Sitelet https://github.com/starkware-libs/cairo/pull/10140
Skip to content

bug fix(semantic): Validate quotient in const DivRem to avoid signed MIN/-1 ICE. - #10140

Merged
orizi merged 1 commit into
mainfrom
orizi/06-21-bug_fix_semantic_validate_quotient_in_const_divrem_to_avoid_signed_min_-1_ice
Jun 22, 2026
Merged

orizi merged 1 commit into
mainfrom
orizi/06-21-bug_fix_semantic_validate_quotient_in_const_divrem_to_avoid_signed_min_-1_ice

Conversation

@orizi

@orizi orizi commented Jun 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds overflow detection for signed integer MIN / -1 in constant evaluation. When evaluating DivRem::div_rem at compile time, the quotient is now validated against the target type's range using validate_literal. If the quotient overflows (e.g., -128_i8 / -1), a clean E2008 diagnostic is emitted instead of silently storing an out-of-range value that would later cause an ICE in sierra-gen. The num-integer crate is introduced to use div_rem for computing both quotient and remainder together.


Type of change

Please check one:

  • Bug fix (fixes incorrect behavior)
  • New feature
  • Performance improvement
  • Documentation change with concrete technical impact
  • Style, wording, formatting, or typo-only change

Why is this change needed?

For signed integers, MIN / -1 produces a quotient that overflows the type (e.g., i8::MIN / -1 = 128, which exceeds i8::MAX). Previously, the constant evaluator would silently store this out-of-range value, which caused an ICE (internal compiler error) later during sierra code generation. The compiler should instead emit a clear, user-facing diagnostic at the point of the constant definition.


What was the behavior or documentation before?

DivRem::div_rem(-128_i8, -1) in a constant expression would silently produce an out-of-range quotient value, leading to an ICE in sierra-gen rather than a proper compiler diagnostic.


What is the behavior or documentation after?

DivRem::div_rem(-128_i8, -1) in a constant expression now emits:

error[E2008]: The value does not fit within the range of type core::integer::i8.

at the site of the offending expression, cleanly rejecting the invalid constant.


Related issue or discussion (if any)

N/A


Additional context

A test case (DIVREM_SIGNED_MIN_OVERFLOW) has been added to the constant evaluation test data to cover this overflow scenario and verify the diagnostic output.

…MIN/-1 ICE.

The const-eval path for `DivRem::div_rem` stored the quotient without
validating it against the input type's range. For signed `iN::MIN / -1` the
quotient is `2^(N-1)` (= `iN::MAX + 1`), which is unrepresentable in `iN`;
the out-of-range value was silently stored and later caused an ICE in
sierra type-specialization (`Got failure while specializing type Const<i8, 128>`).

Now the quotient is validated via `validate_literal`, emitting a clean
E2008 LiteralError::OutOfRange — matching the `/` operator path.

Fixes #10132.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

orizi commented Jun 21, 2026

Copy link
Copy Markdown
Collaborator Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@TomerStarkware TomerStarkware left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:lgtm:

@TomerStarkware reviewed 4 files and all commit messages, and made 1 comment.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved (waiting on eytan-starkware).

@orizi
orizi marked this pull request as ready for review June 22, 2026 05:37
@orizi
orizi added this pull request to the merge queue Jun 22, 2026
@cursor

cursor Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Narrow change to compile-time DivRem in the semantic constant evaluator; aligns overflow handling with other literal validation and only affects invalid constants.

Overview
Constant evaluation for DivRem::div_rem now checks that the quotient fits the operand type (via validate_literal) before building the (quotient, remainder) struct. Signed MIN / -1 (e.g. -128_i8 / -1) no longer stores an out-of-range quotient that could ICE in sierra-gen; it reports E2008 at the expression instead.

Implementation uses num_integer::Integer::div_rem for quotient and remainder together, and adds a regression case DIVREM_SIGNED_MIN_OVERFLOW in constant diagnostics tests.

Reviewed by Cursor Bugbot for commit 6eac831. Bugbot is set up for automated code reviews on this repo. Configure here.

Merged via the queue into main with commit 409502d Jun 22, 2026
55 checks passed
@orizi orizi linked an issue Jun 22, 2026 that may be closed by this pull request
@orizi
orizi deleted the orizi/06-21-bug_fix_semantic_validate_quotient_in_const_divrem_to_avoid_signed_min_-1_ice branch June 23, 2026 07:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: Const DivRem signed MIN over minus one ICE

3 participants