cargo / axum-core / audit
cargo : axum-core @ 0.5.6
PE Patrick Elsen signed 2026-05-27 published 2026-05-27

Claims

has-binarieshas-build-exechas-fuzz-testshas-install-exechas-integration-testshas-property-testshas-unit-testsimpl-algorithmimpl-concurrencyimpl-cryptoimpl-datastructureimpl-interpreterimpl-jitimpl-parserimpl-protocolis-benignuses-concurrencyuses-cryptouses-environmentuses-execuses-filesystemuses-interpreteruses-jituses-networkuses-unsafe

Summary

axum-core 0.5.6 is the foundational trait layer for the axum web framework, defining FromRequest, IntoResponse, Body, and DefaultBodyLimit. The crate declares unsafe_code = "forbid", contains no I/O, no build-time execution, and no binary artifacts. No findings were raised.

Report

Subject

axum-core 0.5.6 is the foundational layer of the axum web framework, extracted into its own crate so that library authors can implement FromRequest, FromRequestParts, and IntoResponse without depending on the full axum crate. It defines the core trait hierarchy (FromRequestParts, FromRequest, IntoResponse, IntoResponseParts), the Body type that wraps an unsync boxed body, the DefaultBodyLimit Tower layer and middleware, request extension helpers (RequestExt, RequestPartsExt), a small set of standard extractor impls for primitive types (Bytes, String, HeaderMap, etc.), and the macro infrastructure (__define_rejection!, __composite_rejection!) used by axum to declare rejection types. The crate declares unsafe_code = "forbid" and is entirely safe Rust.

Methodology

The published crate contents were compared against the upstream Git repository at the commit recorded in .cargo_vcs_info.json using diff -rq. All 18 source files (~3780 LOC total) were read in full. Surveys were run for unsafe, FFI, network, filesystem, process, environment, crypto, RNG, and concurrency patterns using grep. The manifest files Cargo.toml and Cargo.toml.orig were read in full. The CHANGELOG and README were read. The VCS checkout in vcs/ was confirmed present and the diff against published contents showed only the expected Cargo normalization differences.

Tools used: openvet 0.6.0, diff, grep.

Results

The diff between the published crate and the VCS checkout at the pinned commit shows only Cargo.toml normalization and the expected cargo-generated sidecar files (Cargo.toml.orig, Cargo.lock, .cargo_vcs_info.json). All source files are byte-for-byte identical between the published crate and the repository. No unexplained files are present.

The crate declares [lints.rust] unsafe_code = "forbid". A full-codebase grep confirms no unsafe keyword appears anywhere in the source, justifying uses-unsafe = false. There is no build.rs and the crate is not a proc macro, justifying has-build-exec = false and has-install-exec = false. No binary artifacts are present (has-binaries = false).

No network I/O, filesystem access, process execution, environment variable reads, or cryptographic operations appear anywhere in the source, justifying uses-network = false, uses-filesystem = false, uses-exec = false, uses-environment = false, uses-crypto = false. The crate imports no async runtime and spawns no threads; it exposes async trait methods that callers drive via their own executor. This justifies uses-concurrency = false. No JIT, interpreter, or scripting engine is used or implemented, justifying uses-jit = false, uses-interpreter = false, impl-jit = false, impl-interpreter = false.

The crate does not implement cryptographic operations (impl-crypto = false), does not implement a parser (impl-parser = false), does not define new data structures or algorithms beyond straightforward newtype wrappers (impl-datastructure = false, impl-algorithm = false), does not implement a protocol (impl-protocol = false), and does not implement concurrency primitives (impl-concurrency = false).

Unit tests are present inline in multiple source files (13 test functions, justifying has-unit-tests); no integration, fuzz, or property tests are part of this crate (has-integration-tests = false, has-fuzz-tests = false, has-property-tests = false). The test coverage spans the main extractor impls and the rejection macro machinery.

No issues were found warranting a finding. The crate has no malicious or suspicious code (is-benign = true).

Conclusion

All source files matched the upstream repository at the pinned commit. The crate contains no unsafe code, no I/O, and no build-time execution. The public API consists of trait definitions, newtype wrappers, and macro-generated boilerplate; the logic in each file is straightforward. No findings were raised.

Findings

No findings.

Annotations(3)

src/body.rs

body.rs contains no unsafe code. The try_downcast function uses std::any::Any::downcast_mut on an Option wrapping the value, which is entirely safe. The SyncWrapper usage justifies uses-unsafe = false. The file contains one unit test (test_try_downcast) for the downcast helper.

src/extract/default_body_limit.rs

The default body limit is set to 2 MB (2_097_152 bytes) when no explicit limit is configured. The limit is stored in request extensions and enforced by http_body_util::Limited. This is the primary defence against unbounded request body buffering for Bytes, String, and similar extractors.

src/lib.rs

The crate-level attributes include unsafe_code = "forbid" in the lints table, which the compiler enforces. No unsafe keyword appears anywhere in the source, justifying uses-unsafe = false. No build.rs is present and the crate is not a proc macro, justifying has-build-exec = false and has-install-exec = false.