Originally filed by @jessa0 as iqlusioninc/crates#782:
It seems the Zeroize implementation for Option<T> where T: Zeroize has language-level UB here:
|
volatile_set(self as *mut _ as *mut u8, 0, mem::size_of::<Self>()); |
I believe, as a repr(Rust) enum, the memory layout and set of valid bit-patterns for Option is not defined, and that setting an enum's storage to an invalid bit-pattern while a reference to it exists, even if the value is never read, is instant language-level UB. The documentation for Option does mention guarantees for several special cases, but the None case still isn't defined for many of those cases, and the Zeroize implementation is more generic than that. Here's an example of a miri error in such a situation, that scottmcm came up with on URLO here.
Originally filed by @jessa0 as iqlusioninc/crates#782: