Resolve N2: bound align annotations at 4096 (review #006)
align: 2^62 compiled and reported total_size = 2^63 — meaningless layout output the consumer may act on, and the reachable path to the MAX_ARRAY_BYTES cap used exactly this knob. - MAX_ALIGN = 4096 (page granularity) in schema.rs, documented with the probe arithmetic - parse_align returns Result and rejects over-cap values with a clean Schema error naming path/value/maximum — a silent clamp was rejected (it would change layout semantics without telling the consumer); both call sites thread the path, so standalone BastDoc::new (which never runs the meta-schema) is covered - Meta-schema: "maximum": 4096 on StructDef.align and FieldDef.align — the published alk.dev/bast/v1/schema contract now matches the parser - H1's byte-cap test retuned to align 4096 x count 2^16 = 2^28 > 2^26 (the byte cap stays reachable under the new align cap) Tests: 3 new (struct align above cap, field align above cap, align at cap accepted). 511 tests green, clippy -D warnings clean, wasm32 build green, cargo doc zero warnings.
This commit is contained in:
1 parent
8739d29550
commit
0bc5a541ac
5 files changed
+139
-21
No files matched your search
@@ -1,5 +1,5 @@
|
||||
---
|
||||
status: in-progress (H1, L1, H3, L5, L6, H2, M1, M2, M3, L2, L3 resolved 2026-09-02)
|
||||
status: in-progress (H1, L1, H3, L5, L6, H2, M1, M2, M3, L2, L3, N2 resolved 2026-09-02)
|
||||
last_updated: 2026-09-02
|
||||
reviewed_artifacts:
|
||||
- src/read_plan.rs
|
||||
@@ -98,10 +98,11 @@ sub-types, `fingerprint()` methods; `Hash` on `Endian`/
|
||||
| High | 3 (H1, H2, H3) | all resolved 2026-09-02 |
|
||||
| Medium | 4 (M1, M2, M3, M4) | M1, M2, M3 resolved 2026-09-02; M4 ongoing |
|
||||
| Low | 6 (L1–L6) | L1, L2, L3, L5, L6 resolved 2026-09-02 |
|
||||
| Nit | 2 (N1, N2) | open |
|
||||
| Nit | 2 (N1, N2) | N2 resolved 2026-09-02; N1 open |
|
||||
|
||||
All three Highs, three of four Mediums, and five of six Lows are
|
||||
resolved. Remaining: M4 (ongoing per-fix coverage posture), L4, N1, N2.
|
||||
All three Highs, three of four Mediums, five of six Lows, and one of
|
||||
two Nits are resolved. Remaining: M4 (ongoing per-fix coverage
|
||||
posture), L4, N1.
|
||||
|
||||
The three Highs are adversarial-input crashes (H1, H2) and a
|
||||
cross-consumer wire-layout convention gap (H3) — all three are the
|
||||
@@ -141,6 +142,13 @@ them became materially easier to hit with the 0.3.0 surface.
|
||||
0.3.0 compiled-form files already in play) — see the resolution
|
||||
blocks on each finding. 508 tests green, clippy `-D warnings` clean,
|
||||
wasm build green, `cargo doc --no-deps` zero warnings.
|
||||
- **N2 (2026-09-02):** resolved — see the "Resolution (2026-09-02)"
|
||||
block on the finding. `MAX_ALIGN = 4096` enforced in `parse_align`
|
||||
(clean `Schema` error, standalone-safe) and in the meta-schema
|
||||
(`"maximum": 4096` on both align properties); H1's byte-cap test
|
||||
retuned to the new legal maximum. 511 tests green, clippy
|
||||
`-D warnings` clean, wasm build green, `cargo doc --no-deps` zero
|
||||
warnings.
|
||||
|
||||
---
|
||||
|
||||
@@ -954,6 +962,33 @@ the honest layouts in the wild never need >64.
|
||||
(with a clean `Schema` error). A locking test (align above the cap →
|
||||
clean `Err`) mirrors the H1 test family.
|
||||
|
||||
**Resolution (2026-09-02):** both layers, cap = 4096 (page granularity;
|
||||
the finding's suggestion):
|
||||
|
||||
1. **`MAX_ALIGN = 4096`** added to `schema.rs` (documented with the
|
||||
N2 probe arithmetic: `align: 2^62` → `total_size = 2^63`).
|
||||
2. **`parse_align` now returns `Result<Option<usize>>`** and rejects
|
||||
over-cap values with a clean `Schema` error naming the path, the
|
||||
value, and the maximum — a clamp-with-silent-drop was considered
|
||||
and rejected: it would change layout semantics without telling the
|
||||
consumer (AGENTS.md §3 wants a handleable error, not a surprise).
|
||||
Both call sites (`BastStruct::parse`, `BastField::parse`) thread the
|
||||
path. This closes the standalone `BastDoc::new` path, which never
|
||||
runs the meta-schema.
|
||||
3. **Meta-schema `"maximum": 4096`** added to both `align` properties
|
||||
(`StructDef.align`, `FieldDef.align`) — the published
|
||||
`https://alk.dev/bast/v1/schema` contract now matches the parser.
|
||||
4. **H1 byte-cap test retuned**: the old fixture used `align: 2^20` to
|
||||
reach `MAX_ARRAY_BYTES`; it now uses `align: 4096` × count 2^16 =
|
||||
2^28 > 2^26 — the byte cap stays reachable under the new align cap
|
||||
(the finding's point (b) remains testable).
|
||||
|
||||
Tests: `n2_struct_align_above_cap_rejected_at_parse` (message names
|
||||
align + maximum), `n2_field_align_above_cap_rejected_at_parse`,
|
||||
`n2_align_at_cap_accepted` (boundary: align 4096 accepted, total_size
|
||||
4096). Verified: 511 tests green, clippy `-D warnings` clean, wasm
|
||||
build green, `cargo doc --no-deps` zero warnings.
|
||||
|
||||
---
|
||||
|
||||
## What's Good
|
||||
@@ -1011,7 +1046,8 @@ Worth recording, because the findings shouldn't eclipse it:
|
||||
7. **L1–L6, N1, N2** — opportunistic, folded into whichever session
|
||||
touches the relevant file (L6 is the exception — it belongs with
|
||||
H3; N2 pairs naturally with any bast/bast_meta session; L1 done
|
||||
with H1; L5/L6 done with H3; L2/L3 done with the M-fix session).
|
||||
with H1; L5/L6 done with H3; L2/L3 done with the M-fix session;
|
||||
N2 done in the M-fix session's tail).
|
||||
|
||||
## Notes
|
||||
|
||||
|
||||
Reference in new issue
Block a user