Skip to content

Tracking Issue for future-incompatibility lint unsafe_panic_handlers #163263

Description

@theemathas

This is the tracking issue for the unsafe_panic_handlers future-compatibility warning. The goal of this page is to describe why this change was made and how you can fix code that is affected by it. It also provides a place to ask questions or register a complaint if you feel the change should not be made. For more information on the policy around future-compatibility warnings, see our breaking change policy guidelines.

What is the warning for?

The lint gives warnings on unsafe functions with the #[panic_handler] attribute.

Why was this change made?

Unsafe functions (declared as unsafe fn) are functions that can only be called when the caller ensures that their safety requirements are met. On the other hand, #[panic_handler] functions get called automatically by the compiler without checking for any preconditions. Therefore, using the #[panic_handler] attribute on unsafe functions is either incorrect or a misuse of unsafe fn.

Example

#![no_std]

use core::panic::PanicInfo;

#[panic_handler]
unsafe fn handle(_: &PanicInfo<'_>) -> ! {
    loop {}
}
warning: `#[panic_handler]` functions can't be `unsafe`
 --> lint_example.rs:7:1
  |
7 | unsafe fn handle(_: &PanicInfo<'_>) -> ! {
  | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  |
  = warning: this was previously accepted by the compiler but is being phased out; it will become a hard error in a future release!
  = note: for more information, see issue #163263 <https://github.com/rust-lang/rust/issues/163263>
  = note: `#[warn(unsafe_panic_handlers)]` on by default

Recommendations

In most cases, the unsafe can be removed, turning the unsafe fn into a fn. If unsafe operations need to be done inside the function, use a separate unsafe { .... } block inside the function.

When will this warning become a hard error?

After a sufficient time has passed, and a crater run has determined that a sufficiently small amount of code would be broken by this.

Steps

  • Implement the lint
  • Raise lint level to deny
  • Change the lint to report in dependencies
  • Switch to a hard error

Implementation history

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    A-panicArea: Panicking machineryC-future-incompatibilityCategory: Future-incompatibility lintsT-langRelevant to the language team

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions