Repository navigation
Conversation
|
You have reached your Codex usage limits for security reviews. Please try again later. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 02cb8d67e4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
02cb8d6 to
1fe7c4e
Compare
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1fe7c4eb27
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
1fe7c4e to
662a593
Compare
|
You have reached your Codex usage limits for security reviews. Please try again later. |
662a593 to
cb83f00
Compare
|
You have reached your Codex usage limits for security reviews. Please try again later. |
`std::abi::ArrayView<I, T>` views a Solidity ABI `T[]` inside any `ByteInput` without copying it to memory. Creating the view (via `CallData::array_view` or `decode_array_view_at`) performs the checks solc applies to a `T[] calldata` parameter: head word, length word and all element heads within the input, overflow-safe for any word. `get` decodes a single element with the regular Solidity decoder (dirty-bit validation, Panic(0x32) on out-of-range index), `bytes_at`/`string_at` return zero-copy views of dynamic elements, `array_at` returns a nested view, and `element_pos` exposes the validated position of an element for struct field access.
Hand-written decoders that mirror assembly (e.g. Seaport's conduit reading `heads + calldataload(heads + i * 32)`) need the element heads position and unchecked tail positions. Add `ArrayView::heads_pos`, `head_word` and `unchecked_element_pos`, which skip the tail validation of `element_pos` and are documented as only safe when the caller validates the element itself or reads past the end as zeros.
cb83f00 to
d79f2e9
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d79f2e96f8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| let input_len = input.len() | ||
| let head_at = checked_tail<Sol>(base, head_pos) | ||
| checked_frame_end<Sol>(head_at, 32, input_len) | ||
| let tail_at = checked_tail<Sol>(base, input.word_at(head_at)) |
There was a problem hiding this comment.
Reject oversized array offsets explicitly
decode_array_view_at accepts an offset of 2**64 or greater whenever a custom ByteInput reports a sufficiently large (for example, sparse or virtual) frame, because checked_tail only checks u256 addition overflow and checked_frame_end only compares against input_len. This contradicts the documented Solidity-compatible rejection of such offset words and differs from the explicit 64-bit limit applied to len; validate the loaded offset before computing tail_at.
Useful? React with 👍 / 👎.
decode_array_view_at and ArrayView::element_pos only bounded offset words by the input frame. That rejects offsets of 2**64 or more for calldata, but a ByteInput that reports a longer frame (a sparse or virtual input) accepted them, unlike Solidity. Reject them explicitly, as the length word already is.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ff7965389d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| #[arithmetic(unchecked)] | ||
| pub fn bytes_at(self, _ index: u256) -> BytesView<I> { | ||
| self.check_index(index) | ||
| decode_bytes_view_at(self.input, base: self.elems, head_pos: index * 32) |
There was a problem hiding this comment.
Validate oversized element offsets in every accessor
When I is a sparse or virtual ByteInput whose length exceeds 2**64, a Bytes[] element head containing 2**64 passes array construction, and this call forwards it to decode_bytes_view_at, which checks only arithmetic overflow and input bounds; bytes_at therefore accepts an offset Solidity rejects. Although the current element_pos now calls checked_offset, bytes_at, string_at, and get for dynamic elements bypass that validation, producing accessor-dependent results; apply the same offset limit before each dynamic decoding path.
Useful? React with 👍 / 👎.
| #[arithmetic(unchecked)] | ||
| pub fn bytes_at(self, _ index: u256) -> BytesView<I> { | ||
| self.check_index(index) | ||
| decode_bytes_view_at(self.input, base: self.elems, head_pos: index * 32) |
There was a problem hiding this comment.
Reject oversized dynamic element lengths
When a sparse or virtual ByteInput reports more than 2**64 bytes, an otherwise valid Bytes[] element can advertise a payload length of 2**64 and this accessor returns a BytesView because decode_bytes_view_at only checks that the payload fits the reported frame. Solidity rejects dynamic calldata lengths above 2**64 - 1, just as this module already does for the outer array length, so bytes_at and string_at accept an encoding they claim to validate like Solidity; enforce the same length limit on dynamic element payloads.
Useful? React with 👍 / 👎.
Added
std::abi::ArrayView, a lazy view of a Solidity ABIT[]over calldata or any otherByteInput, created withCallData::array_viewordecode_array_view_at. It validates offsets and lengths like a SolidityT[] calldataparameter and decodes elements one at a time withget, with zero-copybytes_at/string_atand nestedarray_ataccessors, so raw-selectorrecvarms can read large arrays without decoding them into memory. For hand-written decoders,heads_pos,head_wordandunchecked_element_posexpose the raw element heads and tail positions without validating element tails.