build_environment_struct and build_environment_api_key_struct in src/environments/builders.rs are serde_json::from_value(value).unwrap(). A document the engine cannot deserialise panics the caller instead of returning an error. The input is whatever the network delivered, so a misbehaving server, or anyone on the path of a plain-HTTP self-hosted deployment, can crash every process embedding the engine, and callers have no way to catch it short of catch_unwind.
In flagsmith-rust-client 3.1.1 that panic happened on the SDK's background refresh thread while it held the datastore mutex, which poisoned the lock and made every later flag read panic as well. Flagsmith/flagsmith-rust-client#62 fixes that on the client side by deserialising the document itself with an error return, so the client no longer calls these builders. Any other caller still gets the panic.
Proposed: return Result<Environment, serde_json::Error> and Result<EnvironmentAPIKey, serde_json::Error> from the two builders. That is a breaking change to the public API, so it wants a version bump and updates to the callers, the Rust client included. Happy to send a PR if this works.
build_environment_structandbuild_environment_api_key_structinsrc/environments/builders.rsareserde_json::from_value(value).unwrap(). A document the engine cannot deserialise panics the caller instead of returning an error. The input is whatever the network delivered, so a misbehaving server, or anyone on the path of a plain-HTTP self-hosted deployment, can crash every process embedding the engine, and callers have no way to catch it short ofcatch_unwind.In
flagsmith-rust-client3.1.1 that panic happened on the SDK's background refresh thread while it held the datastore mutex, which poisoned the lock and made every later flag read panic as well. Flagsmith/flagsmith-rust-client#62 fixes that on the client side by deserialising the document itself with an error return, so the client no longer calls these builders. Any other caller still gets the panic.Proposed: return
Result<Environment, serde_json::Error>andResult<EnvironmentAPIKey, serde_json::Error>from the two builders. That is a breaking change to the public API, so it wants a version bump and updates to the callers, the Rust client included. Happy to send a PR if this works.