2013-05-23 19:12:16 -07:00
|
|
|
// Copyright 2012-2013 The Rust Project Developers. See the COPYRIGHT
|
|
|
|
// file at the top-level directory of this distribution and at
|
|
|
|
// http://rust-lang.org/COPYRIGHT.
|
|
|
|
//
|
|
|
|
// Licensed under the Apache License, Version 2.0 <LICENSE-APACHE or
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0> or the MIT license
|
|
|
|
// <LICENSE-MIT or http://opensource.org/licenses/MIT>, at your
|
|
|
|
// option. This file may not be copied, modified, or distributed
|
|
|
|
// except according to those terms.
|
|
|
|
|
|
|
|
//! Enforces the Rust effect system. Currently there is just one effect,
|
2015-02-19 23:35:33 -06:00
|
|
|
//! `unsafe`.
|
2015-06-05 08:31:27 +02:00
|
|
|
use self::RootUnsafeContext::*;
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2014-05-14 15:31:30 -04:00
|
|
|
use middle::def;
|
2015-01-03 22:42:21 -05:00
|
|
|
use middle::ty::{self, Ty};
|
2014-11-25 14:21:20 -05:00
|
|
|
use middle::ty::MethodCall;
|
2013-05-23 19:12:16 -07:00
|
|
|
|
|
|
|
use syntax::ast;
|
2013-08-31 18:13:04 +02:00
|
|
|
use syntax::codemap::Span;
|
2015-07-31 00:04:06 -07:00
|
|
|
use rustc_front::hir;
|
2015-11-17 17:51:44 -05:00
|
|
|
use rustc_front::intravisit;
|
|
|
|
use rustc_front::intravisit::{FnKind, Visitor};
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2015-06-05 08:31:27 +02:00
|
|
|
#[derive(Copy, Clone)]
|
|
|
|
struct UnsafeContext {
|
|
|
|
push_unsafe_count: usize,
|
|
|
|
root: RootUnsafeContext,
|
|
|
|
}
|
|
|
|
|
|
|
|
impl UnsafeContext {
|
|
|
|
fn new(root: RootUnsafeContext) -> UnsafeContext {
|
|
|
|
UnsafeContext { root: root, push_unsafe_count: 0 }
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-30 09:38:44 -04:00
|
|
|
#[derive(Copy, Clone, PartialEq)]
|
2015-06-05 08:31:27 +02:00
|
|
|
enum RootUnsafeContext {
|
2013-05-23 19:12:16 -07:00
|
|
|
SafeContext,
|
|
|
|
UnsafeFn,
|
2013-07-27 10:25:59 +02:00
|
|
|
UnsafeBlock(ast::NodeId),
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|
|
|
|
|
2014-09-13 21:09:25 +03:00
|
|
|
fn type_is_unsafe_function(ty: Ty) -> bool {
|
2014-10-31 10:51:16 +02:00
|
|
|
match ty.sty {
|
2015-07-31 00:04:06 -07:00
|
|
|
ty::TyBareFn(_, ref f) => f.unsafety == hir::Unsafety::Unsafe,
|
2013-05-23 19:12:16 -07:00
|
|
|
_ => false,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-04-22 15:56:37 +03:00
|
|
|
struct EffectCheckVisitor<'a, 'tcx: 'a> {
|
|
|
|
tcx: &'a ty::ctxt<'tcx>,
|
2013-10-07 14:25:30 -07:00
|
|
|
|
|
|
|
/// Whether we're in an unsafe context.
|
|
|
|
unsafe_context: UnsafeContext,
|
2013-08-13 04:15:54 +02:00
|
|
|
}
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2014-04-22 15:56:37 +03:00
|
|
|
impl<'a, 'tcx> EffectCheckVisitor<'a, 'tcx> {
|
2013-08-31 18:13:04 +02:00
|
|
|
fn require_unsafe(&mut self, span: Span, description: &str) {
|
2015-06-05 08:31:27 +02:00
|
|
|
if self.unsafe_context.push_unsafe_count > 0 { return; }
|
|
|
|
match self.unsafe_context.root {
|
2013-05-23 19:12:16 -07:00
|
|
|
SafeContext => {
|
|
|
|
// Report an error.
|
2014-07-17 19:56:37 +02:00
|
|
|
span_err!(self.tcx.sess, span, E0133,
|
|
|
|
"{} requires unsafe function or block",
|
|
|
|
description);
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|
|
|
|
UnsafeBlock(block_id) => {
|
|
|
|
// OK, but record this.
|
2014-10-15 02:25:34 -04:00
|
|
|
debug!("effect: recording unsafe block as used: {}", block_id);
|
2014-03-20 19:49:20 -07:00
|
|
|
self.tcx.used_unsafe.borrow_mut().insert(block_id);
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|
|
|
|
UnsafeFn => {}
|
|
|
|
}
|
2013-08-13 04:15:54 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-09-10 01:54:36 +03:00
|
|
|
impl<'a, 'tcx, 'v> Visitor<'v> for EffectCheckVisitor<'a, 'tcx> {
|
2015-07-31 00:04:06 -07:00
|
|
|
fn visit_fn(&mut self, fn_kind: FnKind<'v>, fn_decl: &'v hir::FnDecl,
|
|
|
|
block: &'v hir::Block, span: Span, _: ast::NodeId) {
|
2013-10-07 14:25:30 -07:00
|
|
|
|
2014-09-10 01:54:36 +03:00
|
|
|
let (is_item_fn, is_unsafe_fn) = match fn_kind {
|
2015-08-26 12:00:14 +02:00
|
|
|
FnKind::ItemFn(_, _, unsafety, _, _, _) =>
|
2015-07-31 00:04:06 -07:00
|
|
|
(true, unsafety == hir::Unsafety::Unsafe),
|
2015-08-26 12:00:14 +02:00
|
|
|
FnKind::Method(_, sig, _) =>
|
2015-07-31 00:04:06 -07:00
|
|
|
(true, sig.unsafety == hir::Unsafety::Unsafe),
|
2013-10-07 14:25:30 -07:00
|
|
|
_ => (false, false),
|
|
|
|
};
|
|
|
|
|
|
|
|
let old_unsafe_context = self.unsafe_context;
|
|
|
|
if is_unsafe_fn {
|
2015-06-05 08:31:27 +02:00
|
|
|
self.unsafe_context = UnsafeContext::new(UnsafeFn)
|
2013-10-07 14:25:30 -07:00
|
|
|
} else if is_item_fn {
|
2015-06-05 08:31:27 +02:00
|
|
|
self.unsafe_context = UnsafeContext::new(SafeContext)
|
2013-10-07 14:25:30 -07:00
|
|
|
}
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2015-11-17 17:51:44 -05:00
|
|
|
intravisit::walk_fn(self, fn_kind, fn_decl, block, span);
|
2013-08-13 04:15:54 +02:00
|
|
|
|
2013-10-07 14:25:30 -07:00
|
|
|
self.unsafe_context = old_unsafe_context
|
2013-08-13 04:15:54 +02:00
|
|
|
}
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2015-07-31 00:04:06 -07:00
|
|
|
fn visit_block(&mut self, block: &hir::Block) {
|
2013-10-07 14:25:30 -07:00
|
|
|
let old_unsafe_context = self.unsafe_context;
|
2014-02-20 23:22:45 +11:00
|
|
|
match block.rules {
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::UnsafeBlock(source) => {
|
2014-02-20 23:22:45 +11:00
|
|
|
// By default only the outermost `unsafe` block is
|
|
|
|
// "used" and so nested unsafe blocks are pointless
|
|
|
|
// (the inner ones are unnecessary and we actually
|
|
|
|
// warn about them). As such, there are two cases when
|
|
|
|
// we need to create a new context, when we're
|
|
|
|
// - outside `unsafe` and found a `unsafe` block
|
|
|
|
// (normal case)
|
2014-08-23 12:41:32 +02:00
|
|
|
// - inside `unsafe`, found an `unsafe` block
|
2014-02-20 23:22:45 +11:00
|
|
|
// created internally to the compiler
|
|
|
|
//
|
|
|
|
// The second case is necessary to ensure that the
|
|
|
|
// compiler `unsafe` blocks don't accidentally "use"
|
|
|
|
// external blocks (e.g. `unsafe { println("") }`,
|
|
|
|
// expands to `unsafe { ... unsafe { ... } }` where
|
|
|
|
// the inner one is compiler generated).
|
2015-07-31 00:04:06 -07:00
|
|
|
if self.unsafe_context.root == SafeContext || source == hir::CompilerGenerated {
|
2015-06-05 08:31:27 +02:00
|
|
|
self.unsafe_context.root = UnsafeBlock(block.id)
|
2014-02-20 23:22:45 +11:00
|
|
|
}
|
|
|
|
}
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::PushUnsafeBlock(..) => {
|
2015-06-05 08:31:27 +02:00
|
|
|
self.unsafe_context.push_unsafe_count =
|
2015-07-23 16:20:59 +02:00
|
|
|
self.unsafe_context.push_unsafe_count.checked_add(1).unwrap();
|
2015-06-05 08:31:27 +02:00
|
|
|
}
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::PopUnsafeBlock(..) => {
|
2015-06-05 08:31:27 +02:00
|
|
|
self.unsafe_context.push_unsafe_count =
|
2015-07-23 16:20:59 +02:00
|
|
|
self.unsafe_context.push_unsafe_count.checked_sub(1).unwrap();
|
2015-06-05 08:31:27 +02:00
|
|
|
}
|
2015-09-29 13:46:01 +13:00
|
|
|
hir::DefaultBlock | hir::PushUnstableBlock | hir:: PopUnstableBlock => {}
|
2013-10-07 14:25:30 -07:00
|
|
|
}
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2015-11-17 17:51:44 -05:00
|
|
|
intravisit::walk_block(self, block);
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2013-10-07 14:25:30 -07:00
|
|
|
self.unsafe_context = old_unsafe_context
|
2013-08-13 04:15:54 +02:00
|
|
|
}
|
|
|
|
|
2015-07-31 00:04:06 -07:00
|
|
|
fn visit_expr(&mut self, expr: &hir::Expr) {
|
2013-10-07 14:25:30 -07:00
|
|
|
match expr.node {
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::ExprMethodCall(_, _, _) => {
|
2014-03-06 19:24:11 +02:00
|
|
|
let method_call = MethodCall::expr(expr.id);
|
2015-07-04 07:07:10 +03:00
|
|
|
let base_type = self.tcx.tables.borrow().method_map[&method_call].ty;
|
2015-06-18 20:25:05 +03:00
|
|
|
debug!("effect: method call case, base type is {:?}",
|
|
|
|
base_type);
|
2013-10-07 14:25:30 -07:00
|
|
|
if type_is_unsafe_function(base_type) {
|
|
|
|
self.require_unsafe(expr.span,
|
|
|
|
"invocation of unsafe method")
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|
2013-10-07 14:25:30 -07:00
|
|
|
}
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::ExprCall(ref base, _) => {
|
2015-10-01 16:06:50 +03:00
|
|
|
let base_type = self.tcx.expr_ty_adjusted(base);
|
2015-06-18 20:25:05 +03:00
|
|
|
debug!("effect: call case, base type is {:?}",
|
|
|
|
base_type);
|
2013-10-07 14:25:30 -07:00
|
|
|
if type_is_unsafe_function(base_type) {
|
|
|
|
self.require_unsafe(expr.span, "call to unsafe function")
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|
2013-10-07 14:25:30 -07:00
|
|
|
}
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::ExprUnary(hir::UnDeref, ref base) => {
|
2015-10-01 16:06:50 +03:00
|
|
|
let base_type = self.tcx.expr_ty_adjusted(base);
|
2015-06-18 20:25:05 +03:00
|
|
|
debug!("effect: unary case, base type is {:?}",
|
|
|
|
base_type);
|
2015-06-11 16:21:46 -07:00
|
|
|
if let ty::TyRawPtr(_) = base_type.sty {
|
2015-06-09 16:49:24 -04:00
|
|
|
self.require_unsafe(expr.span, "dereference of raw pointer")
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|
2013-10-07 14:25:30 -07:00
|
|
|
}
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::ExprInlineAsm(..) => {
|
2014-11-29 16:41:21 -05:00
|
|
|
self.require_unsafe(expr.span, "use of inline assembly");
|
2013-10-07 14:25:30 -07:00
|
|
|
}
|
2015-07-31 00:04:06 -07:00
|
|
|
hir::ExprPath(..) => {
|
2015-06-25 23:42:17 +03:00
|
|
|
if let def::DefStatic(_, true) = self.tcx.resolve_expr(expr) {
|
2014-11-29 16:41:21 -05:00
|
|
|
self.require_unsafe(expr.span, "use of mutable static");
|
2013-06-21 18:46:34 -07:00
|
|
|
}
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|
2013-10-07 14:25:30 -07:00
|
|
|
_ => {}
|
|
|
|
}
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2015-11-17 17:51:44 -05:00
|
|
|
intravisit::walk_expr(self, expr);
|
2013-08-13 04:15:54 +02:00
|
|
|
}
|
|
|
|
}
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2014-09-07 20:09:06 +03:00
|
|
|
pub fn check_crate(tcx: &ty::ctxt) {
|
2013-08-13 04:15:54 +02:00
|
|
|
let mut visitor = EffectCheckVisitor {
|
|
|
|
tcx: tcx,
|
2015-06-05 08:31:27 +02:00
|
|
|
unsafe_context: UnsafeContext::new(SafeContext),
|
2013-08-13 04:15:54 +02:00
|
|
|
};
|
2013-05-23 19:12:16 -07:00
|
|
|
|
2015-11-17 17:51:44 -05:00
|
|
|
tcx.map.krate().visit_all_items(&mut visitor);
|
2013-05-23 19:12:16 -07:00
|
|
|
}
|