On Wed, Aug 17, 2022 at 10:34 PM Kees Cook <keescook@xxxxxxxxxxxx> wrote: > > Gotcha -- it's for the implicit situations (e.g. -C overflow-checks=on), Yeah, exactly. > nothing is expected to explicitly call the Rust panic handler? If by explicitly you mean calling `panic!()`, then in the `kernel` crate in the v9 patches there is none. Though we may want to call it in the future (we have 4 instances in the full code not submitted here, e.g. for mismatching an independent lock guard with its owner). They can be avoided depending on how we want the design to be and, I guess, what the "Rust panic" policy will finally be (i.e. `BUG()` or something softer). Outside the `kernel` crate, there are also instances in proc macros and Rust hostprogs/scripts (compilation-time in the host), in the `alloc` crate (compiled-out) and in the `compiler_builtins` crate (for e.g. `u128` support that eventually we would like to not see compiled-in). Cheers, Miguel