Bump findshlibs to 0.7.0 #211
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
findshlibs 0.5.0 has a serious defect in
SharedLibrary::id
, where ituses file sizes and offsets when examining the PT_NOTE sections of an
ELF binary instead of the memory size/offset fields. This issue was
corrected by gimli-rs/findshlibs@046a431, but was released along with a
couple of semver breaking changes so it needs a bump in Cargo.toml to be
picked up.
This has a fairly major impact on projects where you have
with_debug_meta
enabled,as it can lead to all sorts of issues, ranging from at best corrupted crash uploads reaching
Sentry, to SEGFAULTs when a thread panics, to wild UB as we try and read from totally
random memory addresses.
We have tested this in production by patching
findshlibs
with Cargo's patch function.I'd suggest pushing out a 0.18.1 release for this if possible, given the impact of the above.