Tracking allocator: mark Spinlock::unlock() as unsafe and provide a safety contract (#2156)

This commit is contained in:
s0me0ne-unkn0wn
2023-11-05 13:51:36 +01:00
committed by GitHub
parent 0c39cf049e
commit c46a7dbb61
+7 -2
View File
@@ -72,8 +72,11 @@ impl<T> Spinlock<T> {
}
}
// SAFETY: It should be only called from the guard's destructor. Calling it explicitly while
// the guard is alive is undefined behavior, as it breaks the security contract of `Deref` and
// `DerefMut`, which implies that lock is held at the moment of dereferencing.
#[inline]
fn unlock(&self) {
unsafe fn unlock(&self) {
self.lock.store(false, Ordering::Release);
}
}
@@ -97,7 +100,9 @@ impl<T> DerefMut for SpinlockGuard<'_, T> {
impl<T> Drop for SpinlockGuard<'_, T> {
fn drop(&mut self) {
self.lock.unlock();
// SAFETY: Calling `unlock` is only safe when it's guaranteed no guard outlives the
// unlocking point; here, the guard is dropped, so it is safe.
unsafe { self.lock.unlock() }
}
}