feat(rust/fe-c): Catch RUSTSEC-2023-0016 (partial_sort) — through-catches spatial OOB
partial_sort 0.1.1 validates its `last` argument with a debug_assert!, elided in
optimized/no-debug-assert builds, so partial_sort(v, last, ..) with last > v.len()
walks its get_unchecked reads past the buffer (a read-only out-of-bounds per the
advisory, until the library's own bounds-checked write panics).
This is the first through-catches / case-elides corpus entry on a real SPATIAL
OOB (the heap analog of through-safe-ref): through checks the safe-reference
reads and aborts OutOfBounds at the first out-of-bounds element, naming the Vec
buffer (I10); case elides those safe derefs (the documented both-modes elision),
so fe-c does not catch the read-only over-read and the library's own
bounds-checked v.swap panics. The assert is asymmetric: through=OutOfBounds,
case=no fe-c-violation.
The fixture's dev profile sets debug-assertions=false + opt-level=3 — the only
shape the CVE manifests in, and it inlines core's get_unchecked reborrow into
partial_sort's MIR where the safe-deref check sees it. No new driver work.
Acceptance: fe-c-partial-sort-0016 (through aborts OutOfBounds naming the buffer,
case elides with no fe-c-violation); all 27 fe-c checks green. Ninth real CVE.
Signed-off-by: Niclas Overby <niclas@overby.me>