You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The threat model for Rust is that the code written by the programmer is non-adversarial. So having some #[doc(hidden)] items is fine.
However, LLMs still flag this in an audit, and it's easier to tighten things up once and for all than to explain to users that this is actually fine every time.
Prior to this PR, __fearless_simd_kernel_impl! accepted both the level token and the corresponding target feature string as arguments and trusts them. So one could theoretically use this private-ish, low-level and doc-hidden API (which can't be fully private due to use in macros which instantiate outside this crate) to construct a function that accepts e.g. an SSE2 token but emits an AVX-512 feature string.
Rust is not a sandbox to defend against adversarial code, unlike e.g. JavaScript running in the browser, so if someone went through this much trouble to get a soundness issue, they probably deserve it. But this PR fixes this loophole regardless.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The threat model for Rust is that the code written by the programmer is non-adversarial. So having some
#[doc(hidden)]items is fine.However, LLMs still flag this in an audit, and it's easier to tighten things up once and for all than to explain to users that this is actually fine every time.