fix: harden SMT, JSON input, and TVM gas estimation - #150
Merged
CodeNinjaEvan merged 2 commits intoJul 31, 2026
Conversation
|
Thank you for your contribution to the Solidity compiler! A team member will follow up shortly. If you haven't read our contributing guidelines and our review checklist before, please do it now, this makes the reviewing process and accepting your contribution smoother. If you have any questions or need our help, feel free to post them in the PR or talk to us directly on the #solidity-dev channel on Matrix. |
yanghang8612
marked this pull request as ready for review
July 31, 2026 01:52
CodeNinjaEvan
approved these changes
Jul 31, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
chain.*,msg.tokenid, andmsg.tokenvaluemagic membersuintreturn valuesDELEGATECALLruntime semanticsJSONErrorresultsMCOPY,NATIVEVOTE,CREATE2, andEXPrulessun/trxdenominationsRoot cause and impact
The TRON transaction tuple used by SMTChecker did not include all magic members exposed by the type system. Legal contracts could therefore hit an assertion or an uncaught map lookup, and nonpayable functions did not constrain TRC-10 call fields. In addition, state-changing TRON builtins with
uintreturns were left as unbounded mathematical integers after symbolic state invalidation, which could produce false BMC/CHC counterexamples.Nonpayable constraints were also applied to public library functions even though both code generators intentionally omit value and token guards for libraries. Since
DELEGATECALLpreserves the caller's transaction context, this allowed BMC and CHC to falsely prove assertions aboutmsg.value,msg.tokenid, andmsg.tokenvalue. Library entry points now remain unconstrained while ordinary nonpayable contracts retain the zero-value assumptions.Standard JSON validation skipped type checks for some empty JSON values and performed unchecked string conversions for
languageandsettings.debug.debugInfo. Malformed input could therefore be silently accepted or surface as an internal nlohmann exception. The parser now validates these shapes before conversion and consistently returnsJSONError.Gas estimation used wrapping
u256arithmetic for memory ranges and did not enforce TVM's 3 MiB memory limit. It also omitted theCREATE2init-code hash charge and used fork-dependent EthereumEXPbyte pricing. The revised model uses checkedbigintrange calculations, handlesMCOPYandNATIVEVOTEwithout wraparound, chargesCREATE2per init-code word, and uses TVM's fixedEXPcost across legacy and via-IR optimizer metrics. These changes affect estimates and optimization choices, not VM execution semantics.Validation
solcandsoltestStandardCompilersuite: 65/65 passedEvmasmGasMeter: 13/13 passedOptimiser: 94/94 passedYulEVMMetrics: 1/1 passedgit diff --checkpassed