Rust: Restrict type propagation into receivers#21333
Rust: Restrict type propagation into receivers#21333hvitved wants to merge 2 commits intogithub:mainfrom
Conversation
652c8db to
e587541
Compare
| strictcount(Expr e | bodyReturns(parent, e)) > 1 and | ||
| prefix.isEmpty() | ||
| or | ||
| exists(Struct s | |
There was a problem hiding this comment.
This change is not what solves the timeout, but I saw cases where type information would incorrectly flow between limits in range expressions, so I decided to treat them as LUB conversions.
There was a problem hiding this comment.
Pull request overview
This PR restricts type propagation into method receivers to fix a combinatorial explosion issue in Rust type inference, addressing a timeout on the stalwartlabs/stalwart repository. The change prevents type information from being propagated back into receiver positions during type inference, since the receiver type must already be known for method resolution to occur.
Changes:
- Modified type inference logic to restrict type propagation into receivers by introducing a new predicate
assocFunctionMentionsTypeParameterAtNonRetPosand updating the context typing logic to never propagate types directly into receivers when the prefix is empty - Refactored the type inference signature from
boolean isReturntoFunctionPosition posfor more precise position tracking - Moved Range type parameter constraints from
typeEqualitytolubCoercionto better reflect their coercion semantics - Added a regression test demonstrating the combinatorial explosion scenario with recursive enum types and method chaining
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| rust/ql/lib/codeql/rust/internal/typeinference/TypeInference.qll | Core type inference logic changes: refactored position tracking, added receiver restriction, moved Range coercion logic, and simplified several helper predicates |
| rust/ql/test/library-tests/type-inference/regressions.rs | New regression test file demonstrating the combinatorial explosion case with recursive enum types |
| rust/ql/test/library-tests/type-inference/main.rs | Added module declaration for the new regressions test file |
| rust/ql/test/library-tests/type-inference/type-inference.expected | Updated expected output reflecting the restricted type propagation (one line removed at 9514, new entries added for regression test) |
| exists(StructExprMatchingInput::Access a, StructExprMatchingInput::AccessPosition apos | | ||
| n = a.getNodeAt(apos) and | ||
| if apos.isStructPos() then isReturn = true else isReturn = false | ||
| if apos.isStructPos() then pos.isReturn() else pos.asPosition() = 0 // the acutal position doesn't matter, as long as it is positional |
There was a problem hiding this comment.
Typo in the comment: "acutal" should be "actual".
| if apos.isStructPos() then pos.isReturn() else pos.asPosition() = 0 // the acutal position doesn't matter, as long as it is positional | |
| if apos.isStructPos() then pos.isReturn() else pos.asPosition() = 0 // the actual position doesn't matter, as long as it is positional |
Fixes a source of type inference combinatorial explosion (see test), which fixes a timeout on
stalwartlabs/stalwart.DCA is great: only a modest decrease in
Percentage of calls with call target, but on the other hand a large decrease inNodes With Type At Length Limit.