AldaronLau / AldaronLau/shared_cell
Yet Another Soundness Issue
- 主要言語
- Rust
- スター
- 3
- フォーク
- 0
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
Current API relies on single threaded `async` task groups to keep there being only one exclusive ref.
This can be broken if someone were to fork the `scoped_tls_hkt` crate to make it async.
Essentially setting the `&mut SharedCell` to a scoped static, `.awaiting` inside the async closure passed to `FOO.set()` and accessing the scoped tls within a the `SharedCell::with()` in order to call `.with()` again reëntrantly.
I think this leaves one API possibility left for using async to guarantee a sound panic-free safely mutably borrowable cell (the goal of this crate).
```rust
async fn task(cx: &mut SharedCell) {
// Closure moves to future, pinned and set atomic ref then yield
cx.with(|cell| cell += 1).await;
}
// Future holding on to task group and
struct With {
task_group: &TaskGroup,
closure: Option<&mut dyn FnOnce(T)>,
// requires a separate type for the future to hold self-reference
...: impl FnOnce(T),
}
struct TaskGroup {
with: AtomicPtr,
}
```
While yielding can consume and run the "with" closure. May be able to simplify too
コントリビューションガイド
評価
この issue はまだ評価されていません。