Skip to content

allocations: document that they can be read-only - #159503

Merged
rust-bors[bot] merged 2 commits into
rust-lang:mainfrom
RalfJung:allocations
Aug 1, 2026
Merged

allocations: document that they can be read-only#159503
rust-bors[bot] merged 2 commits into
rust-lang:mainfrom
RalfJung:allocations

Conversation

@RalfJung

@RalfJungRalfJung commented Jul 18, 2026

Copy link
Copy Markdown
Member

View all comments

Miri currently tracks "read-only" as an explicit flag on allocations that exists independent of provenance. It essentially corresponds to a read-only mapping in the page table.

Let's make this officially part of our model.
Cc @rust-lang/lang @rust-lang/opsem

@rustbotrustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-libs Relevant to the library team, which will review and decide on the PR/issue. labels Jul 18, 2026
@rustbot

rustbot commented Jul 18, 2026

Copy link
Copy Markdown
Collaborator

r? @Mark-Simulacrum

rustbot has assigned @Mark-Simulacrum.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: libs
  • libs expanded to 12 candidates
  • Random selection from 6 candidates

@RalfJung

Copy link
Copy Markdown
MemberAuthor

@rfcbot merge opsem

@rust-rfcbot

rust-rfcbot commented Jul 18, 2026

Copy link
Copy Markdown
Collaborator

@RalfJung has proposed to merge this. The next step is review by the rest of the tagged team members:

No concerns currently listed.

Once a majority of reviewers approve (and at most 2 approvals are outstanding), this will enter its final comment period. If you spot a major issue that hasn't been raised at any point in this process, please speak up!

See this document for info about what commands tagged team members can give me.

@rust-rfcbotrust-rfcbot added proposed-final-comment-period Proposed to merge/close by relevant subteam, see T-<team> label. Will enter FCP once signed off. disposition-merge This issue / PR is in PFCP or FCP with a disposition to merge it. labels Jul 18, 2026

@Mark-SimulacrumMark-Simulacrum left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

r=me with FCP complete, unless you think there's something to be done about the comment

View changes since this review

Comment threadlibrary/core/src/ptr/mod.rs
@rust-rfcbotrust-rfcbot added final-comment-period In the final comment period and will be merged soon unless new substantive objections are raised. and removed proposed-final-comment-period Proposed to merge/close by relevant subteam, see T-<team> label. Will enter FCP once signed off. labels Jul 22, 2026
@rust-rfcbot

Copy link
Copy Markdown
Collaborator

🔔 This is now entering its final comment period, as per the review above. 🔔

@joshlf

Copy link
Copy Markdown
Contributor

Is there a reason we can't model this more simply as just only handing out read-only provenance pointers to these allocations without needing a separate notion of a read-only allocation?

Checking my box anyway – if there's a reason that a provenance-based approach isn't viable (or isn't genuinely simpler) then I'm happy to merge as-is.

@RalfJung

Copy link
Copy Markdown
MemberAuthor

Is there a reason we can't model this more simply as just only handing out read-only provenance pointers to these allocations without needing a separate notion of a read-only allocation?

I think with the restrictions we have on atomics, that does not work. Doing a load(Ordering::Acquire) with read-only provenance is entirely fine, but doing it on a read-only allocation is not.

@joshlf

Copy link
Copy Markdown
Contributor

Our docs on atomic accesses to read-only memory say:

In general, all atomic accesses on read-only memory are undefined behavior. For instance, attempting to do a compare_exchange that will definitely fail (making it conceptually a read-only operation) can still cause a segmentation fault if the underlying memory page is mapped read-only. Since atomic loads might be implemented using compare-exchange operations, even a load can fault on read-only memory.

IIUC, this is a platform-level detail, not an opsem thing? In other words, the fact that an atomic load is implemented using compare-exchange isn't visible to opsem, and thus, as you said:

Doing a load(Ordering::Acquire) with read-only provenance is entirely fine

...because opsem doesn't "know" that the underlying atomic load is implemented via compare-exchange?

@RalfJung

RalfJung commented Jul 22, 2026

Copy link
Copy Markdown
MemberAuthor

...because opsem doesn't "know" that the underlying atomic load is implemented via compare-exchange?

Correct. On the semantics / Abstract Machine level, a failing CAS and an atomic load are read-only operations, they don't change the contents of memory. (They do change some other state related to the concurrency memory model, but that's a separate question.)

In other words, this is sound, at least under Tree Borrows:

use std::sync::atomic::*;fnmain(){unsafe{let x = 0i32;let atomic_x = &*(&x as*consti32as*constAtomicI32);// atomic_x is derived from &x, so it has read-only provenance.
atomic_x.load(Ordering::SeqCst);}}

@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

Co-authored-by: Jacob Lifshay <programmerjake@gmail.com>
@Mark-SimulacrumMark-Simulacrum added the T-opsem Relevant to the opsem team label Jul 25, 2026
@Mark-Simulacrum

Copy link
Copy Markdown
Member

@bors r+ rollup

@rust-bors

rust-borsBot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

📋 This PR cannot be approved because it currently has the following label: final-comment-period.

@rust-rfcbotrust-rfcbot added finished-final-comment-period The final comment period is finished for this PR / Issue. to-announce Announce this issue on triage meeting and removed final-comment-period In the final comment period and will be merged soon unless new substantive objections are raised. labels Aug 1, 2026
@rust-rfcbot

Copy link
Copy Markdown
Collaborator

The final comment period, with a disposition to merge, as per the review above, is now complete.

As the automated representative of the governance process, I would like to thank the author for their work and everyone else who contributed.

@RalfJung

Copy link
Copy Markdown
MemberAuthor

@bors r=Mark-Simulacrum rollup

@rust-bors

rust-borsBot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

📌 Commit 2a8cada has been approved by Mark-Simulacrum

It is now in the queue for this repository.

@rust-borsrust-borsBot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. labels Aug 1, 2026
jhpratt added a commit to jhpratt/rust that referenced this pull request Aug 1, 2026
…acrum
allocations: document that they can be read-only
Miri currently tracks "read-only" as an explicit flag on allocations that exists independent of provenance. It essentially corresponds to a read-only mapping in the page table.
Let's make this officially part of our model.
Cc @rust-lang/lang @rust-lang/opsem
@jhprattjhpratt mentioned this pull request Aug 1, 2026
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Aug 1, 2026
…acrum
allocations: document that they can be read-only
Miri currently tracks "read-only" as an explicit flag on allocations that exists independent of provenance. It essentially corresponds to a read-only mapping in the page table.
Let's make this officially part of our model.
Cc @rust-lang/lang @rust-lang/opsem
rust-borsBot pushed a commit that referenced this pull request Aug 1, 2026
…uwer
Rollup of 10 pull requests
Successful merges:
- #157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
- #160012 (miri: ensure validity of references and pointers we dereference and cast)
- #160294 (Update Enzyme to resolve one of the open bugs)
- #159503 (allocations: document that they can be read-only)
- #160250 (When issuing suggestions for missing trait items, label unstable items)
- #160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
- #160311 (Remove final use of sealed traits from stdlib)
- #160313 (Make the noundef-on-Cast size guard explicit)
- #160323 (Box::leak: tell people to avoid unleaking)
- #160328 (Move `check_track_caller` into the attribute parser)
rust-borsBot pushed a commit that referenced this pull request Aug 1, 2026
…uwer
Rollup of 12 pull requests
Successful merges:
- #157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
- #160012 (miri: ensure validity of references and pointers we dereference and cast)
- #160294 (Update Enzyme to resolve one of the open bugs)
- #159503 (allocations: document that they can be read-only)
- #160179 (std: Update `wasip3` crate dependency)
- #160250 (When issuing suggestions for missing trait items, label unstable items)
- #160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
- #160311 (Remove final use of sealed traits from stdlib)
- #160313 (Make the noundef-on-Cast size guard explicit)
- #160323 (Box::leak: tell people to avoid unleaking)
- #160328 (Move `check_track_caller` into the attribute parser)
- #160333 (Remove itertools dependency from `rustc_ast_pretty`)
@rust-bors
rust-borsBot merged commit 6d27f59 into rust-lang:mainAug 1, 2026
13 checks passed
@rustbotrustbot added this to the 1.99.0 milestone Aug 1, 2026
pullBot pushed a commit to xtqqczze/rust-lang-miri that referenced this pull request Aug 2, 2026
…uwer
Rollup of 12 pull requests
Successful merges:
- rust-lang/rust#157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
- rust-lang/rust#160012 (miri: ensure validity of references and pointers we dereference and cast)
- rust-lang/rust#160294 (Update Enzyme to resolve one of the open bugs)
- rust-lang/rust#159503 (allocations: document that they can be read-only)
- rust-lang/rust#160179 (std: Update `wasip3` crate dependency)
- rust-lang/rust#160250 (When issuing suggestions for missing trait items, label unstable items)
- rust-lang/rust#160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
- rust-lang/rust#160311 (Remove final use of sealed traits from stdlib)
- rust-lang/rust#160313 (Make the noundef-on-Cast size guard explicit)
- rust-lang/rust#160323 (Box::leak: tell people to avoid unleaking)
- rust-lang/rust#160328 (Move `check_track_caller` into the attribute parser)
- rust-lang/rust#160333 (Remove itertools dependency from `rustc_ast_pretty`)
@RalfJung
RalfJung deleted the allocations branch August 2, 2026 16:46
flip1995 pushed a commit to flip1995/rust-clippy that referenced this pull request Aug 17, 2026
…uwer
Rollup of 12 pull requests
Successful merges:
- rust-lang/rust#157572 (stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw)
- rust-lang/rust#160012 (miri: ensure validity of references and pointers we dereference and cast)
- rust-lang/rust#160294 (Update Enzyme to resolve one of the open bugs)
- rust-lang/rust#159503 (allocations: document that they can be read-only)
- rust-lang/rust#160179 (std: Update `wasip3` crate dependency)
- rust-lang/rust#160250 (When issuing suggestions for missing trait items, label unstable items)
- rust-lang/rust#160251 (Replace unsafe usage of `NonNull::new_unchecked` with `Box::into_non_null`)
- rust-lang/rust#160311 (Remove final use of sealed traits from stdlib)
- rust-lang/rust#160313 (Make the noundef-on-Cast size guard explicit)
- rust-lang/rust#160323 (Box::leak: tell people to avoid unleaking)
- rust-lang/rust#160328 (Move `check_track_caller` into the attribute parser)
- rust-lang/rust#160333 (Remove itertools dependency from `rustc_ast_pretty`)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

disposition-mergeThis issue / PR is in PFCP or FCP with a disposition to merge it.finished-final-comment-periodThe final comment period is finished for this PR / Issue.S-waiting-on-borsStatus: Waiting on bors to run and complete tests. Bors will change the label on completion.T-libsRelevant to the library team, which will review and decide on the PR/issue.T-opsemRelevant to the opsem teamto-announceAnnounce this issue on triage meeting

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@RalfJung@rustbot@rust-rfcbot@joshlf@rust-log-analyzer@Mark-Simulacrum@programmerjake