Sitelet https://github.com/starkware-libs/cairo/pull/10218
Skip to content

fix(semantic): enforce the fixed-size-array size cap on the type form - #10218

Merged
orizi merged 1 commit into
mainfrom
orizi/07-20-fix_semantic_enforce_the_fixed-size-array_size_cap_on_the_type_form
Jul 20, 2026
Merged

orizi merged 1 commit into
mainfrom
orizi/07-20-fix_semantic_enforce_the_fixed-size-array_size_cap_on_the_type_form

Conversation

@orizi

@orizi orizi commented Jul 20, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds validation of fixed-size array size limits (< 2^15) when the size is inferred from the array literal expression, rather than only when the size is explicitly specified in the type annotation. Previously, a declaration like let _x = [1_felt252; 32768]; (without an explicit type annotation) would not trigger the E2174 size limit error. Now, verify_fixed_size_array_size is also called during type resolution when the size can be determined from the integer value, ensuring the limit is enforced consistently in both cases.


Type of change

Please check one:

  • Bug fix (fixes incorrect behavior)
  • New feature
  • Performance improvement
  • Documentation change with concrete technical impact
  • Style, wording, formatting, or typo-only change

Why is this change needed?

The E2174 diagnostic for fixed-size arrays exceeding 2^15 was only emitted when the size appeared in an explicit type annotation (e.g., [u32; 32768]). When the size was inferred directly from the array expression (e.g., [1_felt252; 32768]), the size limit was not checked, allowing invalid array sizes to pass through semantic analysis without an error.


What was the behavior or documentation before?

let _x = [1_felt252; 32768]; compiled without any diagnostic, even though the size exceeds the allowed maximum of 2^15 - 1.


What is the behavior or documentation after?

let _x = [1_felt252; 32768]; now correctly emits:

error[E2174]: Fixed size array size must be smaller than 2^15.
 --> lib.cairo:7:14
    let _x = [1_felt252; 32768];
             ^^^^^^^^^^^^^^^^^^

The size limit is enforced regardless of whether the size is written in the type annotation or inferred from the expression.


Related issue or discussion (if any)

N/A


Additional context

The fix also adds an additional E2174 diagnostic for the type annotation side of [u32; 32768] that was previously missing from the test expectations, confirming both the type and expression positions are now validated.

`verify_fixed_size_array_size` (which rejects sizes > i16::MAX with E2174) was
only applied on the value path, so a type like `[felt252; 32768]` in a
signature or annotation slipped through while the value `[0; 32768]` errored.
An un-capped `[T; N]` reaches sierra generation as `[t].repeat(N)`, so this is
also a potential huge allocation from a bare signature.

Run the check in `resolve_type_ex`'s fixed-size-array arm too, matching the
value path.
@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

orizi commented Jul 20, 2026

Copy link
Copy Markdown
Collaborator Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@orizi
orizi marked this pull request as ready for review July 20, 2026 07:20
@cursor

cursor Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Narrow semantic-analysis change that rejects invalid array sizes earlier; no runtime, auth, or data-path impact.

Overview
E2174 (fixed-size array length must be < 2^15) is now applied when resolving a [T; N] type, not only when checking the matching array literal.

During resolve_type for fixed-size array syntax, if the size constant evaluates to a concrete integer, the compiler calls verify_fixed_size_array_size before building the type. Oversized lengths like 32768 therefore error on the type annotation (e.g. [u32; 32768]) as well as on repeat literals such as [1_felt252; 32768], including when no explicit type is written on the binding.

Diagnostic tests for illegal sizes were extended to cover these cases.

Reviewed by Cursor Bugbot for commit 2d4f08c. Bugbot is set up for automated code reviews on this repo. Configure here.

@eytan-starkware eytan-starkware left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@eytan-starkware reviewed 2 files and all commit messages, and made 1 comment.
Reviewable status: all files reviewed, 1 unresolved discussion (waiting on orizi and TomerStarkware).


crates/cairo-lang-semantic/src/types.rs line 691 at r1 (raw file):

            };
            if let Some(size_int) = size.to_int(db) {
                verify_fixed_size_array_size(db, diagnostics, size_int, array_syntax)?;

Wouldn't it be better to check after we resolve generics, some where in lowering?

@orizi orizi left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@orizi made 1 comment.
Reviewable status: all files reviewed, 1 unresolved discussion (waiting on eytan-starkware and TomerStarkware).


crates/cairo-lang-semantic/src/types.rs line 691 at r1 (raw file):

Previously, eytan-starkware wrote…

Wouldn't it be better to check after we resolve generics, some where in lowering?

this is a semantic diagnostic - it is just about too long arrays - we don't know anything about sizes before - but we always do know that size must be in i16 range.

@eytan-starkware eytan-starkware left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@eytan-starkware resolved 1 discussion.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved (waiting on TomerStarkware).

@orizi
orizi added this pull request to the merge queue Jul 20, 2026
Merged via the queue into main with commit d3a6a14 Jul 20, 2026
55 checks passed
@orizi
orizi deleted the orizi/07-20-fix_semantic_enforce_the_fixed-size-array_size_cap_on_the_type_form branch July 20, 2026 10:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants