Skip to content

fix(boundaries): validate script slots and make cleanup portable - #647

Merged
TheWitness merged 1 commit into
refactor/c17-series-09-modulesfrom
refactor/c17-series-10-boundaries
Oct 11, 2026
Merged

TheWitness merged 1 commit into
refactor/c17-series-09-modulesfrom
refactor/c17-series-10-boundaries

Conversation

@somethingwithproof

@somethingwithproof somethingwithproof commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Validate PHP reader process tables and configured/array slot bounds before descriptor access or recovery, and keep owned undefined-result behavior. Make ctype input unsigned, bound shared formatting, enforce monotonic child cleanup budgets and keep BSD spawn/descriptor behavior portable. Tests cover invalid slots, log boundaries, child cleanup, startup and release helpers.

Step 10/14 of the complete C17/native-correctness series. Base: the preceding series branch; merge/review in order so this PR shows only its own step.

Earlier validation, before this review follow-up, in isolated copied snapshots on Linux arm64:

  • Clean GCC build and make check: 18 passed, 1 existing prerequisite skips, 0 failures.
  • ASan/UBSan: 17 passed, 2 existing privilege/allocator-interposition prerequisite skips, 0 failures; no sanitizer findings.
  • Production source/profile integrity verification against disposable MariaDB and loopback SNMP fixtures passed.
  • Release archive extracted into a separate source tree and built/tested out of tree; fuzz checks passed.

Earlier local profiles retain source hashes for the copied validation tree; GitHub checks validate the published commit. No production database/device, host installation or live privilege change is part of validation. Existing prerequisite skips were retained; no test or finding was suppressed to obtain a pass.

Series navigation: Series index; previous step. Next step.

Review follow-up (2026-10-09): Restacked on the corrected preceding branches. The SNMP status fix is introduced in #638, the reindex/completion fixes in #640, and focused regression coverage in #650.

Restacked tip validation: isolated Linux arm64 build and make check passed (18 passed, 1 setuid prerequisite skip, no failures).
GitHub checks validate the updated published commits; earlier profile/archive/sanitizer evidence above belongs to the previous revisions.

Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
@somethingwithproof
somethingwithproof force-pushed the refactor/c17-series-09-modules branch from 260284c to 4552431 Compare October 10, 2026 00:17
@somethingwithproof
somethingwithproof force-pushed the refactor/c17-series-10-boundaries branch from 15a47a5 to 169fa2b Compare October 10, 2026 00:17
@somethingwithproof somethingwithproof self-assigned this Oct 10, 2026
TheWitness pushed a commit that referenced this pull request Oct 11, 2026
…638)

Introduce bounded native interfaces and grouped runtime state, then link
regression and fault contracts against the real poller implementations.
The contracts capture CLI/configuration input, availability
combinations, SNMP request/response ownership, script framing,
reindexing, output persistence, worker completion and shutdown. This
foundational change is larger because the shared interfaces and their
existing production contracts must move together; later changes have
separate review boundaries.

Step 1/14 of the complete C17/native-correctness series. Base: develop.

Earlier validation, before this review follow-up, in isolated copied
snapshots on Linux arm64:

- Clean GCC build and make check: 13 passed, 0 existing prerequisite
skips, 0 failures.
- ASan/UBSan: 12 passed, 1 existing privilege/allocator-interposition
prerequisite skips, 0 failures; no sanitizer findings.
- Production source/profile integrity verification against disposable
MariaDB and loopback SNMP fixtures passed.
- Release archive extracted into a separate source tree and built/tested
out of tree; fuzz checks passed.

Earlier local profiles retain source hashes for the copied validation
tree; GitHub checks validate the published commit. No production
database/device, host installation or live privilege change is part of
validation. Existing prerequisite skips were retained; no test or
finding was suppressed to obtain a pass.


The worker contracts publish owned heap state and release it only after
joining workers and restoring the runtime table. Coverage counters use
atomic updates; cppcheck receives an explicit model of the fatal exit
contract. Fixture images use public mirrors to avoid shared Docker Hub
pull limits.


Series navigation: review and merge in order. Every PR targets the
preceding branch so its diff contains one step.

1. [refactor(core): add bounded native interfaces and polling
contracts](#638)
2. [fix(privileges): drop root before input and retain owned ICMP
sockets](#639)
3. [fix(poller): isolate worker failures and bound database
reconnects](#640)
4. [fix(results): normalize output and unify SNMP batch
persistence](#641)
5. [fix(runtime): bound probe retries and validate CLI and
configuration](#642)
6. [build: select GNU C17 explicitly and probe hardening
support](#643)
7. [fix(threads): size worker stacks and guard size
arithmetic](#644)
8. [refactor(c17): simplify ownership guards and share test
support](#645)
9. [refactor(core): extract configuration polling and runtime
modules](#646)
10. [fix(boundaries): validate script slots and make cleanup
portable](#647)
11. [refactor(layout): organize responsibilities and separate main from
runtime](#648)
12. [docs(license): adopt SPDX notices and retain contributor
credits](#649)
13. [test(runtime): measure all suites and cover protocol
boundaries](#650)
14. [build(ci): validate connectors time width and native C17
modules](#651)

Review follow-up (2026-10-09): Publish the decoded GET/GETNEXT status
back to the host so availability checks observe exception and
missing-response failures, while preserving the legacy transport-success
behavior for agent PDU errors.

Updated step 1 snapshot: isolated Linux arm64 build and make check
passed (13 passed, no skips or failures).
The restacked tip passes all five clang-tidy gate regression tests and
real clang-tidy analysis (26 reviewed baseline findings, no new
findings). Actionlint and matching DCO trailers pass. The setuid test
also passes when run in the separate disposable root container.
GitHub checks validate the updated published commits; earlier
profile/archive/sanitizer evidence above belongs to the previous
revisions.

---------

Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
@TheWitness
TheWitness merged commit 992b911 into refactor/c17-series-09-modules Oct 11, 2026
20 of 38 checks passed
@TheWitness
TheWitness deleted the refactor/c17-series-10-boundaries branch October 11, 2026 00:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants