Rust Sanitizers Miri

mohitmishra786/low-level-dev-skills/skills/rust/rust-sanitizers-miri

作者 mohitmishra786bdc58472fa9f无许可证253 个星标收录于 2026年10月9日更新于 2026年10月9日仓库3个月前更新

Rust sanitizers and Miri skill for memory safety validation. Use when running AddressSanitizer or ThreadSanitizer on Rust code, interpreting sanitizer reports, using Miri to detect undefined behaviour in unsafe Rust, or validating unsafe code correctness. Activates on queries about Rust ASan, Rust TSan, Miri, RUSTFLAGS sanitize, cargo miri, unsafe Rust UB, or interpreting Rust sanitizer output.

AI 生成的概览

指导在 Rust 中运行 ASan、TSan、MSan、UBSan 等 sanitizer 以及 Miri,以检测内存安全问题和未定义行为。

功能
提供通过 RUSTFLAGS 在 Rust 代码上运行 AddressSanitizer、ThreadSanitizer、MemorySanitizer 和 UndefinedBehaviorSanitizer 的说明,以及在 Rust 测试和二进制程序上运行 Miri 的方法。它讲解如何解读 sanitizer 报告,列出 Rust 特有的错误模式,说明 MIRIFLAGS 选项,并给出 CI 集成示例。此外还附带一份 Miri 未定义行为模式的参考文件。
适用场景
适用于验证 Rust 代码(尤其是不安全代码)的内存安全或未定义行为,或运行并解读 sanitizer 与 Miri 输出。也适合在 CI 中配置这些检查。
运行要求
需要 Rust 工具链及 nightly(rustup)、rust-src 组件和 miri 组件;所选 sanitizer 需平台支持(多为 Linux,ASan 也支持 macOS)。文中还提到可选工具:cargo-sanitize、配合 Docker 的 cross。该技能不附带脚本,仅为说明文档。

Rust Sanitizers and Miri

Purpose

Guide agents through runtime safety validation for Rust: ASan/TSan/MSan/UBSan via RUSTFLAGS, Miri for compile-time UB detection in unsafe code, and interpreting sanitizer reports.

Triggers

  • "How do I run AddressSanitizer on Rust code?"
  • "How do I use Miri to check my unsafe Rust?"
  • "How do I run ThreadSanitizer on a Rust program?"
  • "My unsafe Rust might have UB — how do I detect it?"
  • "How do I interpret a Rust ASan report?"
  • "Can I run Rust sanitizers on stable?"

Workflow

1. Sanitizers in Rust (nightly required)

Rust sanitizers require nightly and a compatible platform:

bash
# Install nightlyrustup toolchain install nightlyrustup component add rust-src --toolchain nightly
# AddressSanitizer (Linux, macOS)RUSTFLAGS="-Z sanitizer=address" \    cargo +nightly test -Zbuild-std \    --target x86_64-unknown-linux-gnu
# ThreadSanitizer (Linux)RUSTFLAGS="-Z sanitizer=thread" \    cargo +nightly test -Zbuild-std \    --target x86_64-unknown-linux-gnu
# MemorySanitizer (Linux, requires all-instrumented build)RUSTFLAGS="-Z sanitizer=memory -Zsanitizer-memory-track-origins" \    cargo +nightly test -Zbuild-std \    --target x86_64-unknown-linux-gnu
# UndefinedBehaviorSanitizerRUSTFLAGS="-Z sanitizer=undefined" \    cargo +nightly test -Zbuild-std \    --target x86_64-unknown-linux-gnu

-Zbuild-std rebuilds the standard library with the sanitizer, which is necessary for accurate results.

2. Stable sanitizer workaround

For stable Rust, use the cross tool with a Docker image that has sanitizers pre-configured, or run cargo test inside a Docker container with a nightly image.

Alternatively, for simpler UB checking without nightly:

bash
# cargo-sanitize (wrapper)cargo install cargo-sanitizecargo sanitize address

3. Interpreting ASan output in Rust

==12345==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x602000000050READ of size 4 at 0x602000000050 thread T0    #0 0x401234 in myapp::module::function /src/main.rs:15    #1 0x401567 in myapp::main /src/main.rs:42
0x602000000050 is located 0 bytes after a 40-byte region allocated at:    #0 0x... in alloc::alloc::alloc ...    #1 0x... in myapp::create_buffer /src/main.rs:10

Rust-specific patterns:

ASan errorLikely Rust cause
heap-buffer-overflowunsafe slice access past bounds
use-after-freeunsafe pointer use after Vec realloc
stack-use-after-returnReturning reference to local
heap-use-after-freeUse after drop() or Box::from_raw

4. Miri — interpreter for undefined behaviour

Miri interprets Rust MIR and detects UB that sanitizers might miss:

bash
# Install Miri (requires nightly)rustup +nightly component add miri
# Run tests under Miricargo +nightly miri test
# Run specific testcargo +nightly miri test test_name
# Run a binary under Miricargo +nightly miri run
# Run with Stacked Borrows model (strict aliasing)MIRIFLAGS="-Zmiri-strict-provenance" cargo +nightly miri test
# Disable isolation (allow file I/O, randomness)MIRIFLAGS="-Zmiri-disable-isolation" cargo +nightly miri test

5. What Miri detects

rust
// 1. Dangling pointer useunsafe {    let x = Box::new(42);    let ptr = Box::into_raw(x);    let _ = Box::from_raw(ptr);  // drop    let _val = *ptr;  // Miri: use of dangling pointer}
// 2. Invalid enum discriminantlet x: u8 = 3;let e = unsafe { std::mem::transmute::<u8, MyEnum>(x) };// Miri: enum value has invalid tag
// 3. Uninitialized memory readlet uninit: MaybeUninit<u32> = MaybeUninit::uninit();let val = unsafe { uninit.assume_init() };  // Miri: reading uninitialized bytes
// 4. Stacked borrows violationlet mut x = 5u32;let ptr = &mut x as *mut u32;let _ref = &x;  // shared referenceunsafe { *ptr = 10; }  // Miri: mutable access while shared borrow exists
// 5. Data races (with threads)// Miri simulates sequential execution and detects races via Stacked Borrows

6. ThreadSanitizer for Rust

bash
RUSTFLAGS="-Z sanitizer=thread" \    RUST_TEST_THREADS=8 \    cargo +nightly test -Zbuild-std \    --target x86_64-unknown-linux-gnu 2>&1 | head -50

TSan output:

WARNING: ThreadSanitizer: data race (pid=12345)  Write of size 4 at 0x7f... by thread T2 (mutexes: write M1):    #0 myapp::counter::increment src/counter.rs:10  Previous read of size 4 at 0x7f... by thread T1:    #0 myapp::counter::get src/counter.rs:5

7. Miri configuration via MIRIFLAGS

FlagEffect
-Zmiri-disable-isolationAllow I/O, clock, randomness
-Zmiri-strict-provenanceStrict pointer provenance (stricter than LLVM)
-Zmiri-symbolic-alignment-checkStricter alignment checking
-Zmiri-check-number-validityCheck float/int validity
-Zmiri-num-cpus=NSimulate N CPUs (for concurrency)
-Zmiri-seed=NSeed for random scheduling
-Zmiri-ignore-leaksSuppress memory leak errors
-Zmiri-tag-raw-pointersTrack raw pointer provenance

8. CI integration

yaml
# GitHub Actions- name: Miri  run: |    rustup toolchain install nightly    rustup +nightly component add miri    cargo +nightly miri test  env:    MIRIFLAGS: "-Zmiri-disable-isolation"
- name: ASan (nightly)  run: |    rustup component add rust-src --toolchain nightly    RUSTFLAGS="-Z sanitizer=address" \    cargo +nightly test -Zbuild-std \    --target x86_64-unknown-linux-gnu

Related skills

  • Use skills/rust/rust-debugging for GDB/LLDB debugging of Rust panics
  • Use skills/runtimes/sanitizers for C/C++ sanitizer usage and comparison
  • Use skills/rust/rust-unsafe for unsafe Rust patterns and review checklist
  • Use skills/runtimes/fuzzing to generate inputs that trigger sanitizer errors

来源与署名

来源:mohitmishra786/low-level-dev-skills位于skills/rust/rust-sanitizers-miri提交bdc5847

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架