Skip to main content

Subobject

Enum Subobject 

Source
pub enum Subobject {
    Off,
    Members,
}
Expand description

Whether an access has to stay inside the member it names, from -fsafety-subobject.

Design: spec/safe-memory/09-type-init-and-races.md section 9.4, which is row S4 of document 03 and is the class Fil-C, CHERI by default and ARM MTE all miss. Their metadata is per allocation and a member is not an allocation, so an overflow from one member of a structure into the next is invisible to all three. The type plane is byte granular, so it is not invisible here.

A flag rather than a default because of what a store means. C 6.5 says a store to allocated storage sets that storage’s effective type, so a write that leaves one member and lands in the next is, read literally, a program retyping bytes it owns. Every buffer that gets reused for a second kind of value does the same thing on purpose. So the question a store asks is only asked when somebody has said they want it asked, and what they get in return is the write half of S4 that nothing else catches.

The read half is not behind this and never was: a read that disagrees with the plane is judgement J1 at every tier, because reading bytes back through a type they were not stored through is undefined however the pointer got there.

Variants§

§

Off

No -fsafety-subobject. A store records what it wrote and is asked nothing.

§

Members

-fsafety-subobject. A store asks the plane whether the bytes it is about to write agree with the type it writes them through, which catches an overflow out of a member into a member of a different type.

Two adjacent members of the same type are indistinguishable to this, which section 9.4 states plainly: struct { int a; int b; } overflowing from a into b writes int over int and there is nothing for the plane to disagree with. That is what -fsafety-subobject=strict is for and it is not here yet.

Implementations§

Source§

impl Subobject

Source

pub const fn as_str(self) -> &'static str

The spelling this is asked for by, without the flag in front of it.

Source

pub const fn asks(self) -> bool

Whether a store asks the type plane anything.

Trait Implementations§

Source§

impl Clone for Subobject

Source§

fn clone(&self) -> Subobject

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Subobject

Source§

impl Debug for Subobject

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Subobject

Source§

fn default() -> Subobject

Returns the “default value” for a type. Read more
Source§

impl Display for Subobject

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Subobject

Source§

impl Hash for Subobject

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for Subobject

Source§

fn cmp(&self, other: &Subobject) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

fn clamp_to<R>(self, range: R) -> Self
where Self: Sized, R: ClampBounds<Self>,

🔬This is a nightly-only experimental API. (clamp_to)
Restrict a value to a certain range. Read more
Source§

impl PartialEq for Subobject

Source§

fn eq(&self, other: &Subobject) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl PartialOrd for Subobject

Source§

fn partial_cmp(&self, other: &Subobject) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl StructuralPartialEq for Subobject

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.