3 ms·
no-panic relies on a linker hack because that's what's possible to do in stable Rust today; there's no API for adding an additional compiler pass that prohibits
by ameliaquining 2mo ago
no-panic relies on a linker hack because that's what's possible to do in stable Rust today; there's no API for adding an additional compiler pass that prohibits you from calling certain functions.
Constants are well-defined in Rust; panicking operations like array indexing would be allowed within no-panic functions in const contexts (https://doc.rust-lang.org/reference/const_eval.html#const-context https://doc.rust-lang.org/reference/const_eval.html#const-co...), but not otherwise.
There's a difference between genericity over no-panicness (which I argue is not needed for an MVP) and allowing otherwise generic functions to be no-panic (which I do think is required). I don't think a linter can do the latter, because it would need to integrate with the trait system (e.g., you would need a NoPanicDrop trait and possibly NoPanicFn(|Mut|Once) traits).