check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

check if len of array const arg matches the expected len of the type when lowering to valtree - #158587

Merged
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168
Aug 9, 2026
Merged

check if len of array const arg matches the expected len of the type when lowering to valtree#158587
rust-bors[bot] merged 1 commit into
rust-lang:mainfrom
sjwang05:issue-155168

Conversation

@sjwang05

@sjwang05sjwang05 commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

When creating valtrees for arrays passed as const args in lower_const_arg_array, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to lower_const_arg_tup.

fixes#155168

@rustbot

Copy link
Copy Markdown
Collaborator

HIR ty lowering was modified

cc @fmease

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Jun 29, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

r? @JohnTitor

rustbot has assigned @JohnTitor.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 73 candidates
  • Random selection from 17 candidates

@sjwang05sjwang05 changed the title check if len of array const arg matches the expected lencheck if len of array const arg matches the expected len of the type when lowering to valtreeJun 29, 2026
@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

.map(|elem| self.lower_const_arg(elem, *elem_ty))
.collect::<Vec<_>>();

if let Some(expected_len) = len.try_to_target_usize(tcx)

@JohnTitorJohnTitorJul 3, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should catch more cases if len is normalized, e.g. type const LEN (I haven't checked deeply so it may be caught by somewhere already)

View changes since the review

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, I changed it to call try_normalize_erasing_regions with an empty ParamEnv on the expected len and added a test for it, so now something like fn baz<const A: [u8; <S as Trait>::LEN]>() {} produces the correct error. Something like fn baz<T: Trait, const A: [u8; <T as Trait>::LEN]>() {} still ICEs if too long/produces UB if too short, however, since we can't resolve T to an actual type: trying to do try_evaluate_const with a non-empty ParamEnv led to cycle errors.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you open another issue and add an ICE test for that case (if not exists yet)? At least we should track it.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #160553 and added a corresponding test to the crashes/ dir

@JohnTitorJohnTitor added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
@rustbot

Copy link
Copy Markdown
Collaborator

This PR changes a file inside tests/crashes. If a crash was fixed, please move into the corresponding ui subdir and add 'Fixes #' to the PR description to autoclose the issue upon merge.

@rustbot

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

@rustbot ready

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Aug 5, 2026
@rust-log-analyzer

This comment has been minimized.

@sjwang05

Copy link
Copy Markdown
ContributorAuthor

Looks like -Copt-level=0 is needed for the crashtest, otherwise inlining followed by SimplifyLocals gets rid of the return value entirely.

...Neat!

@JohnTitorJohnTitor left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rust-bors

rust-borsBot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit d43f980 has been approved by JohnTitor

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 8, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 9, 2026
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (rust-lang#155168) or an ICE during CTFE (rust-lang#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixesrust-lang#155168
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 6 pull requests
Successful merges:
- #160529 (Upgrade and deduplicate dependencies)
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@jhprattjhpratt mentioned this pull request Aug 9, 2026
rust-borsBot pushed a commit that referenced this pull request Aug 9, 2026
Rollup of 5 pull requests
Successful merges:
- #158517 (Initial implementation of named `Fn` trait parameters)
- #158587 (check if len of array const arg matches the expected len of the type when lowering to valtree)
- #160748 (Add regression test for cross-crate assoc const private field leak in rustdoc)
- #160708 (remove old update mechanism)
- #160768 (Fix autodiff_illegal.rs test)
@rust-bors
rust-borsBot merged commit fec8cd5 into rust-lang:mainAug 9, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 9, 2026
rust-timer added a commit that referenced this pull request Aug 9, 2026
Rollup merge of #158587 - sjwang05:issue-155168, r=JohnTitor
check if len of array const arg matches the expected len of the type when lowering to valtree
When creating valtrees for arrays passed as const args in `lower_const_arg_array`, we assume the array has the correct length without actually checking the length of the arg, leading to UB at runtime (#155168) or an ICE during CTFE (#151079). This PR adds a check comparing the expected length of the type with the actual number of elements, similar to `lower_const_arg_tup`.
fixes#155168
@BoxyUwUBoxyUwU mentioned this pull request Aug 22, 2026
7 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-compilerRelevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

constructing invalid value of type [u8; 2]: at [0], encountered uninitialized memory, but expected an integer

4 participants

@sjwang05@rustbot@rust-log-analyzer@JohnTitor