Rollup of 6 pull requests - #160072
Closed
JonathanBrouwer wants to merge 20 commits into
Closed
Conversation
Coercing the fn item `bar` to a fn pointer while `Foo::value` holds the
associated-type projection `<<T as Func>::Ret as Id>::Assoc` used to ICE
during normalization ("maybe try to call `try_normalize_erasing_regions`
instead"). It now reports the ordinary `u32: Id` trait-bound error instead
of crashing.
The carets should ideally point to the path, not the entire attribute, but that's hard to achieve with the current code structure.
The carets already point to just the attribute path, which is what we want.
…, r=mati865 Avoid stale closure recovery state across statements Fixes rust-lang#159989 `current_closure` was cleared when starting a new expression through `parse_expr`, but statement expressions call `parse_expr_res` directly. This allowed closure recovery state from one statement to remain active while parsing the next statement. This pr clears `current_closure` when entering `parse_stmt_without_recovery`, matching the behavior of `parse_expr`. https://github.com/rust-lang/rust/blob/da2697d1d842f4faf83083115aab396f82829a3a/compiler/rustc_parse/src/parser/expr.rs#L55-L56 https://github.com/rust-lang/rust/blob/da2697d1d842f4faf83083115aab396f82829a3a/compiler/rustc_parse/src/parser/expr.rs#L63-L64
Add regression test for rust-lang#132767 Closes rust-lang#132767. Coercing a fn item to a fn pointer with an associated type projection used to ICE during normalization. now errors with E0277.
…est, r=GuillaumeGomez Update `browser-ui-test` version to `0.25.0` With this new version we should be able to finally add a regression test for [the "code copy" ](rust-lang#158137). r? ghost
Improve consistency of attribute error messages (part 2) A sequel to rust-lang#159755. r? @estebank
…-fn-turbofish, r=estebank Fix associated function suggestion for generic ADTs Fixes rust-lang#159813 r? @estebank
…g-subscriber-vulnerability, r=jieyouxu Update Rust crate tracing-subscriber to v0.3.23 [SECURITY] This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [tracing-subscriber](https://tokio.rs) ([source](https://redirect.github.com/tokio-rs/tracing)) | dependencies | patch | `0.3.22` → `0.3.23` | | [tracing-subscriber](https://tokio.rs) ([source](https://redirect.github.com/tokio-rs/tracing)) | dev-dependencies | patch | `0.3.22` → `0.3.23` | --- ### Tracing logging user input may result in poisoning logs with ANSI escape sequences [CVE-2025-58160](https://nvd.nist.gov/vuln/detail/CVE-2025-58160) / [GHSA-xwfj-jgwm-7wp5](https://redirect.github.com/advisories/GHSA-xwfj-jgwm-7wp5) <details> <summary>More information</summary> #### Details ##### Impact Previous versions of tracing-subscriber were vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to: - Manipulate terminal title bars - Clear screens or modify terminal display - Potentially mislead users through terminal manipulation In isolation, impact is minimal, however security issues have been found in terminal emulators that enabled an attacker to use ANSI escape sequences via logs to exploit vulnerabilities in the terminal emulator. ##### Patches `tracing-subscriber` version 0.3.20 fixes this vulnerability by escaping ANSI control characters in when writing events to destinations that may be printed to the terminal. ##### Workarounds Avoid printing logs to terminal emulators without escaping ANSI control sequences. ##### References https://www.packetlabs.net/posts/weaponizing-ansi-escape-sequences/ ##### Acknowledgments We would like to thank [zefr0x](http://github.com/zefr0x) who responsibly reported the issue at `security@tokio.rs`. If you believe you have found a security vulnerability in any tokio-rs project, please email us at `security@tokio.rs`. #### Severity - CVSS Score: 2.3 / 10 (Low) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N` #### References - [https://github.com/tokio-rs/tracing/security/advisories/GHSA-xwfj-jgwm-7wp5](https://redirect.github.com/tokio-rs/tracing/security/advisories/GHSA-xwfj-jgwm-7wp5) - [https://nvd.nist.gov/vuln/detail/CVE-2025-58160](https://nvd.nist.gov/vuln/detail/CVE-2025-58160) - [https://rustsec.org/advisories/RUSTSEC-2025-0055.html](https://rustsec.org/advisories/RUSTSEC-2025-0055.html) - [https://github.com/advisories/GHSA-xwfj-jgwm-7wp5](https://redirect.github.com/advisories/GHSA-xwfj-jgwm-7wp5) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-xwfj-jgwm-7wp5) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>tokio-rs/tracing (tracing-subscriber)</summary> ### [`v0.3.23`](https://redirect.github.com/tokio-rs/tracing/releases/tag/tracing-subscriber-0.3.23): tracing-subscriber 0.3.23 [Compare Source](https://redirect.github.com/tokio-rs/tracing/compare/tracing-subscriber-0.3.22...tracing-subscriber-0.3.23) ##### Fixed - Allow ansi sanitization to be disabled ([#&rust-lang#8203;3484]) [#&rust-lang#8203;3484]: https://redirect.github.com/tokio-rs/tracing/pull/3484 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/rust-lang/rust). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Contributor
Author
Contributor
Contributor
|
⌛ Trying commit 15142d2 with merge 8d65e0d… To cancel the try build, run the command Workflow: https://github.com/rust-lang/rust/actions/runs/30361860272 |
rust-bors Bot
pushed a commit
that referenced
this pull request
Jul 28, 2026
Rollup of 6 pull requests try-job: dist-various-1 try-job: test-various try-job: x86_64-gnu-aux try-job: x86_64-gnu-llvm-21-3 try-job: x86_64-msvc-1 try-job: aarch64-apple try-job: x86_64-mingw-1 try-job: i686-msvc-*
Contributor
Author
|
@bors try cancel |
Contributor
|
This pull request was unapproved due to being closed. |
Contributor
|
Try build cancelled. Cancelled workflows: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Successful merges:
try_normalize_erasing_regionsinstead #132767)browser-ui-testversion to0.25.0#160030 (Updatebrowser-ui-testversion to0.25.0)r? @ghost
Create a similar rollup