fix(batch-prover): guard against empty commitments slice in PartitionState::new#3228
Open
amathxbt wants to merge 2 commits into
Open
fix(batch-prover): guard against empty commitments slice in PartitionState::new#3228amathxbt wants to merge 2 commits into
amathxbt wants to merge 2 commits into
Conversation
…State::new PartitionState::new indexed commitments[0] unconditionally, which would cause an out-of-bounds panic if an empty slice was passed. While callers currently never pass an empty slice, there was no compile-time or runtime enforcement of that invariant. Fix: add an anyhow::ensure! at the top of the constructor so the function returns a descriptive Err instead of panicking.
jfldde
approved these changes
Apr 30, 2026
Author
|
@jfldde @eyusufatik — this PR is approved and ready. No lint issues found. Pinging for merge. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PartitionState::newindexescommitments[0]unconditionally on the very first line of the function body. If an empty slice is ever passed (e.g. through a future call site or a test), the process panics with an index-out-of-bounds error rather than returning a descriptiveErr.Bug
There is no compile-time guarantee (e.g.
NonEmpty) nor any runtime check thatcommitmentsis non-empty before this access.Fix
Add an
anyhow::ensure!at the top of the constructor so the invariant is enforced explicitly and the caller receives a cleanErrinstead of a panic:Files changed
crates/batch-prover/src/partition.rs