Skip to content

test(LibBytecode): pin the documented sourceCount(hex"00") == 0 invariant explicitly #115

Description

@thedavidmeister

Gap

LibBytecode.sourceCount NatSpec documents a specific equivalence: "0x and 0x00 are equivalent, both having 0 sources." The "" (empty) case is pinned by testSourceCount0, but the single-byte hex"00" case has no explicit, named assertion in test/src/lib/bytecode/LibBytecode.sourceCount.t.sol.

It is covered indirectly:

  • testSourceCount1 fuzzes bytecode.length > 0 and asserts sourceCount(bytecode) == uint8(bytecode[0]), so hex"00" is within its input domain and is asserted to return 0;
  • checkNoOOBPointers tests exercise hex"00" as well.

So this is LOW / test-hardening, not an open bug — the behavior is fuzz-covered; only a dedicated assertion for the documented invariant is missing.

Proposed fix

Add one explicit unit test to LibBytecodeSourceCountTest:

/// The NatSpec documents 0x and 0x00 as equivalent (both 0 sources). `testSourceCount0`
/// pins the empty case; this pins the single 0x00 byte explicitly.
function testSourceCountSingleZeroByte() external pure {
    assertEq(LibBytecode.sourceCount(hex"00"), 0);
}

Provenance

Surfaced from the internal audit run audit/2026-03-01-01 (pass 2, finding A01-2), which was not carried into that run's triage.md (the triage indexed P2-A01-1 HIGH — bytecodeToSources coverage — but dropped this LOW). Filed so the finding is tracked before the resolved audit-run dirs are removed in #114.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions