Skip to main content

rustc_mir_transform/
known_panics_lint.rs

1//! A lint that checks for known panics like overflows, division by zero,
2//! out-of-bound access etc. Uses const propagation to determine the values of
3//! operands during checks.
4
5use std::fmt::Debug;
6
7use rustc_abi::{BackendRepr, FieldIdx, HasDataLayout, Size, TargetDataLayout, VariantIdx};
8use rustc_const_eval::const_eval::DummyMachine;
9use rustc_const_eval::interpret::{ImmTy, InterpCx, InterpResult, Projectable, Scalar, interp_ok};
10use rustc_data_structures::fx::FxHashSet;
11use rustc_hir::def::DefKind;
12use rustc_hir::{HirId, find_attr};
13use rustc_index::IndexVec;
14use rustc_index::bit_set::DenseBitSet;
15use rustc_lint_defs::builtin::UNCONDITIONAL_PANIC;
16use rustc_middle::mir::visit::{MutatingUseContext, NonMutatingUseContext, PlaceContext, Visitor};
17use rustc_middle::mir::*;
18use rustc_middle::ty::layout::{LayoutError, LayoutOf, LayoutOfHelpers, TyAndLayout};
19use rustc_middle::ty::{
20    self, ConstInt, GenericArgKind, GenericParamDefKind, ScalarInt, Ty, TyCtxt, TypeVisitableExt,
21    Unnormalized,
22};
23use rustc_span::{Span, bug};
24use tracing::{debug, instrument, trace};
25
26use crate::diagnostics::{AssertLint, AssertLintKind, ConstNIsZero};
27
28pub(super) struct KnownPanicsLint;
29
30impl<'tcx> crate::MirLint<'tcx> for KnownPanicsLint {
31    fn run_lint(&self, tcx: TyCtxt<'tcx>, body: &Body<'tcx>) {
32        if body.tainted_by_errors.is_some() {
33            return;
34        }
35
36        let def_id = body.source.def_id().expect_local();
37        let def_kind = tcx.def_kind(def_id);
38        let is_fn_like = def_kind.is_fn_like();
39        let is_assoc_const = def_kind == DefKind::AssocConst;
40
41        // Only run const prop on functions, methods, closures and associated constants
42        if !is_fn_like && !is_assoc_const {
43            // skip anon_const/statics/consts because they'll be evaluated by miri anyway
44            trace!("KnownPanicsLint skipped for {:?}", def_id);
45            return;
46        }
47
48        // FIXME(welseywiser) const prop doesn't work on coroutines because of query cycles
49        // computing their layout.
50        if tcx.is_coroutine(def_id.to_def_id()) {
51            trace!("KnownPanicsLint skipped for coroutine {:?}", def_id);
52            return;
53        }
54
55        trace!("KnownPanicsLint starting for {:?}", def_id);
56
57        let mut linter = ConstPropagator::new(body, tcx);
58        linter.visit_body(body);
59
60        trace!("KnownPanicsLint done for {:?}", def_id);
61    }
62}
63
64/// Visits MIR nodes, performs const propagation
65/// and runs lint checks as it goes
66struct ConstPropagator<'mir, 'tcx> {
67    ecx: InterpCx<'tcx, DummyMachine>,
68    tcx: TyCtxt<'tcx>,
69    typing_env: ty::TypingEnv<'tcx>,
70    worklist: Vec<BasicBlock>,
71    visited_blocks: DenseBitSet<BasicBlock>,
72    locals: IndexVec<Local, Value<'tcx>>,
73    body: &'mir Body<'tcx>,
74    written_only_inside_own_block_locals: FxHashSet<Local>,
75    can_const_prop: IndexVec<Local, ConstPropMode>,
76}
77
78#[derive(Debug, Clone)]
79enum Value<'tcx> {
80    Immediate(ImmTy<'tcx>),
81    Aggregate { variant: VariantIdx, fields: IndexVec<FieldIdx, Value<'tcx>> },
82    Uninit,
83}
84
85impl<'tcx> From<ImmTy<'tcx>> for Value<'tcx> {
86    fn from(v: ImmTy<'tcx>) -> Self {
87        Self::Immediate(v)
88    }
89}
90
91impl<'tcx> Value<'tcx> {
92    fn project(
93        &self,
94        proj: &[PlaceElem<'tcx>],
95        prop: &ConstPropagator<'_, 'tcx>,
96    ) -> Option<&Value<'tcx>> {
97        let mut this = self;
98        for proj in proj {
99            this = match (*proj, this) {
100                (PlaceElem::Field(idx, _), Value::Aggregate { fields, .. }) => {
101                    fields.get(idx).unwrap_or(&Value::Uninit)
102                }
103                (PlaceElem::Index(idx), Value::Aggregate { fields, .. }) => {
104                    let idx = prop.get_const(idx.into())?.immediate()?;
105                    let idx = prop.ecx.read_target_usize(idx).discard_err()?.try_into().ok()?;
106                    if idx <= FieldIdx::MAX_AS_U32 {
107                        fields.get(FieldIdx::from_u32(idx)).unwrap_or(&Value::Uninit)
108                    } else {
109                        return None;
110                    }
111                }
112                (
113                    PlaceElem::ConstantIndex { offset, min_length: _, from_end: false },
114                    Value::Aggregate { fields, .. },
115                ) => fields
116                    .get(FieldIdx::from_u32(offset.try_into().ok()?))
117                    .unwrap_or(&Value::Uninit),
118                _ => return None,
119            };
120        }
121        Some(this)
122    }
123
124    fn project_mut(&mut self, proj: &[PlaceElem<'_>]) -> Option<&mut Value<'tcx>> {
125        let mut this = self;
126        for proj in proj {
127            this = match (proj, this) {
128                (PlaceElem::Field(idx, _), Value::Aggregate { fields, .. }) => {
129                    fields.ensure_contains_elem(*idx, || Value::Uninit)
130                }
131                (PlaceElem::Field(..), val @ Value::Uninit) => {
132                    *val =
133                        Value::Aggregate { variant: VariantIdx::ZERO, fields: Default::default() };
134                    val.project_mut(&[*proj])?
135                }
136                _ => return None,
137            };
138        }
139        Some(this)
140    }
141
142    fn immediate(&self) -> Option<&ImmTy<'tcx>> {
143        match self {
144            Value::Immediate(op) => Some(op),
145            _ => None,
146        }
147    }
148}
149
150impl<'tcx> LayoutOfHelpers<'tcx> for ConstPropagator<'_, 'tcx> {
151    type LayoutOfResult = Result<TyAndLayout<'tcx>, LayoutError<'tcx>>;
152
153    #[inline]
154    fn handle_layout_err(&self, err: LayoutError<'tcx>, _: Span, _: Ty<'tcx>) -> LayoutError<'tcx> {
155        err
156    }
157}
158
159impl HasDataLayout for ConstPropagator<'_, '_> {
160    #[inline]
161    fn data_layout(&self) -> &TargetDataLayout {
162        &self.tcx.data_layout
163    }
164}
165
166impl<'tcx> ty::layout::HasTyCtxt<'tcx> for ConstPropagator<'_, 'tcx> {
167    #[inline]
168    fn tcx(&self) -> TyCtxt<'tcx> {
169        self.tcx
170    }
171}
172
173impl<'tcx> ty::layout::HasTypingEnv<'tcx> for ConstPropagator<'_, 'tcx> {
174    #[inline]
175    fn typing_env(&self) -> ty::TypingEnv<'tcx> {
176        self.typing_env
177    }
178}
179
180impl<'mir, 'tcx> ConstPropagator<'mir, 'tcx> {
181    fn new(body: &'mir Body<'tcx>, tcx: TyCtxt<'tcx>) -> ConstPropagator<'mir, 'tcx> {
182        let def_id = body.source.def_id();
183        // FIXME(#132279): This is used during the phase transition from analysis
184        // to runtime, so we have to manually specify the correct typing mode.
185        let typing_env = ty::TypingEnv::post_analysis(tcx, body.source.def_id());
186        let can_const_prop = CanConstProp::check(tcx, typing_env, body);
187        let ecx = InterpCx::new(tcx, tcx.def_span(def_id), typing_env, DummyMachine);
188
189        ConstPropagator {
190            ecx,
191            tcx,
192            typing_env,
193            worklist: vec![START_BLOCK],
194            visited_blocks: DenseBitSet::new_empty(body.basic_blocks.len()),
195            locals: IndexVec::from_elem_n(Value::Uninit, body.local_decls.len()),
196            body,
197            can_const_prop,
198            written_only_inside_own_block_locals: Default::default(),
199        }
200    }
201
202    fn local_decls(&self) -> &'mir LocalDecls<'tcx> {
203        &self.body.local_decls
204    }
205
206    fn get_const(&self, place: Place<'tcx>) -> Option<&Value<'tcx>> {
207        self.locals[place.local].project(&place.projection, self)
208    }
209
210    /// Remove `local` from the pool of `Locals`. Allows writing to them,
211    /// but not reading from them anymore.
212    fn remove_const(&mut self, local: Local) {
213        self.locals[local] = Value::Uninit;
214        self.written_only_inside_own_block_locals.remove(&local);
215    }
216
217    fn access_mut(&mut self, place: &Place<'_>) -> Option<&mut Value<'tcx>> {
218        match self.can_const_prop[place.local] {
219            ConstPropMode::NoPropagation => return None,
220            ConstPropMode::OnlyInsideOwnBlock => {
221                self.written_only_inside_own_block_locals.insert(place.local);
222            }
223            ConstPropMode::FullConstProp => {}
224        }
225        self.locals[place.local].project_mut(place.projection)
226    }
227
228    fn lint_root(&self, source_info: SourceInfo) -> Option<HirId> {
229        source_info.scope.lint_root(&self.body.source_scopes)
230    }
231
232    fn use_ecx<F, T>(&mut self, f: F) -> Option<T>
233    where
234        F: FnOnce(&mut Self) -> InterpResult<'tcx, T>,
235    {
236        f(self)
237            .inspect_err_info(|err| {
238                trace!("InterpCx operation failed: {:?}", err);
239                // Some errors shouldn't come up because creating them causes
240                // an allocation, which we should avoid. When that happens,
241                // dedicated error variants should be introduced instead.
242                assert!(
243                    !err.kind().formatted_string(),
244                    "known panics lint encountered formatting error: {}",
245                    err.to_string(),
246                );
247            })
248            .discard_err()
249    }
250
251    /// Returns the value, if any, of evaluating `c`.
252    fn eval_constant(&mut self, c: &ConstOperand<'tcx>) -> Option<ImmTy<'tcx>> {
253        // FIXME we need to revisit this for #67176
254        if c.has_param() {
255            return None;
256        }
257
258        // Normalization needed b/c known panics lint runs in
259        // `mir_drops_elaborated_and_const_checked`, which happens before
260        // optimized MIR. Only after optimizing the MIR can we guarantee
261        // that the `PostAnalysisNormalize` pass has happened and that the body's consts
262        // are normalized, so any call to resolve before that needs to be
263        // manually normalized.
264        let val = self
265            .tcx
266            .try_normalize_erasing_regions(self.typing_env, Unnormalized::new_wip(c.const_))
267            .ok()?;
268
269        self.use_ecx(|this| this.ecx.eval_mir_constant(&val, c.span, None))?
270            .as_mplace_or_imm()
271            .right()
272    }
273
274    /// Returns the value, if any, of evaluating `place`.
275    #[instrument(level = "trace", skip(self), ret)]
276    fn eval_place(&mut self, place: Place<'tcx>) -> Option<ImmTy<'tcx>> {
277        match self.get_const(place)? {
278            Value::Immediate(imm) => Some(imm.clone()),
279            Value::Aggregate { .. } => None,
280            Value::Uninit => None,
281        }
282    }
283
284    /// Returns the value, if any, of evaluating `op`. Calls upon `eval_constant`
285    /// or `eval_place`, depending on the variant of `Operand` used.
286    fn eval_operand(&mut self, op: &Operand<'tcx>) -> Option<ImmTy<'tcx>> {
287        match *op {
288            Operand::RuntimeChecks(_) => None,
289            Operand::Constant(ref c) => self.eval_constant(c),
290            Operand::Move(place) | Operand::Copy(place) => self.eval_place(place),
291        }
292    }
293
294    fn report_assert_as_lint(
295        &self,
296        location: Location,
297        lint_kind: AssertLintKind,
298        assert_kind: AssertKind<impl Debug>,
299    ) {
300        let source_info = self.body.source_info(location);
301        if let Some(lint_root) = self.lint_root(*source_info) {
302            let span = source_info.span;
303            self.tcx.emit_node_span_lint(
304                lint_kind.lint(),
305                lint_root,
306                span,
307                AssertLint { span, assert_kind, lint_kind },
308            );
309        }
310    }
311
312    fn check_unary_op(&mut self, op: UnOp, arg: &Operand<'tcx>, location: Location) -> Option<()> {
313        let arg = self.eval_operand(arg)?;
314        // The only operator that can overflow is `Neg`.
315        if op == UnOp::Neg && arg.layout.ty.is_integral() {
316            // Compute this as `0 - arg` so we can use `SubWithOverflow` to check for overflow.
317            let (arg, overflow) = self.use_ecx(|this| {
318                let arg = this.ecx.read_immediate(&arg)?;
319                let (_res, overflow) = this
320                    .ecx
321                    .binary_op(BinOp::SubWithOverflow, &ImmTy::from_int(0, arg.layout), &arg)?
322                    .to_scalar_pair();
323                interp_ok((arg, overflow.to_bool()?))
324            })?;
325            if overflow {
326                self.report_assert_as_lint(
327                    location,
328                    AssertLintKind::ArithmeticOverflow,
329                    AssertKind::OverflowNeg(arg.to_const_int()),
330                );
331                return None;
332            }
333        }
334
335        Some(())
336    }
337
338    fn check_binary_op(
339        &mut self,
340        op: BinOp,
341        left: &Operand<'tcx>,
342        right: &Operand<'tcx>,
343        location: Location,
344    ) -> Option<()> {
345        let r =
346            self.eval_operand(right).and_then(|r| self.use_ecx(|this| this.ecx.read_immediate(&r)));
347        let l =
348            self.eval_operand(left).and_then(|l| self.use_ecx(|this| this.ecx.read_immediate(&l)));
349        // Check for exceeding shifts *even if* we cannot evaluate the LHS.
350        if matches!(op, BinOp::Shr | BinOp::Shl) {
351            let r = r.clone()?;
352            // We need the type of the LHS. We cannot use `place_layout` as that is the type
353            // of the result, which for checked binops is not the same!
354            let left_ty = left.ty(self.local_decls(), self.tcx);
355            let left_size = self.ecx.layout_of(left_ty).ok()?.size;
356            let right_size = r.layout.size;
357            let r_bits = r.to_scalar().to_bits(right_size).discard_err();
358            if r_bits.is_some_and(|b| b >= left_size.bits() as u128) {
359                debug!("check_binary_op: reporting assert for {:?}", location);
360                let panic = AssertKind::Overflow(
361                    op,
362                    // Invent a dummy value, the diagnostic ignores it anyway
363                    ConstInt::new(
364                        ScalarInt::try_from_uint(1_u8, left_size).unwrap(),
365                        left_ty.is_signed(),
366                        left_ty.is_ptr_sized_integral(),
367                    ),
368                    r.to_const_int(),
369                );
370                self.report_assert_as_lint(location, AssertLintKind::ArithmeticOverflow, panic);
371                return None;
372            }
373        }
374
375        // Div/Rem are handled via the assertions they trigger.
376        // But for Add/Sub/Mul, those assertions only exist in debug builds, and we want to
377        // lint in release builds as well, so we check on the operation instead.
378        // So normalize to the "overflowing" operator, and then ensure that it
379        // actually is an overflowing operator.
380        let op = op.wrapping_to_overflowing().unwrap_or(op);
381        // The remaining operators are handled through `wrapping_to_overflowing`.
382        if let (Some(l), Some(r)) = (l, r)
383            && l.layout.ty.is_integral()
384            && op.is_overflowing()
385            && self.use_ecx(|this| {
386                let (_res, overflow) = this.ecx.binary_op(op, &l, &r)?.to_scalar_pair();
387                overflow.to_bool()
388            })?
389        {
390            self.report_assert_as_lint(
391                location,
392                AssertLintKind::ArithmeticOverflow,
393                AssertKind::Overflow(op, l.to_const_int(), r.to_const_int()),
394            );
395            return None;
396        }
397
398        Some(())
399    }
400
401    fn check_rvalue(&mut self, rvalue: &Rvalue<'tcx>, location: Location) -> Option<()> {
402        // Perform any special handling for specific Rvalue types.
403        // Generally, checks here fall into one of two categories:
404        //   1. Additional checking to provide useful lints to the user
405        //        - In this case, we will do some validation and then fall through to the
406        //          end of the function which evals the assignment.
407        //   2. Working around bugs in other parts of the compiler
408        //        - In this case, we'll return `None` from this function to stop evaluation.
409        match rvalue {
410            // Additional checking: give lints to the user if an overflow would occur.
411            // We do this here and not in the `Assert` terminator as that terminator is
412            // only sometimes emitted (overflow checks can be disabled), but we want to always
413            // lint.
414            Rvalue::UnaryOp(op, arg) => {
415                trace!("checking UnaryOp(op = {:?}, arg = {:?})", op, arg);
416                self.check_unary_op(*op, arg, location)?;
417            }
418            Rvalue::BinaryOp(op, (left, right)) => {
419                trace!("checking BinaryOp(op = {:?}, left = {:?}, right = {:?})", op, left, right);
420                self.check_binary_op(*op, left, right, location)?;
421            }
422
423            // Do not try creating references (#67862)
424            Rvalue::RawPtr(_, place) | Rvalue::Ref(_, _, place) | Rvalue::Reborrow(_, _, place) => {
425                trace!("skipping RawPtr | Ref | Reborrow for {:?}", place);
426
427                // This may be creating mutable references or immutable references to cells.
428                // If that happens, the pointed to value could be mutated via that reference.
429                // Since we aren't tracking references, the const propagator loses track of what
430                // value the local has right now.
431                // Thus, all locals that have their reference taken
432                // must not take part in propagation.
433                self.remove_const(place.local);
434
435                return None;
436            }
437            Rvalue::ThreadLocalRef(def_id) => {
438                trace!("skipping ThreadLocalRef({:?})", def_id);
439
440                return None;
441            }
442
443            // There's no other checking to do at this time.
444            Rvalue::Aggregate(..)
445            | Rvalue::Use(..)
446            | Rvalue::CopyForDeref(..)
447            | Rvalue::Repeat(..)
448            | Rvalue::Cast(..)
449            | Rvalue::Discriminant(..)
450            | Rvalue::WrapUnsafeBinder(..) => {}
451        }
452
453        // FIXME we need to revisit this for #67176
454        if rvalue.has_param() {
455            return None;
456        }
457        if !rvalue.ty(self.local_decls(), self.tcx).is_sized(self.tcx, self.typing_env) {
458            // the interpreter doesn't support unsized locals (only unsized arguments),
459            // but rustc does (in a kinda broken way), so we have to skip them here
460            return None;
461        }
462
463        Some(())
464    }
465
466    fn check_assertion(
467        &mut self,
468        expected: bool,
469        msg: &AssertKind<Operand<'tcx>>,
470        cond: &Operand<'tcx>,
471        location: Location,
472    ) {
473        let Some(value) = &self.eval_operand(cond) else { return };
474        trace!("assertion on {:?} should be {:?}", value, expected);
475
476        let expected = Scalar::from_bool(expected);
477        let Some(value_const) = self.use_ecx(|this| this.ecx.read_scalar(value)) else { return };
478
479        if expected != value_const {
480            // Poison all places this operand references so that further code
481            // doesn't use the invalid value
482            if let Some(place) = cond.place() {
483                self.remove_const(place.local);
484            }
485
486            enum DbgVal<T> {
487                Val(T),
488                Underscore,
489            }
490            impl<T: std::fmt::Debug> std::fmt::Debug for DbgVal<T> {
491                fn fmt(&self, fmt: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
492                    match self {
493                        Self::Val(val) => val.fmt(fmt),
494                        Self::Underscore => fmt.write_str("_"),
495                    }
496                }
497            }
498            let mut eval_to_int = |op| {
499                // This can be `None` if the lhs wasn't const propagated and we just
500                // triggered the assert on the value of the rhs.
501                self.eval_operand(op)
502                    .and_then(|op| self.ecx.read_immediate(&op).discard_err())
503                    .map_or(DbgVal::Underscore, |op| DbgVal::Val(op.to_const_int()))
504            };
505            let msg = match msg {
506                AssertKind::DivisionByZero(op) => AssertKind::DivisionByZero(eval_to_int(op)),
507                AssertKind::RemainderByZero(op) => AssertKind::RemainderByZero(eval_to_int(op)),
508                AssertKind::Overflow(bin_op @ (BinOp::Div | BinOp::Rem), op1, op2) => {
509                    // Division overflow is *UB* in the MIR, and different than the
510                    // other overflow checks.
511                    AssertKind::Overflow(*bin_op, eval_to_int(op1), eval_to_int(op2))
512                }
513                AssertKind::BoundsCheck { len, index } => {
514                    let len = eval_to_int(len);
515                    let index = eval_to_int(index);
516                    AssertKind::BoundsCheck { len, index }
517                }
518                // Remaining overflow errors are already covered by checks on the binary operators.
519                AssertKind::Overflow(..) | AssertKind::OverflowNeg(_) => return,
520                // Need proper const propagator for these.
521                _ => return,
522            };
523            self.report_assert_as_lint(location, AssertLintKind::UnconditionalPanic, msg);
524        }
525    }
526
527    fn ensure_not_propagated(&self, local: Local) {
528        if cfg!(debug_assertions) {
529            let val = self.get_const(local.into());
530            assert!(
531                matches!(val, Some(Value::Uninit))
532                    || self
533                        .layout_of(self.local_decls()[local].ty)
534                        .map_or(true, |layout| layout.is_zst()),
535                "failed to remove values for `{local:?}`, value={val:?}",
536            )
537        }
538    }
539
540    #[instrument(level = "trace", skip(self), ret)]
541    fn eval_rvalue(&mut self, rvalue: &Rvalue<'tcx>, dest: &Place<'tcx>) -> Option<()> {
542        if !dest.projection.is_empty() {
543            return None;
544        }
545        use rustc_middle::mir::Rvalue::*;
546        let layout = self.ecx.layout_of(dest.ty(self.body, self.tcx).ty).ok()?;
547        trace!(?layout);
548
549        let val: Value<'_> = match *rvalue {
550            ThreadLocalRef(_) => return None,
551
552            Use(ref operand, _) | WrapUnsafeBinder(ref operand, _) => {
553                self.eval_operand(operand)?.into()
554            }
555
556            CopyForDeref(place) | Reborrow(_, _, place) => self.eval_place(place)?.into(),
557
558            BinaryOp(bin_op, (ref left, ref right)) => {
559                let left = self.eval_operand(left)?;
560                let left = self.use_ecx(|this| this.ecx.read_immediate(&left))?;
561
562                let right = self.eval_operand(right)?;
563                let right = self.use_ecx(|this| this.ecx.read_immediate(&right))?;
564
565                let val = self.use_ecx(|this| this.ecx.binary_op(bin_op, &left, &right))?;
566                if matches!(val.layout.backend_repr, BackendRepr::ScalarPair { .. }) {
567                    // FIXME `Value` should properly support pairs in `Immediate`... but currently
568                    // it does not.
569                    let (val, overflow) = val.to_pair(&self.ecx);
570                    Value::Aggregate {
571                        variant: VariantIdx::ZERO,
572                        fields: [val.into(), overflow.into()].into_iter().collect(),
573                    }
574                } else {
575                    val.into()
576                }
577            }
578
579            UnaryOp(un_op, ref operand) => {
580                let operand = self.eval_operand(operand)?;
581                let val = self.use_ecx(|this| this.ecx.read_immediate(&operand))?;
582
583                let val = self.use_ecx(|this| this.ecx.unary_op(un_op, &val))?;
584                val.into()
585            }
586
587            Aggregate(ref kind, ref fields) => Value::Aggregate {
588                fields: fields
589                    .iter()
590                    .map(|field| self.eval_operand(field).map_or(Value::Uninit, Value::Immediate))
591                    .collect(),
592                variant: match **kind {
593                    AggregateKind::Adt(_, variant, _, _, _) => variant,
594                    AggregateKind::Array(_)
595                    | AggregateKind::Tuple
596                    | AggregateKind::RawPtr(_, _)
597                    | AggregateKind::Closure(_, _)
598                    | AggregateKind::Coroutine(_, _)
599                    | AggregateKind::CoroutineClosure(_, _) => VariantIdx::ZERO,
600                },
601            },
602
603            Repeat(ref op, n) => {
604                trace!(?op, ?n);
605                return None;
606            }
607
608            Ref(..) | RawPtr(..) => return None,
609
610            Cast(ref kind, ref value, to) => match kind {
611                CastKind::IntToInt | CastKind::IntToFloat => {
612                    let value = self.eval_operand(value)?;
613                    let value = self.ecx.read_immediate(&value).discard_err()?;
614                    let to = self.ecx.layout_of(to).ok()?;
615                    let res = self.ecx.int_to_int_or_float(&value, to).discard_err()?;
616                    res.into()
617                }
618                CastKind::FloatToFloat | CastKind::FloatToInt => {
619                    let value = self.eval_operand(value)?;
620                    let value = self.ecx.read_immediate(&value).discard_err()?;
621                    let to = self.ecx.layout_of(to).ok()?;
622                    let res = self.ecx.float_to_float_or_int(&value, to).discard_err()?;
623                    res.into()
624                }
625                CastKind::Transmute | CastKind::Subtype => {
626                    let value = self.eval_operand(value)?;
627                    let to = self.ecx.layout_of(to).ok()?;
628                    // `offset` for immediates only supports scalar/scalar-pair ABIs,
629                    // so bail out if the target is not one.
630                    match (value.layout.backend_repr, to.backend_repr) {
631                        (BackendRepr::Scalar(..), BackendRepr::Scalar(..)) => {}
632                        (BackendRepr::ScalarPair { .. }, BackendRepr::ScalarPair { .. }) => {}
633                        _ => return None,
634                    }
635
636                    value.offset(Size::ZERO, to, &self.ecx).discard_err()?.into()
637                }
638                _ => return None,
639            },
640
641            Discriminant(place) => {
642                let variant = match self.get_const(place)? {
643                    Value::Immediate(op) => {
644                        let op = op.clone();
645                        self.use_ecx(|this| this.ecx.read_discriminant(&op))?
646                    }
647                    Value::Aggregate { variant, .. } => *variant,
648                    Value::Uninit => return None,
649                };
650                let imm = self.use_ecx(|this| {
651                    this.ecx.discriminant_for_variant(
652                        place.ty(this.local_decls(), this.tcx).ty,
653                        variant,
654                    )
655                })?;
656                imm.into()
657            }
658        };
659        trace!(?val);
660
661        *self.access_mut(dest)? = val;
662
663        Some(())
664    }
665}
666
667impl<'tcx> Visitor<'tcx> for ConstPropagator<'_, 'tcx> {
668    fn visit_body(&mut self, body: &Body<'tcx>) {
669        while let Some(bb) = self.worklist.pop() {
670            if !self.visited_blocks.insert(bb) {
671                continue;
672            }
673
674            let data = &body.basic_blocks[bb];
675            self.visit_basic_block_data(bb, data);
676        }
677    }
678
679    fn visit_operand(&mut self, operand: &Operand<'tcx>, location: Location) {
680        self.super_operand(operand, location);
681    }
682
683    fn visit_const_operand(&mut self, constant: &ConstOperand<'tcx>, location: Location) {
684        trace!("visit_const_operand: {:?}", constant);
685        self.super_const_operand(constant, location);
686        self.eval_constant(constant);
687    }
688
689    fn visit_assign(&mut self, place: &Place<'tcx>, rvalue: &Rvalue<'tcx>, location: Location) {
690        self.super_assign(place, rvalue, location);
691
692        let Some(()) = self.check_rvalue(rvalue, location) else { return };
693
694        match self.can_const_prop[place.local] {
695            // Do nothing if the place is indirect.
696            _ if place.is_indirect() => {}
697            ConstPropMode::NoPropagation => self.ensure_not_propagated(place.local),
698            ConstPropMode::OnlyInsideOwnBlock | ConstPropMode::FullConstProp => {
699                if self.eval_rvalue(rvalue, place).is_none() {
700                    // Const prop failed, so erase the destination, ensuring that whatever happens
701                    // from here on, does not know about the previous value.
702                    // This is important in case we have
703                    // ```rust
704                    // let mut x = 42;
705                    // x = SOME_MUTABLE_STATIC;
706                    // // x must now be uninit
707                    // ```
708                    // FIXME: we overzealously erase the entire local, because that's easier to
709                    // implement.
710                    trace!(
711                        "propagation into {:?} failed.
712                        Nuking the entire site from orbit, it's the only way to be sure",
713                        place,
714                    );
715                    self.remove_const(place.local);
716                }
717            }
718        }
719    }
720
721    fn visit_statement(&mut self, statement: &Statement<'tcx>, location: Location) {
722        trace!("visit_statement: {:?}", statement);
723
724        // We want to evaluate operands before any change to the assigned-to value,
725        // so we recurse first.
726        self.super_statement(statement, location);
727
728        match statement.kind {
729            StatementKind::SetDiscriminant { ref place, variant_index } => {
730                match self.can_const_prop[place.local] {
731                    // Do nothing if the place is indirect.
732                    _ if place.is_indirect() => {}
733                    ConstPropMode::NoPropagation => self.ensure_not_propagated(place.local),
734                    ConstPropMode::FullConstProp | ConstPropMode::OnlyInsideOwnBlock => {
735                        match self.access_mut(place) {
736                            Some(Value::Aggregate { variant, .. }) => *variant = variant_index,
737                            _ => self.remove_const(place.local),
738                        }
739                    }
740                }
741            }
742            StatementKind::StorageLive(local) => {
743                self.remove_const(local);
744            }
745            StatementKind::StorageDead(local) => {
746                self.remove_const(local);
747            }
748            _ => {}
749        }
750    }
751
752    fn visit_terminator(&mut self, terminator: &Terminator<'tcx>, location: Location) {
753        self.super_terminator(terminator, location);
754        match &terminator.kind {
755            TerminatorKind::Assert { expected, msg, cond, .. } => {
756                self.check_assertion(*expected, msg, cond, location);
757            }
758            TerminatorKind::SwitchInt { discr, targets } => {
759                if let Some(ref value) = self.eval_operand(discr)
760                    && let Some(value_const) = self.use_ecx(|this| this.ecx.read_scalar(value))
761                    && let Some(constant) = value_const.to_bits(value_const.size()).discard_err()
762                {
763                    // We managed to evaluate the discriminant, so we know we only need to visit
764                    // one target.
765                    let target = targets.target_for_value(constant);
766                    self.worklist.push(target);
767                    return;
768                }
769                // We failed to evaluate the discriminant, fallback to visiting all successors.
770            }
771            TerminatorKind::Call { func, args: _, .. } => {
772                if let Some((def_id, generic_args)) = func.const_fn_def() {
773                    for (index, arg) in generic_args.iter().enumerate() {
774                        if let GenericArgKind::Const(ct) = arg.kind() {
775                            let generics = self.tcx.generics_of(def_id);
776                            let param_def = generics.param_at(index, self.tcx);
777
778                            if let GenericParamDefKind::Const { .. } = param_def.kind
779                                && find_attr!(self.tcx, param_def.def_id, RustcPanicsWhenZero)
780                                && let Some(0) = ct.try_to_target_usize(self.tcx)
781                            {
782                                // We managed to figure-out that the value of a
783                                // `#[rustc_panics_when_zero]` const-generic parameter is zero.
784                                //
785                                // Let's report it as an unconditional panic.
786                                let source_info = self.body.source_info(location);
787                                if let Some(lint_root) = self.lint_root(*source_info) {
788                                    self.tcx.emit_node_span_lint(
789                                        UNCONDITIONAL_PANIC,
790                                        lint_root,
791                                        source_info.span,
792                                        ConstNIsZero {
793                                            const_param_span: source_info.span,
794                                            const_param_name: param_def.name,
795                                        },
796                                    );
797                                }
798                            }
799                        }
800                    }
801                }
802            }
803            // None of these have Operands to const-propagate.
804            TerminatorKind::Goto { .. }
805            | TerminatorKind::UnwindResume
806            | TerminatorKind::UnwindTerminate(_)
807            | TerminatorKind::Return
808            | TerminatorKind::TailCall { .. }
809            | TerminatorKind::Unreachable
810            | TerminatorKind::Drop { .. }
811            | TerminatorKind::Yield { .. }
812            | TerminatorKind::CoroutineDrop
813            | TerminatorKind::FalseEdge { .. }
814            | TerminatorKind::FalseUnwind { .. }
815            | TerminatorKind::InlineAsm { .. } => {}
816        }
817
818        self.worklist.extend(terminator.successors());
819    }
820
821    fn visit_basic_block_data(&mut self, block: BasicBlock, data: &BasicBlockData<'tcx>) {
822        self.super_basic_block_data(block, data);
823
824        // We remove all Locals which are restricted in propagation to their containing blocks and
825        // which were modified in the current block.
826        // Take it out of the ecx so we can get a mutable reference to the ecx for `remove_const`.
827        let mut written_only_inside_own_block_locals =
828            std::mem::take(&mut self.written_only_inside_own_block_locals);
829
830        // This loop can get very hot for some bodies: it check each local in each bb.
831        // To avoid this quadratic behaviour, we only clear the locals that were modified inside
832        // the current block.
833        // The order in which we remove consts does not matter.
834        #[allow(rustc::potential_query_instability)]
835        for local in written_only_inside_own_block_locals.drain() {
836            debug_assert_eq!(self.can_const_prop[local], ConstPropMode::OnlyInsideOwnBlock);
837            self.remove_const(local);
838        }
839        self.written_only_inside_own_block_locals = written_only_inside_own_block_locals;
840
841        if cfg!(debug_assertions) {
842            for (local, &mode) in self.can_const_prop.iter_enumerated() {
843                match mode {
844                    ConstPropMode::FullConstProp => {}
845                    ConstPropMode::NoPropagation | ConstPropMode::OnlyInsideOwnBlock => {
846                        self.ensure_not_propagated(local);
847                    }
848                }
849            }
850        }
851    }
852}
853
854/// The maximum number of bytes that we'll allocate space for a local or the return value.
855/// Needed for #66397, because otherwise we eval into large places and that can cause OOM or just
856/// Severely regress performance.
857const MAX_ALLOC_LIMIT: u64 = 1024;
858
859/// The mode that `ConstProp` is allowed to run in for a given `Local`.
860#[derive(Clone, Copy, Debug, PartialEq)]
861enum ConstPropMode {
862    /// The `Local` can be propagated into and reads of this `Local` can also be propagated.
863    FullConstProp,
864    /// The `Local` can only be propagated into and from its own block.
865    OnlyInsideOwnBlock,
866    /// The `Local` cannot be part of propagation at all. Any statement
867    /// referencing it either for reading or writing will not get propagated.
868    NoPropagation,
869}
870
871/// A visitor that determines locals in a MIR body
872/// that can be const propagated
873struct CanConstProp {
874    can_const_prop: IndexVec<Local, ConstPropMode>,
875    // False at the beginning. Once set, no more assignments are allowed to that local.
876    found_assignment: DenseBitSet<Local>,
877}
878
879impl CanConstProp {
880    /// Returns true if `local` can be propagated
881    fn check<'tcx>(
882        tcx: TyCtxt<'tcx>,
883        typing_env: ty::TypingEnv<'tcx>,
884        body: &Body<'tcx>,
885    ) -> IndexVec<Local, ConstPropMode> {
886        let mut cpv = CanConstProp {
887            can_const_prop: IndexVec::from_elem(ConstPropMode::FullConstProp, &body.local_decls),
888            found_assignment: DenseBitSet::new_empty(body.local_decls.len()),
889        };
890        for (local, val) in cpv.can_const_prop.iter_enumerated_mut() {
891            let ty = body.local_decls[local].ty;
892            if ty.is_async_drop_in_place_coroutine(tcx) {
893                // No const propagation for async drop coroutine (AsyncDropGlue).
894                // Otherwise, tcx.layout_of(typing_env.as_query_input(ty)) will be called
895                // (early layout request for async drop coroutine) to calculate layout size.
896                // Layout for `async_drop_in_place<T>::{closure}` may only be known with known T.
897                *val = ConstPropMode::NoPropagation;
898                continue;
899            } else if ty.is_union() {
900                // Unions are incompatible with the current implementation of
901                // const prop because Rust has no concept of an active
902                // variant of a union
903                *val = ConstPropMode::NoPropagation;
904            } else {
905                match tcx.layout_of(typing_env.as_query_input(ty)) {
906                    Ok(layout) if layout.size < Size::from_bytes(MAX_ALLOC_LIMIT) => {}
907                    // Either the layout fails to compute, then we can't use this local anyway
908                    // or the local is too large, then we don't want to.
909                    _ => {
910                        *val = ConstPropMode::NoPropagation;
911                        continue;
912                    }
913                }
914            }
915        }
916        // Consider that arguments are assigned on entry.
917        for arg in body.args_iter() {
918            cpv.found_assignment.insert(arg);
919        }
920        cpv.visit_body(body);
921        cpv.can_const_prop
922    }
923}
924
925impl<'tcx> Visitor<'tcx> for CanConstProp {
926    fn visit_place(&mut self, place: &Place<'tcx>, mut context: PlaceContext, loc: Location) {
927        use rustc_middle::mir::visit::PlaceContext::*;
928
929        // Dereferencing just read the address of `place.local`.
930        if place.projection.first() == Some(&PlaceElem::Deref) {
931            context = NonMutatingUse(NonMutatingUseContext::Copy);
932        }
933
934        self.visit_local(place.local, context, loc);
935        self.visit_projection(place.as_ref(), context, loc);
936    }
937
938    fn visit_local(&mut self, local: Local, context: PlaceContext, _: Location) {
939        use rustc_middle::mir::visit::PlaceContext::*;
940        match context {
941            // These are just stores, where the storing is not propagatable, but there may be later
942            // mutations of the same local via `Store`
943            | MutatingUse(MutatingUseContext::Call)
944            | MutatingUse(MutatingUseContext::AsmOutput)
945            // Actual store that can possibly even propagate a value
946            | MutatingUse(MutatingUseContext::Store)
947            | MutatingUse(MutatingUseContext::SetDiscriminant) => {
948                if !self.found_assignment.insert(local) {
949                    match &mut self.can_const_prop[local] {
950                        // If the local can only get propagated in its own block, then we don't have
951                        // to worry about multiple assignments, as we'll nuke the const state at the
952                        // end of the block anyway, and inside the block we overwrite previous
953                        // states as applicable.
954                        ConstPropMode::OnlyInsideOwnBlock => {}
955                        ConstPropMode::NoPropagation => {}
956                        other @ ConstPropMode::FullConstProp => {
957                            trace!(
958                                "local {:?} can't be propagated because of multiple assignments. Previous state: {:?}",
959                                local, other,
960                            );
961                            *other = ConstPropMode::OnlyInsideOwnBlock;
962                        }
963                    }
964                }
965            }
966            // Reading constants is allowed an arbitrary number of times
967            NonMutatingUse(NonMutatingUseContext::Copy)
968            | NonMutatingUse(NonMutatingUseContext::Move)
969            | NonMutatingUse(NonMutatingUseContext::Inspect)
970            | NonMutatingUse(NonMutatingUseContext::PlaceMention)
971            | NonUse(_) => {}
972
973            // These could be propagated with a smarter analysis or just some careful thinking about
974            // whether they'd be fine right now.
975            MutatingUse(MutatingUseContext::Yield)
976            | MutatingUse(MutatingUseContext::Drop)
977            // These can't ever be propagated under any scheme, as we can't reason about indirect
978            // mutation.
979            | NonMutatingUse(NonMutatingUseContext::SharedBorrow)
980            | NonMutatingUse(NonMutatingUseContext::FakeBorrow)
981            | NonMutatingUse(NonMutatingUseContext::RawBorrow)
982            | MutatingUse(MutatingUseContext::Borrow)
983            | MutatingUse(MutatingUseContext::RawBorrow) => {
984                trace!("local {:?} can't be propagated because it's used: {:?}", local, context);
985                self.can_const_prop[local] = ConstPropMode::NoPropagation;
986            }
987            MutatingUse(MutatingUseContext::Projection)
988            | NonMutatingUse(NonMutatingUseContext::Projection) => {
989                bug!("visit_place should not pass {context:?} for {local:?}")
990            }
991        }
992    }
993}