GraphiteEditor / GraphiteEditor/Graphite
Context varargs can smuggle graph-runtime references past the borrow tree's lifetime discipline
- Lingua principale
- Rust
- Stelle
- 27.2k
- Fork
- 1.3k
- Merge medio
- 20h 5m
- PR unite (30g)
- 57
Descrizione
Reported by @TrueDoctor following the rank polymorphism PR (#4335). Three existing mechanisms combine into an unsound API surface:
1. The borrow tree launders lifetimes: `NodeContainer` derefs `*const TypeErasedNode<'static>` to `&'static`, so references handed out inside the graph (the `&PlatformEditorApi` scope wire, `&WgpuExecutor`, or any reference to node-owned state) are typed `'static` but actually live only until the next graph recompilation deallocates their owner.
2. `OwnedContextImpl::with_vararg` accepts any `Box`. Its `'static` bound cannot distinguish real ownership from a laundered reference, so safe code in any node can store such a reference into a context. #4335 made this channel idiomatic (render boundary config, per-item lambda rows).
3. Contexts escape the graph: the Monitor node snapshots `IORecord { input: Context, output }` into an `Arc` that the editor introspects and can retain across recompiles.
Combined: a node stores a laundered reference as a vararg, a Monitor captures the context, the graph recompiles and frees the referent, and the editor reads freed memory through entirely safe code (`vararg()` + `downcast_ref`). A vararg with interior mutability would similarly let context readers mutate graph-owned state as a covert return channel.
All current `with_vararg` callers box owned data, so no UB exists in the code today. But the risk remains for the API permitting it silently.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Direzione di ricerca
Start by tracing OwnedContextImpl::with_vararg, NodeContainer's lifetime handling, and the Monitor node's IORecord snapshot path, then review the rank polymorphism changes in #4335. Done means the context and vararg APIs no longer allow graph-runtime references to escape their valid lifetime, including across graph recompilation, without weakening safe-code guarantees.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- rust
- Ambito
- backend-api-design
- Tipo di issue
- Bug
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Tranquilla
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 25/100