Skip to content

zeroize 1.9.0: the optimization_barrier non-asm fallback reads possibly uninitialized memory as u8 (UB from safe code) #1549

Description

@ajit-zer07

On targets without stable asm! (for example wasm32-unknown-unknown), and under
Miri, optimization_barrier<T: ?Sized>(val: &T) (src/barrier.rs:92-100) calls
custom_black_box(ptr.cast::<u8>()), which does core::ptr::read_volatile(p) with
p: *const u8. If byte 0 of *val is uninitialized, producing that u8 is
Undefined Behaviour. Byte 0 is uninitialized for padding, for MaybeUninit, or for the
payload bytes of a niche-encoded enum after a typed write.

optimization_barrier is a safe pub fn, so safe code can trigger this, e.g.
zeroize::optimization_barrier(&core::mem::MaybeUninit::<u8>::uninit()).

We see that #1535 removed the internal callers, but barrier.rs on master is unchanged.

Suggested fix: read_volatile(p.cast::<core::mem::MaybeUninit<u8>>()), or drop
custom_black_box and rely on core::hint::black_box alone.

Could this be included in 1.9.1?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions