Skip to content

Yul: reject non-decimal @use-src source indices - #17072

Open
gophersg wants to merge 1 commit into
argotorg:developfrom
gophersg:fix-use-src-non-decimal-source-index
Open

gophersg wants to merge 1 commit into
argotorg:developfrom
gophersg:fix-use-src-non-decimal-source-index

Conversation

@gophersg

@gophersg gophersg commented Oct 2, 2026 •

Copy link
Copy Markdown

Description

Checklist

The Yul object parser's @use-src directive only allows decimal source indices per
its grammar (UseSrc := [0-9]+ ':' FileName), but the index was parsed with
toUnsignedInt(), which called std::stoul() without checking how many characters
were consumed.

std::stoul() stops at the first non-digit, so inputs such as 0x10 or 1e2 were
silently truncated to 0 and 1 respectively and accepted as valid source indices,
building a wrong source mapping instead of being reported as a syntax error
(error 9804).

This makes toUnsignedInt() require the whole string to be consumed, so a number
followed by trailing characters (including hex/binary/scientific literals) is rejected.
The behavior is covered by new regression tests in the @use-src parser tests and in
the toUnsignedInt() unit tests.

AI Disclosure

  • No AI tools were used

The Yul object parser's @use-src directive only allows decimal source
indices per its grammar (UseSrc := [0-9]+ ':' FileName), but the index
was parsed with toUnsignedInt(), which called std::stoul() without
checking how many characters were consumed.

std::stoul() stops at the first non-digit, so inputs such as 0x10 or
1e2 were silently truncated to 0 and 1 respectively and accepted as
valid source indices, building a wrong source mapping instead of being
reported as a syntax error (error 9804).

Make toUnsignedInt() require the whole string to be consumed, so a
number followed by trailing characters (including hex/binary/scientific
literals) is rejected. Add regression tests for the @use-src parser and
for toUnsignedInt() itself.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant