Repository navigation
implied bounds from associated types may not actually get implied pt 2. #98543
Copy link
Copy link
Closed
Labels
A-associated-itemsArea: Associated items (types, constants & functions)Area: Associated items (types, constants & functions)A-implied-boundsArea: Implied bounds / inferred outlives-boundsArea: Implied bounds / inferred outlives-boundsC-bugCategory: This is a bug.Category: This is a bug.I-unsoundIssue: A soundness hole (worst kind of bug), see: https://en.wikipedia.org/wiki/SoundnessIssue: A soundness hole (worst kind of bug), see: https://en.wikipedia.org/wiki/SoundnessP-highHigh priorityHigh priorityT-typesRelevant to the types team, which will review and decide on the PR/issue.Relevant to the types team, which will review and decide on the PR/issue.
Description
Activity
- addedC-bugCategory: This is a bug.Category: This is a bug.I-unsoundIssue: A soundness hole (worst kind of bug), see: https://en.wikipedia.org/wiki/SoundnessIssue: A soundness hole (worst kind of bug), see: https://en.wikipedia.org/wiki/SoundnessI-types-nominatedNominated for discussion during a types team meeting.Nominated for discussion during a types team meeting.T-typesRelevant to the types team, which will review and decide on the PR/issue.Relevant to the types team, which will review and decide on the PR/issue.
on Jun 26, 2022 - addedI-prioritizeIssue needs a team member to assess the impact. Will be replaced by P-{low,medium,high,critical}Issue needs a team member to assess the impact. Will be replaced by P-{low,medium,high,critical}
on Jun 26, 2022 - addedA-associated-itemsArea: Associated items (types, constants & functions)Area: Associated items (types, constants & functions)A-implied-boundsArea: Implied bounds / inferred outlives-boundsArea: Implied bounds / inferred outlives-bounds
on Jun 26, 2022 Unlike #91068, these code examples compile “successfully” all the way since Rust 1.7.0.
WG-prioritization assigning priority (Zulip discussion).
@rustbot label -I-prioritize +P-high
- addedP-highHigh priorityHigh priorityand removedI-prioritizeIssue needs a team member to assess the impact. Will be replaced by P-{low,medium,high,critical}Issue needs a team member to assess the impact. Will be replaced by P-{low,medium,high,critical}
on Jun 27, 2022 while this currently does not work, we should also add a test for something like this. If we get stronger implied bounds, simply requiring the caller to prove wf for all projection components won't be enough anymore
#![feature(generic_associated_types)] trait Trait<'a> { type Type where Self: 'a; } impl<'a, T> Trait<'a> for T { type Type = () where Self: 'a; // once this bound gets implied, we have UB again } fn f<'a, 'b>(s: &'b str, _: <&'b () as Trait<'a>>::Type) -> &'a str where &'b (): Trait<'a>, // <- adding this bound is the change from #91068 { s } fn main() { let x = String::from("Hello World!"); let y = f(&x, ()); drop(x); println!("{}", y); }
trait Trait<'a>: 'a { type Type; } impl<'a, T> Trait<'a> for T where T: 'a // if this bound get's implied we would probably get ub here again { type Type = (); } fn f<'a, 'b>(s: &'b str, _: <&'b () as Trait<'a>>::Type) -> &'a str where &'b (): Trait<'a>, // <- adding this bound is the change from #91068 { s } fn main() { let x = String::from("Hello World!"); let y = f(&x, ()); drop(x); println!("{}", y); }
There's a PR open that fixes this.
- removedI-types-nominatedNominated for discussion during a types team meeting.Nominated for discussion during a types team meeting.
on Jul 29, 2022 - added a commit that references this issue
on Aug 9, 2022 fixed by #99217
Metadata
Metadata
Assignees
Labels
A-associated-itemsArea: Associated items (types, constants & functions)Area: Associated items (types, constants & functions)A-implied-boundsArea: Implied bounds / inferred outlives-boundsArea: Implied bounds / inferred outlives-boundsC-bugCategory: This is a bug.Category: This is a bug.I-unsoundIssue: A soundness hole (worst kind of bug), see: https://en.wikipedia.org/wiki/SoundnessIssue: A soundness hole (worst kind of bug), see: https://en.wikipedia.org/wiki/SoundnessP-highHigh priorityHigh priorityT-typesRelevant to the types team, which will review and decide on the PR/issue.Relevant to the types team, which will review and decide on the PR/issue.
revives #91068 which has been fixed by only considering implied bounds from projections if they don't normalize while typechecking the function itself
rust/compiler/rustc_borrowck/src/type_check/free_region_relations.rs
Lines 256 to 289 in 7125846
This does not mean that the projection won't normalize when getting called:
The added bound prevents
<&'a &'b () as Trait>::Typefrom getting normalized while borrowcheckingf, as we prefer param candidates over impl candidates. When callingf, we don't have the&'a &'b (): Traitin ourparam_env, so we can now freely use the impl candidate to normalize the projection. The caller therefore doesn't have to prove that&'a &'b ()is well formed, causing unsoundness.I am a bit surprised that the caller doesn't have to prove that the
&'a &'b (): Traitobligation is well formed, which would cause this example to not be unsound. It doesn't remove the general unsoundness here though. Here's an alternative test where that isn't enough: