AldaronLau / AldaronLau/shared_cell

Yet Another Soundness Issue

Ouverte
#1 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
Rust
Étoiles
3
Forks
0
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

Current API relies on single threaded `async` task groups to keep there being only one exclusive ref.

This can be broken if someone were to fork the `scoped_tls_hkt` crate to make it async.

Essentially setting the `&mut SharedCell` to a scoped static, `.awaiting` inside the async closure passed to `FOO.set()` and accessing the scoped tls within a the `SharedCell::with()` in order to call `.with()` again reëntrantly.

I think this leaves one API possibility left for using async to guarantee a sound panic-free safely mutably borrowable cell (the goal of this crate).

```rust
async fn task(cx: &mut SharedCell) {
// Closure moves to future, pinned and set atomic ref then yield
cx.with(|cell| cell += 1).await;
}

// Future holding on to task group and
struct With {
task_group: &TaskGroup,
closure: Option<&mut dyn FnOnce(T)>,
// requires a separate type for the future to hold self-reference
...: impl FnOnce(T),
}

struct TaskGroup {
with: AtomicPtr,
}
```

While yielding can consume and run the "with" closure. May be able to simplify too

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.