Resolve N2: bound align annotations at 4096 (review #006)

align: 2^62 compiled and reported total_size = 2^63 — meaningless
layout output the consumer may act on, and the reachable path to the
MAX_ARRAY_BYTES cap used exactly this knob.

- MAX_ALIGN = 4096 (page granularity) in schema.rs, documented with the
  probe arithmetic
- parse_align returns Result and rejects over-cap values with a clean
  Schema error naming path/value/maximum — a silent clamp was rejected
  (it would change layout semantics without telling the consumer);
  both call sites thread the path, so standalone BastDoc::new (which
  never runs the meta-schema) is covered
- Meta-schema: "maximum": 4096 on StructDef.align and FieldDef.align —
  the published alk.dev/bast/v1/schema contract now matches the parser
- H1's byte-cap test retuned to align 4096 x count 2^16 = 2^28 > 2^26
  (the byte cap stays reachable under the new align cap)

Tests: 3 new (struct align above cap, field align above cap, align at
cap accepted). 511 tests green, clippy -D warnings clean, wasm32 build
green, cargo doc zero warnings.
This commit is contained in:
glm-5.3-flash committed 2026-09-02 19:46:51 +00:00
1 parent 8739d29550
commit 0bc5a541ac
5 files changed
+139 -21

No files matched your search

+41 -5
View File
@@ -1,5 +1,5 @@
---
status: in-progress (H1, L1, H3, L5, L6, H2, M1, M2, M3, L2, L3 resolved 2026-09-02)
status: in-progress (H1, L1, H3, L5, L6, H2, M1, M2, M3, L2, L3, N2 resolved 2026-09-02)
last_updated: 2026-09-02
reviewed_artifacts:
- src/read_plan.rs
@@ -98,10 +98,11 @@ sub-types, `fingerprint()` methods; `Hash` on `Endian`/
| High | 3 (H1, H2, H3) | all resolved 2026-09-02 |
| Medium | 4 (M1, M2, M3, M4) | M1, M2, M3 resolved 2026-09-02; M4 ongoing |
| Low | 6 (L1–L6) | L1, L2, L3, L5, L6 resolved 2026-09-02 |
| Nit | 2 (N1, N2) | open |
| Nit | 2 (N1, N2) | N2 resolved 2026-09-02; N1 open |
All three Highs, three of four Mediums, and five of six Lows are
resolved. Remaining: M4 (ongoing per-fix coverage posture), L4, N1, N2.
All three Highs, three of four Mediums, five of six Lows, and one of
two Nits are resolved. Remaining: M4 (ongoing per-fix coverage
posture), L4, N1.
The three Highs are adversarial-input crashes (H1, H2) and a
cross-consumer wire-layout convention gap (H3) — all three are the
@@ -141,6 +142,13 @@ them became materially easier to hit with the 0.3.0 surface.
0.3.0 compiled-form files already in play) — see the resolution
blocks on each finding. 508 tests green, clippy `-D warnings` clean,
wasm build green, `cargo doc --no-deps` zero warnings.
- **N2 (2026-09-02):** resolved — see the "Resolution (2026-09-02)"
block on the finding. `MAX_ALIGN = 4096` enforced in `parse_align`
(clean `Schema` error, standalone-safe) and in the meta-schema
(`"maximum": 4096` on both align properties); H1's byte-cap test
retuned to the new legal maximum. 511 tests green, clippy
`-D warnings` clean, wasm build green, `cargo doc --no-deps` zero
warnings.
---
@@ -954,6 +962,33 @@ the honest layouts in the wild never need >64.
(with a clean `Schema` error). A locking test (align above the cap →
clean `Err`) mirrors the H1 test family.
**Resolution (2026-09-02):** both layers, cap = 4096 (page granularity;
the finding's suggestion):
1. **`MAX_ALIGN = 4096`** added to `schema.rs` (documented with the
N2 probe arithmetic: `align: 2^62` → `total_size = 2^63`).
2. **`parse_align` now returns `Result<Option<usize>>`** and rejects
over-cap values with a clean `Schema` error naming the path, the
value, and the maximum — a clamp-with-silent-drop was considered
and rejected: it would change layout semantics without telling the
consumer (AGENTS.md §3 wants a handleable error, not a surprise).
Both call sites (`BastStruct::parse`, `BastField::parse`) thread the
path. This closes the standalone `BastDoc::new` path, which never
runs the meta-schema.
3. **Meta-schema `"maximum": 4096`** added to both `align` properties
(`StructDef.align`, `FieldDef.align`) — the published
`https://alk.dev/bast/v1/schema` contract now matches the parser.
4. **H1 byte-cap test retuned**: the old fixture used `align: 2^20` to
reach `MAX_ARRAY_BYTES`; it now uses `align: 4096` × count 2^16 =
2^28 > 2^26 — the byte cap stays reachable under the new align cap
(the finding's point (b) remains testable).
Tests: `n2_struct_align_above_cap_rejected_at_parse` (message names
align + maximum), `n2_field_align_above_cap_rejected_at_parse`,
`n2_align_at_cap_accepted` (boundary: align 4096 accepted, total_size
4096). Verified: 511 tests green, clippy `-D warnings` clean, wasm
build green, `cargo doc --no-deps` zero warnings.
---
## What's Good
@@ -1011,7 +1046,8 @@ Worth recording, because the findings shouldn't eclipse it:
7. **L1–L6, N1, N2** — opportunistic, folded into whichever session
touches the relevant file (L6 is the exception — it belongs with
H3; N2 pairs naturally with any bast/bast_meta session; L1 done
with H1; L5/L6 done with H3; L2/L3 done with the M-fix session).
with H1; L5/L6 done with H3; L2/L3 done with the M-fix session;
N2 done in the M-fix session's tail).
## Notes