Skip to content

fix(binding): reject oversized final-value allocations - #26

Merged
jmgilman merged 3 commits into
masterfrom
fix/issue-13-result-allocation
Aug 24, 2026
Merged

jmgilman merged 3 commits into
masterfrom
fix/issue-13-result-allocation

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

  • reject oversized tuple, list, and dictionary final values before proportional destination allocation
  • allocate only from node-budget-validated container lengths and stream dictionary iteration instead of materializing Dict.Items()
  • add an allocation regression covering all three container converters

Verification

  • regression fails on master: tuple 2,067,136 bytes; list 2,064,480 bytes; dictionary 17,680,784 bytes
  • go test ./internal/binding -count=1
  • public four-million-element Server.Execute reproduction: allocation reduced from 128,034,304 bytes to 64,013,840 bytes while preserving ErrResourceLimit
  • mise exec -- moon run root:check
  • gopls diagnostics: clean for both changed files

The remaining Starlark source allocation is outside final-value conversion; process isolation remains necessary for a hard heap boundary.

Closes #13

Compare source length to remainingNodes before destination allocation so oversized tuples, lists, and dicts fail with ErrValueLimit instead of preallocating from untrusted length.
Prove ConvertFinal returns ErrValueLimit for oversized tuples, lists, and dictionaries without allocating destination memory proportional to source length.
@jmgilman
jmgilman merged commit e2b1e56 into master Aug 24, 2026
4 checks passed
@jmgilman
jmgilman deleted the fix/issue-13-result-allocation branch August 24, 2026 20:26
This was referenced Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Final-value conversion preallocates oversized lists before enforcing limits

1 participant