From ec315207dafdd1768c8b6a75b3019bfdb5c622c9 Mon Sep 17 00:00:00 2001 From: Nia Deckers Date: Fri, 21 Aug 2026 13:03:43 +0200 Subject: [PATCH 1/2] you can write garbage into &mut --- library/core/src/primitive_docs.rs | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/library/core/src/primitive_docs.rs b/library/core/src/primitive_docs.rs index 3e1596689e9d1..39bf5a6e1ac99 100644 --- a/library/core/src/primitive_docs.rs +++ b/library/core/src/primitive_docs.rs @@ -1665,10 +1665,10 @@ const _: () = (); /// not violate these invariants. The full requirements are stronger, as the reference generally /// must point to data that is safe to use as type `T`. /// -/// It is not decided yet whether unsafe code may violate these invariants temporarily on internal -/// data. As a consequence, unsafe code which violates these invariants temporarily on internal data -/// may be unsound or become unsound in future versions of Rust depending on how this question is -/// decided. +/// Unsafe code is allowed to temporarily violate type validity invariants on internal data that +/// cannot be otherwise observed; that is, arbitrary data can be written into the pointed-to bytes +/// of a `&mut T` even if it would constitute an invalid value of `T` or set the disriminant of a +/// wrapping enum to an invalid value, so long as everything is restored before the code returns. /// /// [allocation]: ptr#allocation #[stable(feature = "rust1", since = "1.0.0")] From 6750cff907408237dd11b3fae066e6b83e8a8070 Mon Sep 17 00:00:00 2001 From: Nia Deckers Date: Sat, 29 Aug 2026 00:08:52 +0200 Subject: [PATCH 2/2] typo --- library/core/src/primitive_docs.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/library/core/src/primitive_docs.rs b/library/core/src/primitive_docs.rs index 39bf5a6e1ac99..cb22ace653716 100644 --- a/library/core/src/primitive_docs.rs +++ b/library/core/src/primitive_docs.rs @@ -1667,7 +1667,7 @@ const _: () = (); /// /// Unsafe code is allowed to temporarily violate type validity invariants on internal data that /// cannot be otherwise observed; that is, arbitrary data can be written into the pointed-to bytes -/// of a `&mut T` even if it would constitute an invalid value of `T` or set the disriminant of a +/// of a `&mut T` even if it would constitute an invalid value of `T` or set the discriminant of a /// wrapping enum to an invalid value, so long as everything is restored before the code returns. /// /// [allocation]: ptr#allocation