Skip to content

Treat pointer and Box locals of function items as ordinary variables - #4892

Open
srivatsansamraj wants to merge 1 commit into
model-checking:mainfrom
srivatsansamraj:fn-item-pointer-locals
Open

srivatsansamraj wants to merge 1 commit into
model-checking:mainfrom
srivatsansamraj:fn-item-pointer-locals

Conversation

@srivatsansamraj

Copy link
Copy Markdown
Contributor

codegen_local_fndef replaced a local whose type is a raw pointer to a function item, or a Box of one, with a fixed expression: &f::FnDefSingleton, or a Box literal around it. That is only right for the function item itself, which is zero-sized, so all its values are the same. A pointer holds whatever was assigned to it. The substitution caused three failures:

This keeps only the FnDef arm, so pointer and Box locals of function items are ordinary variables, and deletes box_value, whose only caller was the Box arm.

The new test FunctionSymbols/fn_item_address.rs covers the #2255 program, the value of a pointer to a function item, and a should_panic harness that fails if a null one reads as non-null. DynTrait/boxed_fn_item.rs drops --only-codegen and now verifies. The programs from #4857 and #1257 verify, and variants with a wrong expected value fail. Calls through Box<dyn Fn>, Box<dyn FnMut> and Box<dyn FnOnce> of a function item, and reads and calls through a dangling pointer to one, verify. The kani and expected suites pass, apart from two Quantifiers tests that fail the same way on main on this machine.

This replaces #4860.

Resolves #2255
Resolves #4857
Resolves #1257

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 and MIT licenses.

codegen_local_fndef replaced a local of type *const FnDef, *mut FnDef or
Box<FnDef> with &f::FnDefSingleton, or a Box literal around it. A pointer
holds whatever was assigned to it, so reads ignored the stored value,
writes assigned to a non-lvalue (model-checking#4857, model-checking#1257), and naming the singleton
needed a function symbol that reachability had not declared (model-checking#2255).

Keep only the FnDef arm, which is zero-sized, and delete box_value, whose
only caller was the Box arm.
@srivatsansamraj
srivatsansamraj requested review from a team as code owners September 28, 2026 00:22
@srivatsansamraj

Copy link
Copy Markdown
Contributor Author

@CYJ904 @Tianshu-Huang @wodex1nhaoIeng @acearyanarun for review.

In Kani, a function item (foo used as a value) is zero-sized, so Kani stands one global object in for it. Kani did the same for a pointer to a function item and for a Box of one: instead of a real variable, it used a fixed "address of foo". A pointer can hold any address, including null, so that shortcut was wrong. It caused a crash when printing &foo with {:p} (#2255), a CBMC error when writing to such a pointer (#4857, #1257), and, with our earlier fix #4860, a wrong result: a null pointer read as non-null.

This PR removes the shortcut for pointers and boxes, so they are ordinary variables.

@github-actions github-actions Bot added Z-EndToEndBenchCI Tag a PR to run benchmark CI Z-CompilerBenchCI Tag a PR to run benchmark CI labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Z-CompilerBenchCI Tag a PR to run benchmark CI Z-EndToEndBenchCI Tag a PR to run benchmark CI

Projects

None yet

1 participant