Sitelet https://github.com/argotorg/fe/pull/1703
Skip to content

Feat/std calldata array view - #1703

Open
cburgdorf wants to merge 3 commits into
masterfrom
feat/std-calldata-array-view
Open

cburgdorf wants to merge 3 commits into
masterfrom
feat/std-calldata-array-view

Conversation

@cburgdorf

Copy link
Copy Markdown
Collaborator

Added std::abi::ArrayView, a lazy view of a Solidity ABI T[] over calldata or any other ByteInput, created with CallData::array_view or decode_array_view_at. It validates offsets and lengths like a Solidity T[] calldata parameter and decodes elements one at a time with get, with zero-copy bytes_at/string_at and nested array_at accessors, so raw-selector recv arms can read large arrays without decoding them into memory. For hand-written decoders, heads_pos, head_word and unchecked_element_pos expose the raw element heads and tail positions without validating element tails.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T18:52:27.979314Z ff79653 New commits
🔒 Security Review ✅ Completed 2026-10-07T18:52:18.685770Z ff79653 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 02cb8d67e4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ingots/std/src/abi/array_view.fe Outdated
@cburgdorf
cburgdorf force-pushed the feat/std-calldata-array-view branch from 02cb8d6 to 1fe7c4e Compare October 2, 2026 15:38
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1fe7c4eb27

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ingots/std/src/abi/array_view.fe Outdated
@cburgdorf
cburgdorf force-pushed the feat/std-calldata-array-view branch from 1fe7c4e to 662a593 Compare October 2, 2026 17:04
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@cburgdorf
cburgdorf force-pushed the feat/std-calldata-array-view branch from 662a593 to cb83f00 Compare October 2, 2026 18:00
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@cburgdorf
cburgdorf requested a review from sbillig October 3, 2026 07:43
`std::abi::ArrayView<I, T>` views a Solidity ABI `T[]` inside any
`ByteInput` without copying it to memory. Creating the view (via
`CallData::array_view` or `decode_array_view_at`) performs the checks
solc applies to a `T[] calldata` parameter: head word, length word and
all element heads within the input, overflow-safe for any word. `get`
decodes a single element with the regular Solidity decoder (dirty-bit
validation, Panic(0x32) on out-of-range index), `bytes_at`/`string_at`
return zero-copy views of dynamic elements, `array_at` returns a nested
view, and `element_pos` exposes the validated position of an element
for struct field access.
Hand-written decoders that mirror assembly (e.g. Seaport's conduit
reading `heads + calldataload(heads + i * 32)`) need the element heads
position and unchecked tail positions. Add `ArrayView::heads_pos`,
`head_word` and `unchecked_element_pos`, which skip the tail validation
of `element_pos` and are documented as only safe when the caller
validates the element itself or reads past the end as zeros.
@cburgdorf
cburgdorf force-pushed the feat/std-calldata-array-view branch from cb83f00 to d79f2e9 Compare October 4, 2026 22:16

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d79f2e96f8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ingots/std/src/abi/array_view.fe Outdated
let input_len = input.len()
let head_at = checked_tail<Sol>(base, head_pos)
checked_frame_end<Sol>(head_at, 32, input_len)
let tail_at = checked_tail<Sol>(base, input.word_at(head_at))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject oversized array offsets explicitly

decode_array_view_at accepts an offset of 2**64 or greater whenever a custom ByteInput reports a sufficiently large (for example, sparse or virtual) frame, because checked_tail only checks u256 addition overflow and checked_frame_end only compares against input_len. This contradicts the documented Solidity-compatible rejection of such offset words and differs from the explicit 64-bit limit applied to len; validate the loaded offset before computing tail_at.

Useful? React with 👍 / 👎.

decode_array_view_at and ArrayView::element_pos only bounded offset words
by the input frame. That rejects offsets of 2**64 or more for calldata,
but a ByteInput that reports a longer frame (a sparse or virtual input)
accepted them, unlike Solidity. Reject them explicitly, as the length
word already is.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ff7965389d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

#[arithmetic(unchecked)]
pub fn bytes_at(self, _ index: u256) -> BytesView<I> {
self.check_index(index)
decode_bytes_view_at(self.input, base: self.elems, head_pos: index * 32)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate oversized element offsets in every accessor

When I is a sparse or virtual ByteInput whose length exceeds 2**64, a Bytes[] element head containing 2**64 passes array construction, and this call forwards it to decode_bytes_view_at, which checks only arithmetic overflow and input bounds; bytes_at therefore accepts an offset Solidity rejects. Although the current element_pos now calls checked_offset, bytes_at, string_at, and get for dynamic elements bypass that validation, producing accessor-dependent results; apply the same offset limit before each dynamic decoding path.

Useful? React with 👍 / 👎.

#[arithmetic(unchecked)]
pub fn bytes_at(self, _ index: u256) -> BytesView<I> {
self.check_index(index)
decode_bytes_view_at(self.input, base: self.elems, head_pos: index * 32)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject oversized dynamic element lengths

When a sparse or virtual ByteInput reports more than 2**64 bytes, an otherwise valid Bytes[] element can advertise a payload length of 2**64 and this accessor returns a BytesView because decode_bytes_view_at only checks that the payload fits the reported frame. Solidity rejects dynamic calldata lengths above 2**64 - 1, just as this module already does for the outer array length, so bytes_at and string_at accept an encoding they claim to validate like Solidity; enforce the same length limit on dynamic element payloads.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant