Skip to content

fix(py-sdk): reject slot accesses that do not fit in a slot 🐛 - #38

Open
kriss39 wants to merge 1 commit into
genlayerlabs:v0.6-devfrom
kriss39:fix/slot-access-bounds
Open

kriss39 wants to merge 1 commit into
genlayerlabs:v0.6-devfrom
kriss39:fix/slot-access-bounds

Conversation

@kriss39

@kriss39 kriss39 commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

What

Slot.read / Slot.write in genlayer-py-std pass the byte offset straight to _genlayer_wasi.storage_read / storage_write, whose PyArg_ParseTuple format "y*Iw*" / "y*Iy*" uses the I converter — documented as "without overflow checking". An offset of 2**32 + 5 reaches the executor as 5, -1 as 0xffffffff, 2**40 + 7 as 7. That defeats the executor's slot_access_fits guard (wasi/genlayer_sdk/mod.rs), which exists precisely so an out-of-slot access becomes Errno::Inval: the guest never sends the out-of-range offset, it silently reads or overwrites another location in the same slot.

Offsets are plain Python ints built by pointer arithmetic (VLA.__getitem__: self._off + 4 + idx * size; Slot.read/write are public), so e.g. vla.set_length(2**31); vla[2**30] on a 32-byte element aliases offset (4 + 2**35) mod 2**32 == 4. Slot.indirect is already protected by off.to_bytes(4, 'little'); read/write were not.

Change (executor line v0.3, runners/genlayer-py-std)

  • storage/core.py: add SLOT_SIZE = 1 << 32 and check_slot_access(off, len) mirroring the executor's slot_access_fits (off >= 0, len >= 0, off + len <= SLOT_SIZE), called from Slot.read and Slot.write; raises OverflowError, consistent with what indirect already raises.
  • tests/test_storage_core.py: in-range boundaries accepted; SLOT_SIZE, SLOT_SIZE - 3 + 4, 2**40 + 7, negative offset and negative length rejected on both read and write (via InmemManager, which would otherwise try to allocate the wrapped range).
  • runners/support/versions/current.nix: refreshed genlayer-std, py-genlayer, py-genlayer-multi hashes.

Executor commit: kriss39/genvm-executor@90d4ef1 on pr/v0.3/fix/slot-access-bounds (rebased onto the current pinned 7e0936a).

The root cause in the C shim (runners/cpython/modules/_genlayer_wasi/genlayer.c, "I" → parse as object + PyLong_AsUnsignedLongLong + > UINT32_MAX check) is worth fixing too, but it needs a cpython runner rebuild, which I cannot produce here; the Python-side guard covers the only caller. Happy to add the C change if you prefer it in this PR and can refresh the cpython hash.

Verification

  • runners/genlayer-py-std: pytest tests --ignore=tests/embeddings → 978 passed, 1 failed (test_render_rejects_malformed_image, PIL not installed in my venv — unrelated).
  • PyArg_ParseTuple('I') masking behaviour confirmed against CPython (PyLong_AsUnsignedLongMask).
  • ruff format / ruff check clean on the changed files.
  • Runner hashes: I cannot run hash-updater.py here (no nix; runners are not built on macOS). I reproduced the content-addressing locally (make-zip.py under Python 3.13 over the cleanSource-filtered src/ + runner.json, then the wrapper Depends uids) and confirmed it reproduces the three currently committed hashes bit-for-bit before applying it to the patched tree. Please treat the #runners-all nix build as unrun on my side; if it reports a mismatch I will update from the got: values.
  • Not built here: the Rust executor crate (unchanged by this PR).

v0.2.x does not vendor the Python runner sources, so no pr/v0.2/... branch.

Independent of the other two PRs I opened today; whichever current.nix change lands second I will rebase and recompute.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: genlayerlabs/genvm-manager/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: e799e104-3b1e-480a-bc1d-6fe02245ff97

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

GenVM PR actions

Tick a box to run it (the box unticks itself when handled). Actions only run while the PR has the ci-safe label.

  • Force run full tests
  • Provision executor PRs
Commands
  • /genvm-run-tests — run full tests once for the current manager snapshot
  • /merge — queue the exact manager snapshot through the App-owned E2E merge train

@github-actions github-actions Bot added the not rebased branch is behind its base; rebase before it can be merged label Sep 14, 2026
@kriss39
kriss39 force-pushed the fix/slot-access-bounds branch from c722b34 to bee9d94 Compare September 15, 2026 09:01
@github-actions github-actions Bot added not rebased branch is behind its base; rebase before it can be merged and removed not rebased branch is behind its base; rebase before it can be merged labels Sep 15, 2026
@kriss39
kriss39 force-pushed the fix/slot-access-bounds branch from bee9d94 to 25e15e5 Compare September 16, 2026 13:00
@github-actions github-actions Bot added not rebased branch is behind its base; rebase before it can be merged and removed not rebased branch is behind its base; rebase before it can be merged labels Sep 16, 2026
@kriss39
kriss39 force-pushed the fix/slot-access-bounds branch from 25e15e5 to 41f3213 Compare September 16, 2026 19:12
@github-actions github-actions Bot added not rebased branch is behind its base; rebase before it can be merged and removed not rebased branch is behind its base; rebase before it can be merged labels Sep 16, 2026
@kriss39
kriss39 force-pushed the fix/slot-access-bounds branch from 41f3213 to 4200db2 Compare September 18, 2026 08:46
@github-actions github-actions Bot removed the not rebased branch is behind its base; rebase before it can be merged label Sep 18, 2026
@github-actions github-actions Bot added the not rebased branch is behind its base; rebase before it can be merged label Sep 30, 2026
@kriss39
kriss39 force-pushed the fix/slot-access-bounds branch from 4200db2 to 32fd6de Compare September 30, 2026 08:48
@github-actions github-actions Bot added not rebased branch is behind its base; rebase before it can be merged and removed not rebased branch is behind its base; rebase before it can be merged labels Sep 30, 2026
@kp2pml30

kp2pml30 commented Oct 2, 2026

Copy link
Copy Markdown
Member

Hello, I do not see much value in this check, because it is checked on the rust level. Moreover, this is a big breaking change, so I will leave it as is for now

@kriss39
kriss39 force-pushed the fix/slot-access-bounds branch from 32fd6de to 9099ff7 Compare October 2, 2026 13:35
@github-actions github-actions Bot removed the not rebased branch is behind its base; rebase before it can be merged label Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants