Skip to content

vexos: clear .bss from assembly - #163960

Merged
rust-bors[bot] merged 3 commits into
rust-lang:mainfrom
vexide:tropicaaal/asm-bss-clear
Oct 8, 2026
Merged

rust-bors[bot] merged 3 commits into
rust-lang:mainfrom
vexide:tropicaaal/asm-bss-clear

Conversation

@tropicaaal

@tropicaaal tropicaaal commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

On target_os = "vexos", libstd is responsible for clearing the .bss section during runtime initialization. This PR moves that step from Rust (previously done via core::ptr::write_bytes) to some assembly that runs even earlier into execution.

The previous approach was sketchy at best when considering soundness, because:

  • Pointer provenance (probably) makes this UB since .bss lives inside the bounds of the abstract machine and we'd be writing to memory that will eventually hold statics. I have no idea how this plays out in practice, especially because it's a linkerscript symbol which isn't an actual value.
  • core::ptr::write_bytes gets lowered to a memclr intrinsic, which may access .bss depending on how its implemented in compiler-rt.
  • On debug profiles, UB precondition checks might cause problems depending on what's being asserted before the runtime environment is sane.

Anyways, for peace-of-mind it's much better to do this from assembly. The compiler changes here are trivial, just a change to the linkerscript to ensure that __bss_start gets aligned to a 4-byte boundary.

@rustbot rustbot added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. T-libs Relevant to the library team, which will review and decide on the PR/issue. labels Oct 8, 2026
@tropicaaal

tropicaaal commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor Author

marked as a draft until I get a chance to test this

this loop was originally written for thumb-2, but since we start in ARM mode we want regular mov
@tropicaaal

Copy link
Copy Markdown
Contributor Author

tested in QEMU, seems to work fine

@tropicaaal
tropicaaal marked this pull request as ready for review October 8, 2026 06:18
@rustbot

rustbot commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

These commits modify compiler targets.
(See the Target Tier Policy.)

@rustbot rustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Oct 8, 2026
@rustbot

rustbot commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

r? @aapoalas

rustbot has assigned @aapoalas.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: @ChrisDenton, libs
  • @ChrisDenton, libs expanded to 13 candidates
  • Random selection from ChrisDenton, JohnTitor, Mark-Simulacrum, aapoalas, clarfonthey

@hanna-kruppe

hanna-kruppe commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

I don't know anything about vexos, but this looks good to me:

  • This only affects the thumbv7a-vex-v5 target (tier 3) and the PR comes from a target maintainers
  • I agree that doing this initialization from Rust (or C) is extremely sketchy for all the reasons described.
  • The new code look clear and plausible to me
  • This is very target-specific so I don't expect there's any good way to have more target-independent / shared code for this

r? me @bors r+ rollup

@rust-bors

rust-bors Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

📌 Commit 810627f has been approved by hanna-kruppe

It is now in the queue for this repository.

@rust-bors rust-bors Bot added the S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. label Oct 8, 2026
@rust-bors rust-bors Bot removed the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Oct 8, 2026
rust-bors Bot pushed a commit that referenced this pull request Oct 8, 2026
…uwer

Rollup of 19 pull requests

Successful merges:

 - #156112 (Distinguish `repr(C)` ZSTs from others in ABI computation)
 - #157941 (Deny partial `-Z stack-protector` by default in all editions)
 - #163462 (Fix COFF renaming of decorated (stdcall/fastcall/vectorcall) exports)
 - #163855 (Include enclosing item's context on const errors)
 - #163861 (Run LLDB debuginfo tests on `x86_64-mingw`)
 - #163913 ( Silence redundant failed obligations on the same statement)
 - #161201 (Speed up tidy again)
 - #163380 (Tweak "name not found" resolution error when it happens from within a derive expansion)
 - #163538 (Add `rustc::missing_generic_type_visitable` lint)
 - #163617 (mips: make `Complex<T>` ABI match GCC)
 - #163772 (comptime fn error: suggest wrapping in const block)
 - #163813 (use pre-borrowck typing env for early MIR validation)
 - #163924 (replace instances of NonNull::new(&mut x).expect("...") with NonNull::from_mut)
 - #163958 (only make `RustaceansAreAwesome` satisfy trait clauses)
 - #163960 (vexos: clear .bss from assembly)
 - #163974 (Condense AdtDef lang item checks into one match)
 - #163979 (Add `bf16` to arm features)
 - #163989 (Revert "compiletest: stream output of executor process when --no-capture is set")
 - #163995 (m68k-unknown-none-elf: Remove code model)

Failed merges:

 - #163832 (reject non-async coroutine closures as async callables)
 - #163972 (const-eval: ICE when we hit a non-const fn)
@rust-bors
rust-bors Bot merged commit b0c172e into rust-lang:main Oct 8, 2026
14 checks passed
@rustbot rustbot added this to the 1.101.0 milestone Oct 8, 2026
rust-bors Bot pushed a commit that referenced this pull request Oct 8, 2026
Rollup merge of #163960 - vexide:tropicaaal/asm-bss-clear, r=hanna-kruppe

vexos: clear .bss from assembly

On `target_os = "vexos"`, libstd is responsible for clearing the `.bss` section during runtime initialization. This PR moves that step from Rust (previously done via `core::ptr::write_bytes`) to some assembly that runs even earlier into execution.

The previous approach was sketchy at best when considering soundness, because:
- Pointer provenance (probably) makes this UB since `.bss` lives inside the bounds of the abstract machine and we'd be writing to memory that will eventually hold statics. I have no idea how this plays out in practice, especially because it's a linkerscript symbol which isn't an actual value.
- `core::ptr::write_bytes` gets lowered to a memclr intrinsic, which may access `.bss` depending on how its [implemented](https://github.com/rust-lang/compiler-builtins/blob/7f5edc1fc0f7b736d9beb6f817650feac7247114/compiler-builtins/src/arm.rs#L248) in `compiler-rt`.
- On debug profiles, UB precondition checks might cause problems depending on what's being asserted before the runtime environment is sane.

Anyways, for peace-of-mind it's much better to do this from assembly. The compiler changes here are trivial, just a change to the linkerscript to ensure that `__bss_start` gets aligned to a 4-byte boundary.
programskillforverification pushed a commit to programskillforverification/miri that referenced this pull request Oct 9, 2026
…uwer

Rollup of 19 pull requests

Successful merges:

 - rust-lang/rust#156112 (Distinguish `repr(C)` ZSTs from others in ABI computation)
 - rust-lang/rust#157941 (Deny partial `-Z stack-protector` by default in all editions)
 - rust-lang/rust#163462 (Fix COFF renaming of decorated (stdcall/fastcall/vectorcall) exports)
 - rust-lang/rust#163855 (Include enclosing item's context on const errors)
 - rust-lang/rust#163861 (Run LLDB debuginfo tests on `x86_64-mingw`)
 - rust-lang/rust#163913 ( Silence redundant failed obligations on the same statement)
 - rust-lang/rust#161201 (Speed up tidy again)
 - rust-lang/rust#163380 (Tweak "name not found" resolution error when it happens from within a derive expansion)
 - rust-lang/rust#163538 (Add `rustc::missing_generic_type_visitable` lint)
 - rust-lang/rust#163617 (mips: make `Complex<T>` ABI match GCC)
 - rust-lang/rust#163772 (comptime fn error: suggest wrapping in const block)
 - rust-lang/rust#163813 (use pre-borrowck typing env for early MIR validation)
 - rust-lang/rust#163924 (replace instances of NonNull::new(&mut x).expect("...") with NonNull::from_mut)
 - rust-lang/rust#163958 (only make `RustaceansAreAwesome` satisfy trait clauses)
 - rust-lang/rust#163960 (vexos: clear .bss from assembly)
 - rust-lang/rust#163974 (Condense AdtDef lang item checks into one match)
 - rust-lang/rust#163979 (Add `bf16` to arm features)
 - rust-lang/rust#163989 (Revert "compiletest: stream output of executor process when --no-capture is set")
 - rust-lang/rust#163995 (m68k-unknown-none-elf: Remove code model)

Failed merges:

 - rust-lang/rust#163832 (reject non-async coroutine closures as async callables)
 - rust-lang/rust#163972 (const-eval: ICE when we hit a non-const fn)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. T-libs Relevant to the library team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants