From 83218bf0dab4950e4736f848a5d7f434b0e26a3d Mon Sep 17 00:00:00 2001 From: Alexander McLin Date: Sat, 4 Apr 2026 13:37:42 -0400 Subject: [PATCH] Issue 3223: make `unsafe` scopes tighter --- src/arena.rs | 5 ++--- src/atom_table.rs | 2 -- src/ffi.rs | 20 ++++++++++---------- src/machine/heap.rs | 10 +++++----- src/machine/stack.rs | 2 +- src/read.rs | 2 +- 6 files changed, 19 insertions(+), 22 deletions(-) diff --git a/src/arena.rs b/src/arena.rs index f8cd9695..53bf5cc2 100644 --- a/src/arena.rs +++ b/src/arena.rs @@ -496,14 +496,13 @@ impl Arena { } } -unsafe fn drop_slab_in_place(value: NonNull, tag: ArenaHeaderTag) { - unsafe { +unsafe fn drop_slab_in_place(value: NonNull, tag: ArenaHeaderTag) { macro_rules! drop_typed_slab_in_place { ($payload: ty, $value: expr) => { <$payload as ArenaAllocated>::dealloc($value.cast::>()) }; } - + unsafe { match tag { ArenaHeaderTag::Integer => { drop_typed_slab_in_place!(Integer, value); diff --git a/src/atom_table.rs b/src/atom_table.rs index 5292d208..3e156b35 100644 --- a/src/atom_table.rs +++ b/src/atom_table.rs @@ -386,8 +386,6 @@ impl Atom { unsafe fn write_to_ptr(string: &str, ptr: *mut u8) { unsafe { ptr::write(ptr as *mut _, AtomHeader::build_with(string.len() as u64)); - } - unsafe { let str_ptr = ptr.add(mem::size_of::()); ptr::copy_nonoverlapping(string.as_ptr(), str_ptr, string.len()); } diff --git a/src/ffi.rs b/src/ffi.rs index d319cfc7..8cfc2979 100644 --- a/src/ffi.rs +++ b/src/ffi.rs @@ -56,8 +56,8 @@ impl FunctionImpl { unsafe fn call_void(&self, args: &[Arg], _: &mut Arena) -> Result { unsafe { self.cif.call_return_into(self.code_ptr, args, Ret::void()); - Ok(Value::Number(Number::Fixnum(Fixnum::build_with(0)))) } + Ok(Value::Number(Number::Fixnum(Fixnum::build_with(0)))) } unsafe fn call_int(&self, args: &[Arg], arena: &mut Arena) -> Result @@ -204,14 +204,14 @@ impl StructImpl { layout: &mut Layout, val: T, ) -> Result<(), FfiError> { + let (new_layout, offset) = layout + .extend(Layout::new::()) + .map_err(|_| FfiError::LayoutError)?; + *layout = new_layout; unsafe { - let (new_layout, offset) = layout - .extend(Layout::new::()) - .map_err(|_| FfiError::LayoutError)?; - *layout = new_layout; ptr.byte_offset(offset as isize).cast::().write(val); - Ok(()) } + Ok(()) } for arg in args { @@ -267,11 +267,11 @@ impl StructImpl { ptr: *mut c_void, layout: &mut Layout, ) -> Result { + let (new_layout, offset) = layout + .extend(Layout::new::()) + .map_err(|_| FfiError::LayoutError)?; + *layout = new_layout; unsafe { - let (new_layout, offset) = layout - .extend(Layout::new::()) - .map_err(|_| FfiError::LayoutError)?; - *layout = new_layout; let n = std::ptr::read::(ptr.byte_offset(offset as isize).cast()); Ok(n) } diff --git a/src/machine/heap.rs b/src/machine/heap.rs index 3353056f..ba39c028 100644 --- a/src/machine/heap.rs +++ b/src/machine/heap.rs @@ -58,7 +58,6 @@ struct InnerHeap { impl InnerHeap { unsafe fn grow(&mut self) -> bool { - unsafe { let new_cap = if self.byte_cap == 0 { 256 * 256 * 8 } else { @@ -72,7 +71,7 @@ impl InnerHeap { new_layout.size() <= isize::MAX as usize, "Allocation too large. We should probably GC (TODO)" ); - + unsafe { let new_ptr = if self.byte_cap == 0 { alloc::alloc(new_layout) } else { @@ -105,11 +104,12 @@ pub struct HeapStringScan<'a> { // The heap_slice should be inside the heap unsafe fn scan_slice_to_str(heap_slice: &[u8]) -> HeapStringScan<'_> { - unsafe { let string_len = heap_slice .iter() .position(|b| *b == 0u8) .unwrap_or(heap_slice.len()); + + unsafe { let zero_byte_addr = heap_slice.as_ptr().add(string_len); let sentinel_len = pstr_sentinel_length(zero_byte_addr.addr()); @@ -130,7 +130,6 @@ unsafe fn scan_slice_to_str(heap_slice: &[u8]) -> HeapStringScan<'_> { // Same as scan_slice_to_str but assumes that the slice is from the start of a string. // Can be used on strings out of the heap. unsafe fn scan_slice_to_str_from_start(heap_slice: &[u8]) -> HeapStringScan<'_> { - unsafe { let string_len = heap_slice .iter() .position(|b| *b == 0u8) @@ -143,7 +142,8 @@ unsafe fn scan_slice_to_str_from_start(heap_slice: &[u8]) -> HeapStringScan<'_> ); let str_slice = &heap_slice[..string_len]; - + + unsafe { HeapStringScan { string: std::str::from_utf8_unchecked(str_slice), tail_idx, diff --git a/src/machine/stack.rs b/src/machine/stack.rs index df9cd111..598a4846 100644 --- a/src/machine/stack.rs +++ b/src/machine/stack.rs @@ -176,8 +176,8 @@ impl Stack { #[inline(always)] unsafe fn alloc(&mut self, frame_size: usize) -> Result, AllocError> { - unsafe { loop { + unsafe { let ptr = self.buf.alloc(frame_size); if let Some(ptr) = NonNull::new(ptr) { return Ok(ptr); diff --git a/src/read.rs b/src/read.rs index 45a06f7e..7ff88f41 100644 --- a/src/read.rs +++ b/src/read.rs @@ -102,7 +102,7 @@ pub(crate) fn set_prompt(value: bool) { #[cfg(feature = "repl")] #[inline] fn get_prompt() -> &'static str { - unsafe { if PROMPT { "?- " } else { "" } } + if unsafe { PROMPT } { "?- " } else { "" } } thread_local! {