Remove Copy supertrait from VaList - #160221
Conversation
|
r? @clarfonthey rustbot has assigned @clarfonthey. Use Why was this reviewer chosen?The reviewer was selected based on:
|
|
r? me r=me if CI passes |
|
@bors delegate+ |
|
✌️ @Jules-Bertholet, you can now approve this pull request! If @nia-e told you to " |
| /// - If `T` is not [`Copy`], then it must not have already been read using `next_arg` | ||
| /// on a [`clone`][VaList::clone]d copy of this `VaList`. | ||
| /// (Currently, all types implementing [`VaArgSafe`] also implement [`Copy`], | ||
| /// but this may change in the future.) |
There was a problem hiding this comment.
Miri has been enforcing the other conditions, does it already catch this?
Cc @rust-lang/miri
There was a problem hiding this comment.
I wouldn't expect Miri to directly enforce this, as it is library UB and not language UB. Similar to ptr::reading a valid instance of an arbitrary type
There was a problem hiding this comment.
Good point, the UB would probably manifest upon drop and be caught.
There was a problem hiding this comment.
This cannot be triggered because VaArgSafe is only implemented for Copy types currently.
I personally have little appetite for opening that up much further. There are some obscure numeric types that we will likely add in time (f16, f128, x87 f80, ppc f128, Complex<T>, bf16), but portability for some of those is already not great (e.g. clang and gcc diverge), and for anything beyond that I just don't think it is needed.
(I'm fine with this change though, if we believe this is a better way to handle it)
There was a problem hiding this comment.
My personal preference would be the exact opposite, have impl<T> VaArgSafe for T {} and rely on lints to flag incorrect usage instead. But that is a discussion for another day
There was a problem hiding this comment.
i think cutting the user-visible behaviour is good, so i concur fully with removing the copy bound esp if it's a change we can undo if needed in the future & makes the stabilised api surface smaller. i would certainly raise more eyebrows at a blanket impl of the likes suggested but that's offtopic ^^
|
@bors r+ rollup |
…uwer Rollup of 25 pull requests Successful merges: - #160204 (Sync from portable simd 2026 07 30) - #138230 (Add `raw_borrows_via_references` lint) - #158057 (Don't escape U+FF9E and U+FF9F in `escape_debug_ext`) - #160015 (refactor(mir-transform): Merge `can_be_overridden`, `is_required` and `is_enabled` into one) - #160031 (std: make positioned I/O unsupported on VxWorks) - #160125 (Fix typing mode handling in transmute checks and rustc_dump_layout) - #160152 (Create on-demand CI job for testing EC2 instances) - #160232 (rustdoc: fix ICE when a grapheme cluster joins a Prepend-class character to `_` or `:`) - #159214 (std: improve the documentation of the random feature) - #159818 (Resolve vars before calling `unnormalized_obligations`) - #159955 (Stop using higher-order macros to declare arenas) - #159958 (Fix avoid cycle for self referential return type notation) - #160040 (Split function parsing out of `item.rs` to a new module.) - #160044 (Add regression tests for fixed dead-code issues) - #160144 (renovate: group lockfiles PRs) - #160149 (Fix Windows on Arm PAC default) - #160164 (Derive `GenericTypeVisitable` for `RegionConstraint`) - #160175 (Try to recover less from incorrectly parsed const arg) - #160177 (A few more "predicate"-to-"clause" renamings) - #160181 (Mark `Tuple` and `FnPtr` traits `#[fundamental]`) - #160192 (Fix ICE for parsing issue with a closing brace) - #160209 (bootstrap: Remove method `Subcommand::kind`) - #160221 (Remove `Copy` supertrait from `VaList`) - #160223 (interpret: rename validate_operand → validate_place) - #160234 (Always use short ty path for call with missing arguments suggestion)
…uwer Rollup of 25 pull requests Successful merges: - #160204 (Sync from portable simd 2026 07 30) - #138230 (Add `raw_borrows_via_references` lint) - #158057 (Don't escape U+FF9E and U+FF9F in `escape_debug_ext`) - #160015 (refactor(mir-transform): Merge `can_be_overridden`, `is_required` and `is_enabled` into one) - #160031 (std: make positioned I/O unsupported on VxWorks) - #160125 (Fix typing mode handling in transmute checks and rustc_dump_layout) - #160152 (Create on-demand CI job for testing EC2 instances) - #160232 (rustdoc: fix ICE when a grapheme cluster joins a Prepend-class character to `_` or `:`) - #159214 (std: improve the documentation of the random feature) - #159818 (Resolve vars before calling `unnormalized_obligations`) - #159955 (Stop using higher-order macros to declare arenas) - #159958 (Fix avoid cycle for self referential return type notation) - #160040 (Split function parsing out of `item.rs` to a new module.) - #160044 (Add regression tests for fixed dead-code issues) - #160144 (renovate: group lockfiles PRs) - #160149 (Fix Windows on Arm PAC default) - #160164 (Derive `GenericTypeVisitable` for `RegionConstraint`) - #160175 (Try to recover less from incorrectly parsed const arg) - #160177 (A few more "predicate"-to-"clause" renamings) - #160181 (Mark `Tuple` and `FnPtr` traits `#[fundamental]`) - #160192 (Fix ICE for parsing issue with a closing brace) - #160209 (bootstrap: Remove method `Subcommand::kind`) - #160221 (Remove `Copy` supertrait from `VaList`) - #160223 (interpret: rename validate_operand → validate_place) - #160234 (Always use short ty path for call with missing arguments suggestion)
Rollup merge of #160221 - Jules-Bertholet:valist-noncopy, r=nia-e Remove `Copy` supertrait from `VaList` … And adjust `next_arg`'s safety comment accordingly. This leaves us more flexibility for the future. Zulip discussion: https://rust-lang.zulipchat.com/#narrow/channel/219381-t-libs/topic/.60.3A.20Copy.60.20bound.20on.20.60VaArgSafe.60 @rustbot label T-libs-api
…uwer Rollup of 25 pull requests Successful merges: - rust-lang/rust#160204 (Sync from portable simd 2026 07 30) - rust-lang/rust#138230 (Add `raw_borrows_via_references` lint) - rust-lang/rust#158057 (Don't escape U+FF9E and U+FF9F in `escape_debug_ext`) - rust-lang/rust#160015 (refactor(mir-transform): Merge `can_be_overridden`, `is_required` and `is_enabled` into one) - rust-lang/rust#160031 (std: make positioned I/O unsupported on VxWorks) - rust-lang/rust#160125 (Fix typing mode handling in transmute checks and rustc_dump_layout) - rust-lang/rust#160152 (Create on-demand CI job for testing EC2 instances) - rust-lang/rust#160232 (rustdoc: fix ICE when a grapheme cluster joins a Prepend-class character to `_` or `:`) - rust-lang/rust#159214 (std: improve the documentation of the random feature) - rust-lang/rust#159818 (Resolve vars before calling `unnormalized_obligations`) - rust-lang/rust#159955 (Stop using higher-order macros to declare arenas) - rust-lang/rust#159958 (Fix avoid cycle for self referential return type notation) - rust-lang/rust#160040 (Split function parsing out of `item.rs` to a new module.) - rust-lang/rust#160044 (Add regression tests for fixed dead-code issues) - rust-lang/rust#160144 (renovate: group lockfiles PRs) - rust-lang/rust#160149 (Fix Windows on Arm PAC default) - rust-lang/rust#160164 (Derive `GenericTypeVisitable` for `RegionConstraint`) - rust-lang/rust#160175 (Try to recover less from incorrectly parsed const arg) - rust-lang/rust#160177 (A few more "predicate"-to-"clause" renamings) - rust-lang/rust#160181 (Mark `Tuple` and `FnPtr` traits `#[fundamental]`) - rust-lang/rust#160192 (Fix ICE for parsing issue with a closing brace) - rust-lang/rust#160209 (bootstrap: Remove method `Subcommand::kind`) - rust-lang/rust#160221 (Remove `Copy` supertrait from `VaList`) - rust-lang/rust#160223 (interpret: rename validate_operand → validate_place) - rust-lang/rust#160234 (Always use short ty path for call with missing arguments suggestion)
… And adjust
next_arg's safety comment accordingly. This leaves us more flexibility for the future.Zulip discussion: https://rust-lang.zulipchat.com/#narrow/channel/219381-t-libs/topic/.60.3A.20Copy.60.20bound.20on.20.60VaArgSafe.60
@rustbot label T-libs-api