Skip to content

Warning 7239 about assignment to storage array while it's being enlarged not issued when expansion happens inside a function #17030

Description

@nikola-matic

Given the following reproduction scenario:

contract C {
    bytes public x;

    function _grow() private returns (bytes storage)  {
        x.push();
        return x;
    }

    function corrupt(bytes1 b) external {
        require(x.length == 31, "need len 31");
        (x[0], _grow()[1]) = (b, bytes1(0x00));
    }
}

the warning 7239 should be issued, however, this does not happen due to gaps in our static analysis, where we only perform such checks on direct .push() calls on storage pointers, and not much else. This should be improved so that indirect (i.e. from another function) array expansion is also covered.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bug 🐛low effortThere is not much implementation work to be done. The task is very easy or tiny.low impactChanges are not very noticeable or potential benefits are limited.should haveWe like the idea but it’s not important enough to be a part of the roadmap.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions