glm-5.2 5f88bca0d8 Fix L2: replace unreachable! with Err for untrusted-schema safety
The immediate downstream consumer (alkcall) accepts schemas from
arbitrary internet peers in its hub/spoke topology. A panic is the
wrong failure mode for a malicious or unsupported schema - an Err
the caller can handle is correct.

Three sites converted:
- offset_map.rs: _ => Err(Offset { unsupported AlkType kind for
  aligned offset computation })
- layout_builder.rs: _ => Err(Offset { unsupported AlkType kind
  for packed layout computation })
- materialize.rs: _ => Err(Schema { internal: union discriminator
  type N is not a supported byte discriminator })

The materialize.rs site uses Schema (not Access) because a wrong
disc_type is a schema-authoring bug (parse_discriminator should have
caught it), not a buffer-access error. The sibling sites in
sequential_reader.rs and tunion.rs already returned Err(Schema) -
only materialize.rs was the holdout.

Note: the k if k.is_fixed_size() guard in offset_map and
layout_builder means the compiler cannot enforce exhaustiveness at
compile time. Converting _ from unreachable! to Err is the runtime
mitigation. A future refactor could list all fixed-size kinds
explicitly to restore compile-time checking. Deferred to a separate
cleanup pass.

Verified: no unreachable! remains in production code (the one
remaining hit at offset_map.rs:688 is inside a #[test] fn).

cargo test --release: 396 tests pass, 0 failures
cargo clippy --all-targets -- -D warnings: clean
cargo build --target wasm32-unknown-unknown --release: clean (prior)
2026-08-11 09:02:56 +00:00
S
Description
No description provided
1.2 MiB
0 Stars 6 Watchers 0 Forks
Languages
Rust 97%
Python 2.9%
Shell 0.1%