- Reported
-
- Issued
-
- Package
-
rutie
(crates.io)
- Type
-
INFO
Unsound
- Categories
-
- Keywords
-
#from-raw-parts
- References
-
- Patched
-
>=0.10.3, <0.11.0
>=0.11.3, <0.12.0
>=0.12.1, <0.13.0
>=0.13.1, <0.14.0
>=0.14.1
Description
parse_arguments is safe. It takes arguments: *const AnyObject and argc, and calls slice::from_raw_parts(arguments, argc as usize).
It does not check that arguments is non-null and aligned, or that argc elements are initialized. Safe Rust can pass a null pointer or a length past the allocation. The maintainer confirmed this on 2026-10-03, including a debug abort on Rust 1.78+ when Ruby calls an arity -1 method (to_s via format, puts, or Array#join) with a NULL argv and argc of 0.
Advisory available under CC0-1.0
license.