alloc_error_handler can be an `unsafe fn` which is then unsoundly invoked
Open
Nobody has claimed this yet.
A-allocators
C-bug
I-unsound
requires-nightly
T-compiler
- Dominant language
- Rust
- Stars
- 119k
- Forks
- 16.1k
- PR merge metrics
- PR metrics pending
Description
This code currently compiles:
#![feature(alloc_error_handler)]
#![no_std]
extern crate alloc;
#[alloc_error_handler]
unsafe fn f(_: alloc::alloc::Layout) -> ! {
core::hint::unreachable_unchecked();
}
This is unsound if the alloc error handler ever gets invoked.
The alloc_error_handler feature is still unstable, tracking issue: https://github.com/rust-lang/rust/issues/51540
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the provided no_std example with the unstable alloc_error_handler feature, then read tracking issue #51540 for the intended contract. Trace how the attribute accepts and invokes the handler, and add a regression test showing that an unsafe handler cannot lead to an unsound invocation; done means the example is rejected or the call is properly handled.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- compilers
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100