Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions library/core/src/primitive_docs.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1665,10 +1665,10 @@ const _: () = ();
/// not violate these invariants. The full requirements are stronger, as the reference generally
/// must point to data that is safe to use as type `T`.
///
/// It is not decided yet whether unsafe code may violate these invariants temporarily on internal
/// data. As a consequence, unsafe code which violates these invariants temporarily on internal data
/// may be unsound or become unsound in future versions of Rust depending on how this question is
/// decided.
/// Unsafe code is allowed to temporarily violate type validity invariants on internal data that
/// cannot be otherwise observed; that is, arbitrary data can be written into the pointed-to bytes
/// of a `&mut T` even if it would constitute an invalid value of `T` or set the discriminant of a
/// wrapping enum to an invalid value, so long as everything is restored before the code returns.
Comment on lines +1668 to +1671

@RalfJung RalfJung Sep 18, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a monster sentence.

Suggested change
/// Unsafe code is allowed to temporarily violate type validity invariants on internal data that
/// cannot be otherwise observed; that is, arbitrary data can be written into the pointed-to bytes
/// of a `&mut T` even if it would constitute an invalid value of `T` or set the discriminant of a
/// wrapping enum to an invalid value, so long as everything is restored before the code returns.
/// Unsafe code is allowed to *temporarily* violate type validity invariants on internal data that
/// cannot be otherwise observed; that is, arbitrary data can be written into the pointed-to bytes
/// of a `&mut T` even if it would constitute an invalid value of `T`, so long as everything is restored
/// before the data might be used at type `T` again (in particular, before control is passed to "outside"
/// code that has access to the data this reference points to).
/// This is allowed even if the temporary value sets the discriminant of a
/// wrapping enum to an invalid value.

Also can you make "pointed-to bytes" link to this?

View changes since the review

///
/// [allocation]: ptr#allocation
#[stable(feature = "rust1", since = "1.0.0")]
Expand Down
Loading