Skip to content

Panic on zkVM argv and env overflows#158018

Open
kevin-valerio wants to merge 1 commit into
rust-lang:mainfrom
kevin-valerio:fix-zkvm-length-overflow
Open

Panic on zkVM argv and env overflows#158018
kevin-valerio wants to merge 1 commit into
rust-lang:mainfrom
kevin-valerio:fix-zkvm-length-overflow

Conversation

@kevin-valerio

@kevin-valerio kevin-valerio commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Fixes #158016

I'm not sure if the trade-of is worth, waiting for other people opinions on that. My take was that because this overflow is directly impacted from the host it should be avoided at all cost since this overflow can ultimately lead to slice::from_raw_parts(ptr, len) with the huge length

@rustbot rustbot added S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-libs Relevant to the library team, which will review and decide on the PR/issue. labels Jun 17, 2026
@rustbot

rustbot commented Jun 17, 2026

Copy link
Copy Markdown
Collaborator

Thanks for the pull request, and welcome! The Rust team is excited to review your changes, and you should hear from @Mark-Simulacrum (or someone else) some time within the next two weeks.

Please see the contribution instructions for more information. Namely, in order to ensure the minimum review times lag, PR authors and assigned reviewers should ensure that the review label (S-waiting-on-review and S-waiting-on-author) stays updated, invoking these commands when appropriate:

  • @rustbot author: the review is finished, PR author should check the comments and take action accordingly
  • @rustbot review: the author is ready for a review, this PR will be queued again in the reviewer's queue
Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: @ChrisDenton, libs
  • @ChrisDenton, libs expanded to 12 candidates
  • Random selection from 6 candidates

@Mark-Simulacrum Mark-Simulacrum left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would be great to add a few SAFETY comments as well.

View changes since this review

arg_len.checked_next_multiple_of(WORD_SIZE).expect("argument length overflowed");
assert!(arg_len_rounded <= isize::MAX as usize, "argument length is too large");
let arg_len_words = arg_len_rounded / WORD_SIZE;
let words = unsafe { abi::sys_alloc_words(arg_len_words) };

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sys_alloc_words appears to be marked deprecated upstream; the replacement (I assume) is https://docs.rs/risc0-zkvm-platform/latest/risc0_zkvm_platform/syscall/fn.sys_alloc_aligned.html. It's suspiciously documented as safe, which seems a bit odd to me.

It seems like zkvm supports a global allocator based on the bare Vec::with_capacity above, is there a reason we're not using that here? That would avoid needing to reference the allocation primitives directly and Layout will take take of the isize restriction (if you use it in safe code).

@rustbot rustbot removed the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Jun 21, 2026
@rustbot

rustbot commented Jun 21, 2026

Copy link
Copy Markdown
Collaborator

Reminder, once the PR becomes ready for a review, use @rustbot ready.

@rustbot rustbot added the S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. label Jun 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. T-libs Relevant to the library team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

zkVM args and env length can overflow

3 participants