage)

This perf run didn't have relevant results for this metric.

Cycles

This perf run didn't have relevant results for this metric.

Binary size

This perf run didn't have relevant results for this metric.

Bootstrap: missing data
Artifact size: 401.86 MiB -> 401.08 MiB (-0.20%)

pull Bot pushed a commit to LeeeeeeM/miri that referenced this pull request Sep 4, 2026
…uwer

Rollup of 25 pull requests

Successful merges:

 - rust-lang/rust#161694 (add `Complex` ABI run-make test)
 - rust-lang/rust#162014 (Move more `rustdoc-html` tests using `--test` into the right folder)
 - rust-lang/rust#162164 (Revert "Implement Debug for C-like enums with a concatenated string")
 - rust-lang/rust#160564 (volatile: allow accesses to non-AM memory to trap)
 - rust-lang/rust#161579 (suggest calling a fn item used as the iterator of a `for` loop)
 - rust-lang/rust#162044 (coverage: Resolve spans to file-coordinates in a separate step)
 - rust-lang/rust#162120 (Introduce `PerOwnerLoweringState`)
 - rust-lang/rust#162132 (std: improve safety documentation in UNIX stack overflow code)
 - rust-lang/rust#162151 (Test itanium mangling of `f16` and `f128`)
 - rust-lang/rust#162162 (Don't special-case `!` in stability checks anymore)
 - rust-lang/rust#162181 (Remove wrong UnusedBraces lint for iterator loop in edition 2024 )
 - rust-lang/rust#162187 (Rename `thir::ExprKind::Use` to `ValueExpr`)
 - rust-lang/rust#158401 (mgca: Don't ICE when evaluating ValTrees that contain error constants)
 - rust-lang/rust#159873 (fuchsia: Add safestack as a supported sanitizer for x86_64 fuchsia)
 - rust-lang/rust#161135 (Add `f16` and `f128` inline ASM support for PowerPC)
 - rust-lang/rust#161847 (Preserve visibility in nested macro import suggestions)
 - rust-lang/rust#161972 (Improve tests for `#[track_caller]` in async)
 - rust-lang/rust#162008 (Render the `box` pattern removal diagnostic more actionable & remove `box` expression recovery)
 - rust-lang/rust#162065 (std: don't reference `libc::O_NOFOLLOW` on VxWorks in `set_perm_nofollow`)
 - rust-lang/rust#162076 (docs(num): clarify conditions under which error occurs in `impl TryFrom<int> for int`)
 - rust-lang/rust#162111 (Update mailmap for Will Crichton and Petr Hosek)
 - rust-lang/rust#162152 (Revert "retrieve supported GCC targets from the sysroot")
 - rust-lang/rust#162153 (Prefer `LLVMGetVersion` for runtime info)
 - rust-lang/rust#162168 (fix ICE in project_goals/inherent)
 - rust-lang/rust#162171 (Explain LoongArch f16 NaN-boxing in inline asm)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

O-unix Operating system: Unix-like S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. T-libs Relevant to the library team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants