Environment variable to disable `rust-toolchain.toml`
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 7k
- Forks
- 1.1k
- Avg merge
- 22h 40m
- Merged PRs (30d)
- 46
Description
Describe the problem you are trying to solve
In order to support VS Code's "workspace trust" feature in rust-analyzer (https://github.com/rust-analyzer/rust-analyzer/issues/9224), we'd like to disable rust-toolchain.toml support, since that allows arbitrary code execution.
Describe the solution you'd like
The easiest solution would be some environment variable that simply disables this toolchain file, but I'm open to alternatives.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing how rustup handles rust-toolchain.toml and review the linked rust-analyzer workspace-trust context. Define the environment-variable behavior for disabling that file, then verify that the resulting behavior addresses the arbitrary-code-execution concern with tests for enabled and disabled cases.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust, vscode
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100