Skip to content

linux: Improve panic message for out-of-range fds in FD_* functions - #5528

Merged
tgross35 merged 1 commit into
rust-lang:mainfrom
danielcanencia:I_1401
Oct 1, 2026
Merged

tgross35 merged 1 commit into
rust-lang:mainfrom
danielcanencia:I_1401

Conversation

@danielcanencia

@danielcanencia danielcanencia commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Part of #1401

Fixes the out-of-bounds FD_SET/FD_CLR/FD_ISSET panic for Linux
(linux_like). The issue also calls for the same clear panic message in
other platforms; those remain a follow-up (cygwin, haiku, solaris, etc).

Note:

  • FD_ZERO needs no change — it takes no fd and fills the set, so there
    is nothing to range-check.

@tgross35 tgross35 left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for putting this together!

The issue also calls for the same clear panic message in other platforms; those remain a follow-up (cygwin, haiku, solaris, etc).

I'd prefer to get them all done at the same time.

View changes since this review

Comment thread src/unix/linux_like/mod.rs Outdated
Comment thread src/unix/linux_like/mod.rs Outdated
Comment thread src/unix/linux_like/mod.rs
@rustbot

rustbot commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

Reminder, once the PR becomes ready for a review, use @rustbot ready.

@rustbot

rustbot commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

Some changes occurred in a solarish module

cc @jclulow, @pfmooney

@rustbot

This comment has been minimized.

@danielcanencia

Copy link
Copy Markdown
Contributor Author

@tgross35 All three review points are addressed: let-else style, panic! in the prelude, and coverage of all platforms. Ready for another look.

@rustbot ready

@tgross35 tgross35 left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One followup that came with the new changes, otherwise LGTM

View changes since this review

Comment thread src/fuchsia/mod.rs

f! {
pub unsafe fn FD_CLR(fd: c_int, set: *mut fd_set) -> () {
let fd = fd as usize;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you keep the single let fd = fd as usize; and use that? Since all other uses of fd are currently doing the same cast.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, sorry about that. All functions now keep the single upfront cast.

@rustbot

rustbot commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed.

Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers.

Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401
@danielcanencia

Copy link
Copy Markdown
Contributor Author

@rustbot ready

@tgross35 tgross35 left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tgross35
tgross35 added this pull request to the merge queue Oct 1, 2026
Merged via the queue into rust-lang:main with commit 5b6e5a6 Oct 1, 2026
60 checks passed
@tgross35 tgross35 added the stable-nominated This PR should be considered for cherry-pick to libc's stable release branch label Oct 1, 2026
tgross35 pushed a commit to tgross35/rust-libc that referenced this pull request Oct 1, 2026
Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401

(backport <rust-lang#5528>)
(cherry picked from commit 5b6e5a6)
tgross35 pushed a commit to tgross35/rust-libc that referenced this pull request Oct 1, 2026
Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401

(backport <rust-lang#5528>)
(cherry picked from commit 5b6e5a6)
tgross35 pushed a commit to tgross35/rust-libc that referenced this pull request Oct 1, 2026
Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401

(backport <rust-lang#5528>)
(cherry picked from commit 5b6e5a6)
tgross35 pushed a commit to tgross35/rust-libc that referenced this pull request Oct 1, 2026
Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401

(backport <rust-lang#5528>)
(cherry picked from commit 5b6e5a6)

[ needed to add an extra cast on WASI for the 0.2 branch - Trevor ]
tgross35 pushed a commit to tgross35/rust-libc that referenced this pull request Oct 1, 2026
Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401

(backport <rust-lang#5528>)
(cherry picked from commit 5b6e5a6)

[ needed to add an extra cast on WASI for the 0.2 branch - Trevor ]
tgross35 pushed a commit to tgross35/rust-libc that referenced this pull request Oct 1, 2026
Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401

(backport <rust-lang#5528>)
(cherry picked from commit 5b6e5a6)

[ needed to add an extra cast on WASI for the 0.2 branch - Trevor ]
@tgross35 tgross35 mentioned this pull request Oct 1, 2026
renovate-bot pushed a commit to renovate-bot/rust-lang-_-libc that referenced this pull request Oct 1, 2026
Passing a file descriptor that is negative or >= FD_SETSIZE to FD_SET,
FD_CLR or FD_ISSET is undefined behavior per POSIX, and the previous
"index out of bounds" panic gave no hint of the required range. Panic
with a message that states the valid 0..FD_SETSIZE range instead.

Applies the fix across all platforms: linux_like, bsd, solarish, redox,
nto, newlib, fuchsia, haiku, cygwin, hurd, aix (bitmask via get/get_mut
+ let-else) and wasi (explicit range check). FD_ZERO is unchanged (takes
no fd). WASI has no FD_CLR.

Also adds panic! and Option::{self, None, Some} to the prelude so the
new code resolves under no_core (rustc-dep-of-std) builds.

Part of rust-lang#1401

(backport <rust-lang#5528>)
(cherry picked from commit 5b6e5a6)

[ needed to add an extra cast on WASI for the 0.2 branch - Trevor ]
@tgross35 tgross35 added stable-applied This PR has been cherry-picked to libc's stable release branch and removed stable-nominated This PR should be considered for cherry-pick to libc's stable release branch labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants