GothenburgBitFactory / GothenburgBitFactory/taskwarrior

RUSTSEC-2021-0124: Data race when sending and receiving after closing a `oneshot` channel

Open
#2,794 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C++
Stars
6.1k
Forks
423
Avg merge
1d 19h
Merged PRs (30d)
11

Description

> Data race when sending and receiving after closing a `oneshot` channel

| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `tokio` |
| Version | `0.2.25` |
| URL | [https://github.com/tokio-rs/tokio/issues/4225](https://github.com/tokio-rs/tokio/issues/4225) |
| Date | 2021-11-16 |
| Patched versions | `>=1.8.4, <1.9.0,>=1.13.1` |
| Unaffected versions | `<0.1.14` |

If a `tokio::sync::oneshot` channel is closed (via the
[`oneshot::Receiver::close`] method), a data race may occur if the
`oneshot::Sender::send` method is called while the corresponding
`oneshot::Receiver` is `await`ed or calling `try_recv`.

When these methods are called concurrently on a closed channel, the two halves
of the channel can concurrently access a shared memory location, resulting in a
data race. This has been observed to [cause memory corruption][corruption].

Note that the race only occurs when **both** halves of the channel are used
after the `Receiver` half has called `close`. Code where `close` is not used, or where the
`Receiver` is not `await`ed and `try_recv` is not called after calling `close`,
is not affected.

See [tokio#4225][issue] for more details.

[corruption]: https://github.com/tokio-rs/tokio/issues/4225#issuecomment-967434847
[issue]: https://github.com/tokio-rs/tokio/issues/4225
[`oneshot::Receiver::close`]: https://docs.rs/tokio/1.14.0/tokio/sync/oneshot/struct.Receiver.html#method.close

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2021-0124.html) for additional details.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.