rustc_lint/
non_fmt_panic.rs

1use rustc_ast as ast;
2use rustc_errors::Applicability;
3use rustc_hir::{self as hir, LangItem};
4use rustc_infer::infer::TyCtxtInferExt;
5use rustc_middle::{bug, ty};
6use rustc_parse_format::{ParseMode, Parser, Piece};
7use rustc_session::lint::fcw;
8use rustc_session::{declare_lint, declare_lint_pass};
9use rustc_span::{InnerSpan, Span, Symbol, hygiene, sym};
10use rustc_trait_selection::infer::InferCtxtExt;
11
12use crate::lints::{NonFmtPanicBraces, NonFmtPanicUnused};
13use crate::{LateContext, LateLintPass, LintContext, fluent_generated as fluent};
14
15declare_lint! {
16    /// The `non_fmt_panics` lint detects `panic!(..)` invocations where the first
17    /// argument is not a formatting string.
18    ///
19    /// ### Example
20    ///
21    /// ```rust,no_run,edition2018
22    /// panic!("{}");
23    /// panic!(123);
24    /// ```
25    ///
26    /// {{produces}}
27    ///
28    /// ### Explanation
29    ///
30    /// In Rust 2018 and earlier, `panic!(x)` directly uses `x` as the message.
31    /// That means that `panic!("{}")` panics with the message `"{}"` instead
32    /// of using it as a formatting string, and `panic!(123)` will panic with
33    /// an `i32` as message.
34    ///
35    /// Rust 2021 always interprets the first argument as format string.
36    NON_FMT_PANICS,
37    Warn,
38    "detect single-argument panic!() invocations in which the argument is not a format string",
39    @future_incompatible = FutureIncompatibleInfo {
40        reason: fcw!(EditionSemanticsChange 2021 "panic-macro-consistency"),
41        explain_reason: false,
42    };
43    report_in_external_macro
44}
45
46declare_lint_pass!(NonPanicFmt => [NON_FMT_PANICS]);
47
48impl<'tcx> LateLintPass<'tcx> for NonPanicFmt {
49    fn check_expr(&mut self, cx: &LateContext<'tcx>, expr: &'tcx hir::Expr<'tcx>) {
50        if let hir::ExprKind::Call(f, [arg]) = &expr.kind
51            && let &ty::FnDef(def_id, _) = cx.typeck_results().expr_ty(f).kind()
52        {
53            let f_diagnostic_name = cx.tcx.get_diagnostic_name(def_id);
54
55            if cx.tcx.is_lang_item(def_id, LangItem::BeginPanic)
56                || cx.tcx.is_lang_item(def_id, LangItem::Panic)
57                || f_diagnostic_name == Some(sym::panic_str_2015)
58            {
59                if let Some(id) = f.span.ctxt().outer_expn_data().macro_def_id {
60                    if matches!(
61                        cx.tcx.get_diagnostic_name(id),
62                        Some(sym::core_panic_2015_macro | sym::std_panic_2015_macro)
63                    ) {
64                        check_panic(cx, f, arg);
65                    }
66                }
67            } else if f_diagnostic_name == Some(sym::unreachable_display) {
68                if let Some(id) = f.span.ctxt().outer_expn_data().macro_def_id
69                    && cx.tcx.is_diagnostic_item(sym::unreachable_2015_macro, id)
70                {
71                    check_panic(
72                        cx,
73                        f,
74                        // This is safe because we checked above that the callee is indeed
75                        // unreachable_display
76                        match &arg.kind {
77                            // Get the borrowed arg not the borrow
78                            hir::ExprKind::AddrOf(ast::BorrowKind::Ref, _, arg) => arg,
79                            _ => bug!("call to unreachable_display without borrow"),
80                        },
81                    );
82                }
83            }
84        }
85    }
86}
87
88fn check_panic<'tcx>(cx: &LateContext<'tcx>, f: &'tcx hir::Expr<'tcx>, arg: &'tcx hir::Expr<'tcx>) {
89    if let hir::ExprKind::Lit(lit) = &arg.kind {
90        if let ast::LitKind::Str(sym, _) = lit.node {
91            // The argument is a string literal.
92            check_panic_str(cx, f, arg, sym.as_str());
93            return;
94        }
95    }
96
97    // The argument is *not* a string literal.
98
99    let (span, panic, symbol) = panic_call(cx, f);
100
101    if span.in_external_macro(cx.sess().source_map()) {
102        // Nothing that can be done about it in the current crate.
103        return;
104    }
105
106    // Find the span of the argument to `panic!()` or `unreachable!`, before expansion in the
107    // case of `panic!(some_macro!())` or `unreachable!(some_macro!())`.
108    // We don't use source_callsite(), because this `panic!(..)` might itself
109    // be expanded from another macro, in which case we want to stop at that
110    // expansion.
111    let mut arg_span = arg.span;
112    let mut arg_macro = None;
113    while !span.contains(arg_span) {
114        let ctxt = arg_span.ctxt();
115        if ctxt.is_root() {
116            break;
117        }
118        let expn = ctxt.outer_expn_data();
119        arg_macro = expn.macro_def_id;
120        arg_span = expn.call_site;
121    }
122
123    #[allow(rustc::diagnostic_outside_of_impl)]
124    cx.span_lint(NON_FMT_PANICS, arg_span, |lint| {
125        lint.primary_message(fluent::lint_non_fmt_panic);
126        lint.arg("name", symbol);
127        lint.note(fluent::lint_note);
128        lint.note(fluent::lint_more_info_note);
129        if !is_arg_inside_call(arg_span, span) {
130            // No clue where this argument is coming from.
131            return;
132        }
133        if arg_macro.is_some_and(|id| cx.tcx.is_diagnostic_item(sym::format_macro, id)) {
134            // A case of `panic!(format!(..))`.
135            lint.note(fluent::lint_supports_fmt_note);
136            if let Some((open, close, _)) = find_delimiters(cx, arg_span) {
137                lint.multipart_suggestion(
138                    fluent::lint_supports_fmt_suggestion,
139                    vec![
140                        (arg_span.until(open.shrink_to_hi()), "".into()),
141                        (close.until(arg_span.shrink_to_hi()), "".into()),
142                    ],
143                    Applicability::MachineApplicable,
144                );
145            }
146        } else {
147            let ty = cx.typeck_results().expr_ty(arg);
148            // If this is a &str or String, we can confidently give the `"{}", ` suggestion.
149            let is_str = matches!(
150                ty.kind(),
151                ty::Ref(_, r, _) if r.is_str(),
152            ) || matches!(
153                ty.ty_adt_def(),
154                Some(ty_def) if cx.tcx.is_lang_item(ty_def.did(), LangItem::String),
155            );
156
157            let (infcx, param_env) = cx.tcx.infer_ctxt().build_with_typing_env(cx.typing_env());
158            let suggest_display = is_str
159                || cx
160                    .tcx
161                    .get_diagnostic_item(sym::Display)
162                    .is_some_and(|t| infcx.type_implements_trait(t, [ty], param_env).may_apply());
163            let suggest_debug = !suggest_display
164                && cx
165                    .tcx
166                    .get_diagnostic_item(sym::Debug)
167                    .is_some_and(|t| infcx.type_implements_trait(t, [ty], param_env).may_apply());
168
169            let suggest_panic_any = !is_str && panic == Some(sym::std_panic_macro);
170
171            let fmt_applicability = if suggest_panic_any {
172                // If we can use panic_any, use that as the MachineApplicable suggestion.
173                Applicability::MaybeIncorrect
174            } else {
175                // If we don't suggest panic_any, using a format string is our best bet.
176                Applicability::MachineApplicable
177            };
178
179            if suggest_display {
180                lint.span_suggestion_verbose(
181                    arg_span.shrink_to_lo(),
182                    fluent::lint_display_suggestion,
183                    "\"{}\", ",
184                    fmt_applicability,
185                );
186            } else if suggest_debug {
187                lint.arg("ty", ty);
188                lint.span_suggestion_verbose(
189                    arg_span.shrink_to_lo(),
190                    fluent::lint_debug_suggestion,
191                    "\"{:?}\", ",
192                    fmt_applicability,
193                );
194            }
195
196            if suggest_panic_any {
197                if let Some((open, close, del)) = find_delimiters(cx, span) {
198                    lint.arg("already_suggested", suggest_display || suggest_debug);
199                    lint.multipart_suggestion(
200                        fluent::lint_panic_suggestion,
201                        if del == '(' {
202                            vec![(span.until(open), "std::panic::panic_any".into())]
203                        } else {
204                            vec![
205                                (span.until(open.shrink_to_hi()), "std::panic::panic_any(".into()),
206                                (close, ")".into()),
207                            ]
208                        },
209                        Applicability::MachineApplicable,
210                    );
211                }
212            }
213        }
214    });
215}
216
217fn check_panic_str<'tcx>(
218    cx: &LateContext<'tcx>,
219    f: &'tcx hir::Expr<'tcx>,
220    arg: &'tcx hir::Expr<'tcx>,
221    fmt: &str,
222) {
223    if !fmt.contains(&['{', '}']) {
224        // No brace, no problem.
225        return;
226    }
227
228    let (span, _, _) = panic_call(cx, f);
229
230    let sm = cx.sess().source_map();
231    if span.in_external_macro(sm) && arg.span.in_external_macro(sm) {
232        // Nothing that can be done about it in the current crate.
233        return;
234    }
235
236    let fmt_span = arg.span.source_callsite();
237
238    let (snippet, style) = match sm.span_to_snippet(fmt_span) {
239        Ok(snippet) => {
240            // Count the number of `#`s between the `r` and `"`.
241            let style = snippet.strip_prefix('r').and_then(|s| s.find('"'));
242            (Some(snippet), style)
243        }
244        Err(_) => (None, None),
245    };
246
247    let mut fmt_parser = Parser::new(fmt, style, snippet.clone(), false, ParseMode::Format);
248    let n_arguments = (&mut fmt_parser).filter(|a| matches!(a, Piece::NextArgument(_))).count();
249
250    if n_arguments > 0 && fmt_parser.errors.is_empty() {
251        let arg_spans: Vec<_> = match &fmt_parser.arg_places[..] {
252            [] => vec![fmt_span],
253            v => v
254                .iter()
255                .map(|span| fmt_span.from_inner(InnerSpan::new(span.start, span.end)))
256                .collect(),
257        };
258        cx.emit_span_lint(
259            NON_FMT_PANICS,
260            arg_spans,
261            NonFmtPanicUnused {
262                count: n_arguments,
263                suggestion: is_arg_inside_call(arg.span, span).then_some(arg.span),
264            },
265        );
266    } else {
267        let brace_spans: Option<Vec<_>> =
268            snippet.filter(|s| s.starts_with('"') || s.starts_with("r#")).map(|s| {
269                s.char_indices()
270                    .filter(|&(_, c)| c == '{' || c == '}')
271                    .map(|(i, _)| fmt_span.from_inner(InnerSpan { start: i, end: i + 1 }))
272                    .collect()
273            });
274        let count = brace_spans.as_ref().map(|v| v.len()).unwrap_or(/* any number >1 */ 2);
275        cx.emit_span_lint(
276            NON_FMT_PANICS,
277            brace_spans.unwrap_or_else(|| vec![span]),
278            NonFmtPanicBraces {
279                count,
280                suggestion: is_arg_inside_call(arg.span, span).then_some(arg.span.shrink_to_lo()),
281            },
282        );
283    }
284}
285
286/// Given the span of `some_macro!(args);`, gives the span of `(` and `)`,
287/// and the type of (opening) delimiter used.
288fn find_delimiters(cx: &LateContext<'_>, span: Span) -> Option<(Span, Span, char)> {
289    let snippet = cx.sess().source_map().span_to_snippet(span).ok()?;
290    let (open, open_ch) = snippet.char_indices().find(|&(_, c)| "([{".contains(c))?;
291    let close = snippet.rfind(|c| ")]}".contains(c))?;
292    Some((
293        span.from_inner(InnerSpan { start: open, end: open + 1 }),
294        span.from_inner(InnerSpan { start: close, end: close + 1 }),
295        open_ch,
296    ))
297}
298
299fn panic_call<'tcx>(
300    cx: &LateContext<'tcx>,
301    f: &'tcx hir::Expr<'tcx>,
302) -> (Span, Option<Symbol>, Symbol) {
303    let mut expn = f.span.ctxt().outer_expn_data();
304
305    let mut panic_macro = None;
306
307    // Unwrap more levels of macro expansion, as panic_2015!()
308    // was likely expanded from panic!() and possibly from
309    // [debug_]assert!().
310    loop {
311        let parent = expn.call_site.ctxt().outer_expn_data();
312        let Some(id) = parent.macro_def_id else { break };
313        let Some(name) = cx.tcx.get_diagnostic_name(id) else { break };
314        if !matches!(
315            name,
316            sym::core_panic_macro
317                | sym::std_panic_macro
318                | sym::assert_macro
319                | sym::debug_assert_macro
320                | sym::unreachable_macro
321        ) {
322            break;
323        }
324        expn = parent;
325        panic_macro = Some(name);
326    }
327
328    let macro_symbol =
329        if let hygiene::ExpnKind::Macro(_, symbol) = expn.kind { symbol } else { sym::panic };
330    (expn.call_site, panic_macro, macro_symbol)
331}
332
333fn is_arg_inside_call(arg: Span, call: Span) -> bool {
334    // We only add suggestions if the argument we're looking at appears inside the
335    // panic call in the source file, to avoid invalid suggestions when macros are involved.
336    // We specifically check for the spans to not be identical, as that happens sometimes when
337    // proc_macros lie about spans and apply the same span to all the tokens they produce.
338    call.contains(arg) && !call.source_equal(arg)
339}