Skip to content

UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy - #157658

Merged
rust-bors[bot] merged 4 commits into
rust-lang:mainfrom
RalfJung:unsafe-cell-docs
Jun 12, 2026
Merged

UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy#157658
rust-bors[bot] merged 4 commits into
rust-lang:mainfrom
RalfJung:unsafe-cell-docs

Conversation

@RalfJung

@RalfJungRalfJung commented Jun 9, 2026

Copy link
Copy Markdown
Member

Addresses parts of #157544.

The second commit fixes a slight inaccuracy in the aliasing model section.

@kpreid I hope I interpreted your feedback correctly, and this would be helpful?

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-libs Relevant to the library team, which will review and decide on the PR/issue. labels Jun 9, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @joboet

rustbot has assigned @joboet.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: libs
  • libs expanded to 10 candidates
  • Random selection from LawnGnome, Mark-Simulacrum, clarfonthey, jhpratt, joboet

/// to an `&T`, then the data in `T` must remain immutable (modulo any `UnsafeCell` data found
/// within `T`, of course) until that reference's lifetime expires. Similarly, if you create a
/// `&mut T` reference that is released to safe code, then you must not access the data within the
/// `&mut T` reference, then you must not access the data within the

@RalfJungRalfJungJun 9, 2026

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The existing docs seemed to imply that if you don't release the &mut to safe code, the rules don't apply. That's incorrect, these rules always apply.

View changes since the review

@RalfJungRalfJung changed the title UnsafeCell: mention shared-ref-to-interior case in type-level docsUnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuractJun 9, 2026
@RalfJungRalfJung changed the title UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuractUnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracyJun 9, 2026

@kpreidkpreid left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kpreid I hope I interpreted your feedback correctly, and this would be helpful?

Yes, this is a significant improvement.

View changes since this review

Comment threadlibrary/core/src/cell.rs Outdated
Co-authored-by: Kevin Reid <kpreid@switchb.org>

@joboetjoboet left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍
r=me with the nits addressed.

View changes since this review

Comment threadlibrary/core/src/cell.rs Outdated
/// This can be cast to a pointer of any kind. When creating references, you must uphold the
/// aliasing rules; see [the type-level docs][UnsafeCell#aliasing-rules] for more discussion and
/// caveats.
/// This can be cast to a pointer of any kind. When creating (shared or mutable) references, you

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd remove the parentheses, for me they just add unnecessary nesting.

Suggested change
/// This can be cast to a pointer of any kind. When creating (shared or mutable) references, you
/// This can be cast to a pointer of any kind. When creating shared or mutable references, you

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was deliberate. We could arguably just say "when creating references" since the kind of reference does not matter -- the parenthetical just clarifies that yes we mean both kinds of references.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mmmh, fair enough...

Comment threadlibrary/core/src/cell.rs
@joboet

Copy link
Copy Markdown
Member

@bors r+ rollup

@rust-bors

rust-borsBot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

📌 Commit c40fe47 has been approved by joboet

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Jun 11, 2026
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Jun 11, 2026
UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy
Addresses parts of rust-lang#157544.
The second commit fixes a slight inaccuracy in the aliasing model section.
@kpreid I hope I interpreted your feedback correctly, and this would be helpful?
rust-borsBot pushed a commit that referenced this pull request Jun 11, 2026
…uwer
Rollup of 23 pull requests
Successful merges:
- #157716 (update Enzyme, June'26)
- #149793 (Add inline asm support for amdgpu)
- #152852 (Remove driver_lint_caps)
- #155299 (make repr_transparent_non_zst_fields a hard error)
- #155439 (Enable Cargo's new build-dir layout)
- #157612 (Add a test where subtyping inhibits coercion.)
- #157626 (Autogenerate unstable compiler flag stubs for unstable-book)
- #157667 (Rename typing modes to better describe real usage)
- #156212 (Additionally gate negative bounds behind new `-Zinternal-testing-features`)
- #157342 (Reduce verbosity of cycle errors when possible)
- #157366 (Add a regression test for an unconstrained TransmuteFrom ICE)
- #157459 (rustc_target: callconv: powerpc64: Remove unreachable fallback code path)
- #157658 (UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy)
- #157698 (Remove an unnecessary cloning)
- #157699 (Arg splat experiment - hir FnDecl impl)
- #157713 (resolve: Remove exported imports from `maybe_unused_trait_imports`)
- #157722 (Move create_scope_map to rustc_codegen_ssa.)
- #157725 (Keep generic suggestion for macro-expanded missing-type items)
- #157733 (Remove old FIXMEs about nocapture attribute)
- #157737 (Reorganize `tests/ui/issues` [7/N])
- #157746 (supports_c_variadic_definitions: extend checklist for new targets)
- #157763 (Move unused target expression error to appropriate place and rename it)
- #157768 (codegen_ssa: peel trans. wrappers on scalable vecs)
rust-borsBot pushed a commit that referenced this pull request Jun 11, 2026
…uwer
Rollup of 23 pull requests
Successful merges:
- #157716 (update Enzyme, June'26)
- #149793 (Add inline asm support for amdgpu)
- #152852 (Remove driver_lint_caps)
- #155299 (make repr_transparent_non_zst_fields a hard error)
- #155439 (Enable Cargo's new build-dir layout)
- #157612 (Add a test where subtyping inhibits coercion.)
- #157626 (Autogenerate unstable compiler flag stubs for unstable-book)
- #157667 (Rename typing modes to better describe real usage)
- #156212 (Additionally gate negative bounds behind new `-Zinternal-testing-features`)
- #157342 (Reduce verbosity of cycle errors when possible)
- #157366 (Add a regression test for an unconstrained TransmuteFrom ICE)
- #157459 (rustc_target: callconv: powerpc64: Remove unreachable fallback code path)
- #157658 (UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy)
- #157698 (Remove an unnecessary cloning)
- #157699 (Arg splat experiment - hir FnDecl impl)
- #157713 (resolve: Remove exported imports from `maybe_unused_trait_imports`)
- #157722 (Move create_scope_map to rustc_codegen_ssa.)
- #157725 (Keep generic suggestion for macro-expanded missing-type items)
- #157733 (Remove old FIXMEs about nocapture attribute)
- #157737 (Reorganize `tests/ui/issues` [7/N])
- #157746 (supports_c_variadic_definitions: extend checklist for new targets)
- #157763 (Move unused target expression error to appropriate place and rename it)
- #157768 (codegen_ssa: peel trans. wrappers on scalable vecs)
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Jun 11, 2026
UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy
Addresses parts of rust-lang#157544.
The second commit fixes a slight inaccuracy in the aliasing model section.
@kpreid I hope I interpreted your feedback correctly, and this would be helpful?
rust-borsBot pushed a commit that referenced this pull request Jun 11, 2026
…uwer
Rollup of 23 pull requests
Successful merges:
- #157716 (update Enzyme, June'26)
- #149793 (Add inline asm support for amdgpu)
- #155299 (make repr_transparent_non_zst_fields a hard error)
- #155439 (Enable Cargo's new build-dir layout)
- #157612 (Add a test where subtyping inhibits coercion.)
- #157626 (Autogenerate unstable compiler flag stubs for unstable-book)
- #157667 (Rename typing modes to better describe real usage)
- #149749 (Make `BorrowedBuf` and `BorrowedCursor` generic over the data)
- #156212 (Additionally gate negative bounds behind new `-Zinternal-testing-features`)
- #157342 (Reduce verbosity of cycle errors when possible)
- #157366 (Add a regression test for an unconstrained TransmuteFrom ICE)
- #157459 (rustc_target: callconv: powerpc64: Remove unreachable fallback code path)
- #157658 (UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy)
- #157698 (Remove an unnecessary cloning)
- #157699 (Arg splat experiment - hir FnDecl impl)
- #157713 (resolve: Remove exported imports from `maybe_unused_trait_imports`)
- #157722 (Move create_scope_map to rustc_codegen_ssa.)
- #157725 (Keep generic suggestion for macro-expanded missing-type items)
- #157733 (Remove old FIXMEs about nocapture attribute)
- #157737 (Reorganize `tests/ui/issues` [7/N])
- #157746 (supports_c_variadic_definitions: extend checklist for new targets)
- #157763 (Move unused target expression error to appropriate place and rename it)
- #157768 (codegen_ssa: peel trans. wrappers on scalable vecs)
@jhprattjhpratt mentioned this pull request Jun 12, 2026
rust-borsBot pushed a commit that referenced this pull request Jun 12, 2026
Rollup of 24 pull requests
Successful merges:
- #157716 (update Enzyme, June'26)
- #149793 (Add inline asm support for amdgpu)
- #155299 (make repr_transparent_non_zst_fields a hard error)
- #157612 (Add a test where subtyping inhibits coercion.)
- #157626 (Autogenerate unstable compiler flag stubs for unstable-book)
- #157667 (Rename typing modes to better describe real usage)
- #149749 (Make `BorrowedBuf` and `BorrowedCursor` generic over the data)
- #155113 (Ensure Send/Sync impl for std::process::CommandArgs)
- #156212 (Additionally gate negative bounds behind new `-Zinternal-testing-features`)
- #157342 (Reduce verbosity of cycle errors when possible)
- #157366 (Add a regression test for an unconstrained TransmuteFrom ICE)
- #157459 (rustc_target: callconv: powerpc64: Remove unreachable fallback code path)
- #157658 (UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy)
- #157698 (Remove an unnecessary cloning)
- #157699 (Arg splat experiment - hir FnDecl impl)
- #157713 (resolve: Remove exported imports from `maybe_unused_trait_imports`)
- #157722 (Move create_scope_map to rustc_codegen_ssa.)
- #157723 (Move uninhabited unreachable code lint to rustc_mir_transform)
- #157725 (Keep generic suggestion for macro-expanded missing-type items)
- #157733 (Remove old FIXMEs about nocapture attribute)
- #157737 (Reorganize `tests/ui/issues` [7/N])
- #157746 (supports_c_variadic_definitions: extend checklist for new targets)
- #157763 (Move unused target expression error to appropriate place and rename it)
- #157768 (codegen_ssa: peel trans. wrappers on scalable vecs)
@rust-bors
rust-borsBot merged commit abe85f4 into rust-lang:mainJun 12, 2026
12 checks passed
@rustbotrustbot added this to the 1.98.0 milestone Jun 12, 2026
rust-timer added a commit that referenced this pull request Jun 12, 2026
Rollup merge of #157658 - RalfJung:unsafe-cell-docs, r=joboet
UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy
Addresses parts of #157544.
The second commit fixes a slight inaccuracy in the aliasing model section.
@kpreid I hope I interpreted your feedback correctly, and this would be helpful?
pullBot pushed a commit to xtqqczze/rust-lang-miri that referenced this pull request Jun 13, 2026
Rollup of 24 pull requests
Successful merges:
- rust-lang/rust#157716 (update Enzyme, June'26)
- rust-lang/rust#149793 (Add inline asm support for amdgpu)
- rust-lang/rust#155299 (make repr_transparent_non_zst_fields a hard error)
- rust-lang/rust#157612 (Add a test where subtyping inhibits coercion.)
- rust-lang/rust#157626 (Autogenerate unstable compiler flag stubs for unstable-book)
- rust-lang/rust#157667 (Rename typing modes to better describe real usage)
- rust-lang/rust#149749 (Make `BorrowedBuf` and `BorrowedCursor` generic over the data)
- rust-lang/rust#155113 (Ensure Send/Sync impl for std::process::CommandArgs)
- rust-lang/rust#156212 (Additionally gate negative bounds behind new `-Zinternal-testing-features`)
- rust-lang/rust#157342 (Reduce verbosity of cycle errors when possible)
- rust-lang/rust#157366 (Add a regression test for an unconstrained TransmuteFrom ICE)
- rust-lang/rust#157459 (rustc_target: callconv: powerpc64: Remove unreachable fallback code path)
- rust-lang/rust#157658 (UnsafeCell: mention shared-ref-to-interior case, fix aliasing model inaccuracy)
- rust-lang/rust#157698 (Remove an unnecessary cloning)
- rust-lang/rust#157699 (Arg splat experiment - hir FnDecl impl)
- rust-lang/rust#157713 (resolve: Remove exported imports from `maybe_unused_trait_imports`)
- rust-lang/rust#157722 (Move create_scope_map to rustc_codegen_ssa.)
- rust-lang/rust#157723 (Move uninhabited unreachable code lint to rustc_mir_transform)
- rust-lang/rust#157725 (Keep generic suggestion for macro-expanded missing-type items)
- rust-lang/rust#157733 (Remove old FIXMEs about nocapture attribute)
- rust-lang/rust#157737 (Reorganize `tests/ui/issues` [7/N])
- rust-lang/rust#157746 (supports_c_variadic_definitions: extend checklist for new targets)
- rust-lang/rust#157763 (Move unused target expression error to appropriate place and rename it)
- rust-lang/rust#157768 (codegen_ssa: peel trans. wrappers on scalable vecs)
@RalfJung
RalfJung deleted the unsafe-cell-docs branch June 21, 2026 18:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-libsRelevant to the library team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@RalfJung@rustbot@joboet@kpreid