cargo / bon / audit
cargo : bon @ 3.9.1
PE Patrick Elsen signed 2026-05-27 published 2026-05-27

Claims

has-binarieshas-build-exechas-fuzz-testshas-install-exechas-integration-testshas-property-testshas-unit-testsimpl-algorithmimpl-concurrencyimpl-cryptoimpl-datastructureimpl-interpreterimpl-jitimpl-parserimpl-protocolis-benignuses-concurrencyuses-cryptouses-environmentuses-execuses-filesystemuses-interpreteruses-jituses-networkuses-unsafe

Summary

bon 3.9.1 is the runtime companion to the bon-macros proc-macro builder generator; it exposes sealed typestate marker traits, collection-construction macros, and IDE completion stubs. The audit found no findings, no unsafe code, and no I/O of any kind.

Report

Subject

bon 3.9.1 is the runtime half of a builder-pattern code-generation library. It re-exports five proc-macro entry points (builder, bon, Builder, map, set) from the sibling crate bon-macros, which does all the heavy lifting. The runtime crate contributes: the IsSet/IsUnset sealed marker traits that back the typestate API (src/builder_state.rs); four declarative macros for collection construction with Into coercion (src/collections.rs); and a private module (src/__/) that holds IDE-completion stubs, error-message helpers, and a compile-time cfg-predicate evaluator. The public API is no-std-compatible via the alloc and std feature flags; the std feature is the default. Two experimental features (experimental-overwritable, experimental-generics-setters) and one stabilised legacy alias (experimental-getter) are present; all delegate to feature flags on bon-macros.

Methodology

Audit performed using openvet 0.6.0. All 570 lines across six source files (src/lib.rs, src/builder_state.rs, src/collections.rs, src/__/mod.rs, src/__/better_errors.rs, src/__/cfg_eval.rs, src/__/ide.rs) were read in full. Source surveys used ripgrep patterns from the audit runbook to check for unsafe blocks, FFI, network, filesystem, process execution, environment variable access, cryptographic operations, RNG, and concurrency primitives; all returned no matches. The published tarball was diffed against the VCS checkout (vcs/, SHA1 1f427d01048ae86c6d929ed1e7c18ec994b43227, repository path bon within https://github.com/elastio/bon). No build script is present.

Results

The diff between contents/ and vcs/ shows only the normalised Cargo.toml differing; all source files are byte-for-byte identical. No binary assets are present. The VCS directory does not contain a .git directory in the pre-loaded workspace, so git-level provenance was verified via the embedded .cargo_vcs_info.json commit SHA rather than by running git log.

The crate contains no unsafe blocks, no FFI declarations, no network or filesystem access, and no process execution at runtime or build time. Accordingly uses-unsafe=false, uses-network=false, uses-filesystem=false, uses-exec=false, uses-crypto=false, uses-environment=false, uses-concurrency=false, uses-jit=false, and uses-interpreter=false all hold. There is no binary crate, no build script, and no install script, so has-binaries=false, has-build-exec=false, and has-install-exec=false.

On the implementation side, the crate delegates parsing to bon-macros and does not itself implement a parser, algorithm, data structure, protocol, concurrency primitive, or cryptographic operation: impl-parser=false, impl-algorithm=false, impl-datastructure=false, impl-protocol=false, impl-concurrency=false, impl-crypto=false, impl-jit=false, and impl-interpreter=false.

Unit tests in src/collections.rs cover arr!, vec!, map!, and set! with both empty and non-empty cases (has-unit-tests=true). The tests/integration/ directory contains 202 annotated test functions across 32 files covering builder attributes, generics, cfg handling, and UI compile-failure expectations (has-integration-tests=true). No fuzz or property tests are present (has-fuzz-tests=false, has-property-tests=false).

No obfuscated code, base64-encoded payloads, telemetry, timing-dependent behaviour, or suspicious network endpoints were observed. is-benign=true.

No findings were raised. The code is straightforward and well-commented; the cfg_eval.rs module in particular documents its non-obvious declarative macro technique with an inline explanation.

Conclusion

bon 3.9.1 is a thin runtime companion to bon-macros. Its own code carries no safety hazards: no unsafe blocks, no I/O, and no build-time execution. The typestate machinery in builder_state.rs is sound safe Rust. The only substantive logic is the cfg-predicate evaluator, which is purely declarative and thoroughly documented.

Findings

No findings.

Annotations(4)

src/__/cfg_eval.rs

Implements the __eval_cfg_callback, __eval_cfg_callback_true, and __eval_cfg_callback_false declarative macros. These cooperate with the bon-macros proc-macro to evaluate #[cfg(...)] predicates at compile time. The technique uses conditional use aliases (#[cfg(...)] use ... as $pred_id) so the compiler resolves the alias to either the _true or _false variant, which then accumulates boolean results for the proc-macro to read back.

The macro is purely declarative, no I/O or unsafe. The algorithm is clearly documented inline. Justifies is-benign=true.

src/builder_state.rs

Defines the IsSet and IsUnset marker traits used by the typestate pattern in generated builder code. Both traits are sealed via a private Sealed supertrait. The implementation is entirely safe Rust: no unsafe blocks, no raw pointers, no transmutes. The rustversion::attr attribute attaches human-readable diagnostic::on_unimplemented messages on compilers >= 1.78.0 to improve error output when a member has not been set.

Justifies uses-unsafe=false.

src/collections.rs

Implements four declarative macros: vec! (alloc-gated), arr!, map! (proc-macro re-export via bon-macros), and set! (proc-macro re-export). Each wraps standard collection constructors and applies Into::into() on each element, allowing callers to pass heterogeneous items that coerce to the target element type. The module contains five unit tests covering empty and non-empty cases for arr!, vec!, map!, and set!.

No unsafe code, no I/O. Justifies has-unit-tests=true.

src/lib.rs

The library root re-exports five macros from bon-macros (bon, builder, map, set, Builder) and declares three internal modules: collections (declarative macros for vec!, arr!, map!, set!), __ (private implementation details re-exported for generated code), and builder_state (the IsSet/IsUnset marker traits).

No unsafe blocks, no FFI, no network or filesystem access, and no build script exist in this crate. Justifies uses-unsafe=false, uses-network=false, uses-filesystem=false, has-build-exec=false, is-benign=true.