Skip to content

Reject non-canonical lengths when decoding - #36

Merged
sc0Vu merged 1 commit into
web3p:masterfrom
sc0Vuai:fix/canonical-length
Sep 23, 2026
Merged

sc0Vu merged 1 commit into
web3p:masterfrom
sc0Vuai:fix/canonical-length

Conversation

@sc0Vuai

@sc0Vuai sc0Vuai commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

The decoder accepted long-form prefixes (0xb8-0xbf, 0xf8-0xff) for lengths below 56 (e.g. b80161, f80180) and lengths with a leading zero byte (e.g. b90038...), except for an exact "00". geth rejects these as non-canonical. A long string declaring a length beyond PHP_INT_MAX also crashed with a TypeError instead of a RuntimeException.

Reject both non-canonical forms in the long string and long list branches, and check the declared long string size before slicing.

Re-enable testInvalidRlp so it decodes invalidrlptest.json and expects an exception, and add canonical and non-canonical boundary vectors.

The decoder accepted long-form prefixes (0xb8-0xbf, 0xf8-0xff) for
lengths below 56 (e.g. b80161, f80180) and lengths with a leading zero
byte (e.g. b90038...), except for an exact "00". geth rejects these as
non-canonical. A long string declaring a length beyond PHP_INT_MAX also
crashed with a TypeError instead of a RuntimeException.

Reject both non-canonical forms in the long string and long list
branches, and check the declared long string size before slicing.

Re-enable testInvalidRlp so it decodes invalidrlptest.json and expects
an exception, and add canonical and non-canonical boundary vectors.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sc0Vu
sc0Vu merged commit 3edcb80 into web3p:master Sep 23, 2026
4 checks passed
@codecov

codecov Bot commented Sep 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.55%. Comparing base (1478705) to head (b05b878).
⚠️ Report is 4 commits behind head on master.

Additional details and impacted files
@@             Coverage Diff              @@
##             master      #36      +/-   ##
============================================
+ Coverage     94.44%   96.55%   +2.10%     
- Complexity       61       68       +7     
============================================
  Files             3        3              
  Lines           162      174      +12     
============================================
+ Hits            153      168      +15     
+ Misses            9        6       -3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants