AldaronLau / AldaronLau/shared_cell

Yet Another Soundness Issue

Aperta
#1 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Rust
Stelle
3
Fork
0
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Current API relies on single threaded `async` task groups to keep there being only one exclusive ref.

This can be broken if someone were to fork the `scoped_tls_hkt` crate to make it async.

Essentially setting the `&mut SharedCell` to a scoped static, `.awaiting` inside the async closure passed to `FOO.set()` and accessing the scoped tls within a the `SharedCell::with()` in order to call `.with()` again reëntrantly.

I think this leaves one API possibility left for using async to guarantee a sound panic-free safely mutably borrowable cell (the goal of this crate).

```rust
async fn task(cx: &mut SharedCell) {
// Closure moves to future, pinned and set atomic ref then yield
cx.with(|cell| cell += 1).await;
}

// Future holding on to task group and
struct With {
task_group: &TaskGroup,
closure: Option<&mut dyn FnOnce(T)>,
// requires a separate type for the future to hold self-reference
...: impl FnOnce(T),
}

struct TaskGroup {
with: AtomicPtr,
}
```

While yielding can consume and run the "with" closure. May be able to simplify too

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.