Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Soundness issues for futures-intrusive #1175

Open
2 tasks
jonasbb opened this issue Feb 3, 2022 · 2 comments
Open
2 tasks

Soundness issues for futures-intrusive #1175

jonasbb opened this issue Feb 3, 2022 · 2 comments
Labels
Unmaintained Informational / Unmaintained Unsound Informational / Unsound

Comments

@jonasbb
Copy link
Contributor

jonasbb commented Feb 3, 2022

I stumbled over two soundness issues of futures-intrusive which are currently unfixed.

@pinkforest
Copy link
Contributor

pinkforest commented Aug 13, 2022

@Matthias247 would you want / prefer for us to file any advisories on any of these soundness issues potentially ?

Reading from responses "it shouldn't have caused any issues in practice" seems to indicate some disagreement re: as whether there is / are any issue/s on we should file any advisories on ?

@alexmoon I notice you may have fixed something - do you have any opinion either way? Thanks

If there are any proven soundness issues we should file advisory on

Then actionable fix should be there e.g. new crates.io release if any to point any users to potentially.

Also -

We don't have any actionable advisory here atm in a form of a pull request yet.

Cheers

@pinkforest pinkforest added Unsound Informational / Unsound Unmaintained Informational / Unmaintained labels Aug 14, 2022
@pinkforest
Copy link
Contributor

I also pinged about maintenance status here: Matthias247/futures-intrusive#65

This crate has 2,304,739 downloads with ~8k downloads a day - last release was a year ago with open questions re: soundness.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Unmaintained Informational / Unmaintained Unsound Informational / Unsound
Projects
None yet
Development

No branches or pull requests

2 participants