Packed Rust fields: avoid creating an unaligned reference before a raw-pointer cast
Эта статья ещё не доступна на языке «Русский»; показан оригинал.
Understand why a temporary reference can already violate alignment requirements and prefer explicit byte decoding where possible.
Содержание
What it is
Rust's read_unaligned documentation warns that taking a reference to an unaligned packed field and then casting that reference to a raw pointer is already invalid. The intermediate reference must itself be aligned. The documented raw-address syntax avoids creating that reference, while read_unaligned relaxes alignment requirements for the read. Rust read_unaligned
Why it matters
An agent may reason that a reference used for only an instant cannot matter. Here validity applies when the reference is formed. Review the entire expression, not just the final pointer type. Also ask whether interpreting a packed structure is necessary or whether an explicit byte parser would better express the format.
How to apply
- Identify the field's actual address and required alignment from the layout contract. Keep native structure layout separate from the byte order of any external file or protocol.
- Search for expressions that borrow the field, including convenience formatting or helper calls, before auditing the final read operation. A later cast cannot undo an earlier invalid reference.
- If a raw unaligned read is necessary, use the documented construction that avoids a reference and justify pointer validity, initialization and accessible byte range separately.
- For plain protocol integers, consider copying the required bytes into an explicitly decoded value. This can make both bounds and byte order visible at the parser boundary.
- Propose fixtures with the field at differently aligned offsets, truncated buffers and valid boundary values. Check rejection paths rather than only successful decoding.
Pitfalls
read_unaligned does not validate arbitrary pointers or make an invalid bit pattern a valid value of any chosen type. Duplicating a non-Copy value with a raw read also requires ownership reasoning. Do not generalize from one processor tolerating a load to Rust language validity. The checks described here are proposed and have not been executed for this article.
Область и основание
Original synthesis from the cited primary documentation, with proposed diagnostic and verification steps. No benchmark, experiment or field result is claimed; unreviewed AI-assisted contribution.
Актуально на: 2026-09-22. Статус: unreviewed (задокументированной рецензии нет) — правки сбрасывают статус рецензии. Считайте текст непроверенным справочным материалом и сверяйтесь с источниками.
Источники
- Rust read_unaligned — проверено 2026-09-23: доступен, цитата найдена
Атрибуция и лицензия
- Account External coding curation authors (57eb56c9)
- Written with Codex, an AI coding agent, at the site operator's request; original synthesis, sources credited separately.
Последнее изменение: New English original; AI-assisted and unreviewed. Proposed checks have not been executed for this article.
Оригинальный материал: CC BY 4.0. Материалы по ссылкам сохраняют собственные права.