From 408ef6c564512a859bc2b8a94570983c4032d45c Mon Sep 17 00:00:00 2001 From: Zack Maril Date: Wed, 7 Oct 2026 21:32:06 +0000 Subject: [PATCH 1/9] Finding 8 reduced to one line: a generic fn using slice get, at -Zmir-opt-level=3 The difference needs MIR inlining from core; a generic local helper, a non-generic function or level 2 do not show it. All the level-4 fuzz differences go away with -Zinline-mir=no. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_018Mnrg9JXj9X1ht6Qkz2ybh --- docs/hunt.md | 2 +- docs/hunt/issue-inlined-alloc-identity.md | 73 +++++++++++++---------- docs/hunt/repro.sh | 8 +-- 3 files changed, 46 insertions(+), 37 deletions(-) diff --git a/docs/hunt.md b/docs/hunt.md index 91a813e..0393e65 100644 --- a/docs/hunt.md +++ b/docs/hunt.md @@ -31,7 +31,7 @@ with `-Zthreads=8`. `rustc/check.sh wide` runs the ordinary checks. | 5 | six untracked options change results incremental compilation reuses; with `-Zno-leak-check`, a rebuild accepts a program a clean build rejects | **looks new**; the first three found by a query written from a closed bug and an option audit ([`ur-queries.md`](ur-queries.md)), `-Zno-leak-check`, `-C extra-filename` and `-Zfuture-incompat-test` by reporting untracked reads ([`untracked-reads.md`](untracked-reads.md)); report drafted | | 6 | reused object code keeps the previous checksum of an edited source file in its debuginfo, and with `-Zembed-source` the previous file; with optimizations, ThinLTO symbol names then differ from a clean build | **looks new**; found by the fuzzer at `-Copt-level=2`; root cause found, since 1.44 (#69718); report drafted and a regression test (`hunt/tests/incr-debuginfo-embedded-source`, failing: no fix) | | 7 | warnings from inline assembly are not shown again when an incremental rebuild reuses the codegen unit | **looks new**; found while checking reused codegen units ([`shadow-mode.md`](shadow-mode.md)); on 1.60.0 through the nightly; report drafted ([draft](hunt/issue-asm-warnings-reused-cgu.md)) and a regression test (`hunt/tests/incr-asm-warning-reused`, failing: no fix) | -| 8 | with `-Zmir-opt-level=3` and debuginfo, an incremental rebuild encodes an allocation twice where a clean build encodes it once | **looks new**; found by the fuzzer at `-Zmir-opt-level=4` and named by the reuse check, reduced to three lines; on 1.60.0 through the nightly; report drafted ([draft](hunt/issue-inlined-alloc-identity.md)), no fix | +| 8 | with `-Zmir-opt-level=3`, an incremental rebuild encodes an allocation from inlined `core` MIR twice where a clean build encodes it once | **looks new**; found by the fuzzer at `-Zmir-opt-level=4` and named by the reuse check, reduced to one line; on 1.60.0 through the nightly; report drafted ([draft](hunt/issue-inlined-alloc-identity.md)), no fix | Findings 1 and 2 are single-threaded: an ordinary `cargo build`, an edit, another `cargo build`, and the metadata differs from a clean build of the edited source. Both come diff --git a/docs/hunt/issue-inlined-alloc-identity.md b/docs/hunt/issue-inlined-alloc-identity.md index c669810..6540872 100644 --- a/docs/hunt/issue-inlined-alloc-identity.md +++ b/docs/hunt/issue-inlined-alloc-identity.md @@ -1,4 +1,4 @@ -# With `-Zmir-opt-level=3` and debuginfo, an incremental rebuild encodes an allocation twice where a clean build encodes it once +# With `-Zmir-opt-level=3`, an incremental rebuild encodes an allocation from inlined `core` MIR twice where a clean build encodes it once