Backport SOL-2025-1 through SOL-2026-3 fixes to release_0.8.30#141
Closed
yanghang8612 wants to merge 17 commits into
Closed
Backport SOL-2025-1 through SOL-2026-3 fixes to release_0.8.30#141yanghang8612 wants to merge 17 commits into
yanghang8612 wants to merge 17 commits into
Conversation
…and copy) Co-authored-by: Daniel Kirchner <daniel@ekpyron.org> Co-authored-by: clonker <1685266+clonker@users.noreply.github.com> Co-authored-by: Kamil Śliwak <kamil.sliwak@codepoets.it> (cherry picked from commit 2ab47bd)
Co-authored-by: Daniel Kirchner <daniel@ekpyron.org> Co-authored-by: Kamil Śliwak <kamil.sliwak@codepoets.it> (cherry picked from commit 44cdd8d)
…cy and via-ir on deletion, partial assigments and copy Co-authored-by: Daniel Kirchner <daniel@ekpyron.org> Co-authored-by: Kamil Śliwak <kamil.sliwak@codepoets.it> (cherry picked from commit 0495910)
(cherry picked from commit d38b746)
(cherry picked from commit c4dd9e4)
(cherry picked from commit 0983a90)
(cherry picked from commit a0a3dd8)
(cherry picked from commit 139d696)
Use Tarjan's strongly-connected-components algorithm: a function is recursive iff it lies in a non-trivial SCC or has a self-edge. Also add intersection recursive cycles regression test to function specializer tests. (cherry picked from commit 5025618)
These are tests to demonstrate incorrect processing of inheritance hierarchy in the presence of custom storage layout close to the storage end. (cherry picked from commit 2ac7929)
When the compiler emits a warning about storage base location being too close to storage end, it calls a helper function to determine the last storage variable. This helper function previously unintentionally reversed the linearized based contracts annotation. The function only needs to take reversed **view**. It should not modify the underlying data. (cherry picked from commit 9fb715d)
(cherry picked from commit 58bc9f8)
(cherry picked from commit 56edc07)
…nHandle` to utilities (cherry picked from commit 47e36a3)
(cherry picked from commit 422fe84)
…ambiguated (cherry picked from commit d32ee36)
(cherry picked from commit 11815d2)
|
Thank you for your contribution to the Solidity compiler! A team member will follow up shortly. If you haven't read our contributing guidelines and our review checklist before, please do it now, this makes the reviewing process and accepting your contribution smoother. If you have any questions or need our help, feel free to post them in the PR or talk to us directly on the #solidity-dev channel on Matrix. |
Author
|
Superseded by #142 after renaming the fork branch to |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Backports the upstream security fixes corresponding to
SOL-2025-1throughSOL-2026-3torelease_0.8.30, following the already mergedrelease_0.8.31backport in #135.2^256storage boundary in both the legacy and via-IR pipelinesBackport notes
docs/bugs_by_version.jsonconflict by retaining the vulnerability version matrix introduced by the source fixValidation
USE_Z3=OFFstandard_via_ir_intersecting_recursive_cycles_stack_too_deepstorage_layout_specifier_with_inheritancestorage_transient_storage_collision_ir_outputdocs/bugs.jsonanddocs/bugs_by_version.jsonpassed JSON validationSemantic execution and
SolidityOptimizertests were attempted locally but require the TRON test-only EVMC shim for no-tokenCALLTOKENID/CALLTOKENVALUEbehavior. A stock evmone VM rejects deployment, so those results are not reported as passing here. The same fixes passed the full semantic and optimizer validation documented in #135 onrelease_0.8.31; this PR should be rerun in the shim-enabled 0.8.30 test environment before release.Impact
This makes the 0.8.30 release candidate include the same critical compiler correctness and security fixes already accepted for 0.8.31, without merging unrelated 0.8.31 changes.