oxidecomputer / oxidecomputer/sprockets

attestation protocol is not cancel safe

Open
#73 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
10
Forks
2
Avg merge
8d 20h
Merged PRs (30d)
1

Description

i took a shortcut implementing the attestation protocol and used read_exact. This function is not cancel safe. Probably worth the effort to just use the cancel safe read function and do the extra work to handle io::ErrorKind::Interrupted.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the attestation protocol implementation and find its use of Tokio's read_exact. Read the cancel-safety documentation for read and inspect existing protocol tests, if present; done means the protocol uses cancel-safe reads while handling io::ErrorKind::Interrupted correctly.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.