Given the following reproduction scenario:
contract C {
bytes public x;
function _grow() private returns (bytes storage) {
x.push();
return x;
}
function corrupt(bytes1 b) external {
require(x.length == 31, "need len 31");
(x[0], _grow()[1]) = (b, bytes1(0x00));
}
}
the warning 7239 should be issued, however, this does not happen due to gaps in our static analysis, where we only perform such checks on direct .push() calls on storage pointers, and not much else. This should be improved so that indirect (i.e. from another function) array expansion is also covered.
Given the following reproduction scenario:
the warning 7239 should be issued, however, this does not happen due to gaps in our static analysis, where we only perform such checks on direct
.push()calls on storage pointers, and not much else. This should be improved so that indirect (i.e. from another function) array expansion is also covered.