From: Patrick Steinhardt Date: Mon, 08 Sep 2025 06:44:17 GMT Subject: Re: [PATCH RFC 2/3] rust: implement a test balloon via the "varint" subsystem Message-ID: In-Reply-To: <8A7DBC60-286A-48FE-A3D3-CAFC11FD3AEA@gmail.com> On Sun, Sep 07, 2025 at 04:07:17PM -0400, Ben Knoble wrote: > > diff --git a/src/varint.rs b/src/varint.rs > > new file mode 100644 > > index 00000000000..3d41760a555 > > --- /dev/null > > +++ b/src/varint.rs > > @@ -0,0 +1,92 @@ > > +use std::os::raw::c_int; > > +use std::os::raw::c_uchar; > > + > > +#[no_mangle] > > +pub unsafe extern "C" fn decode_varint(bufp: *mut *const c_uchar) -> usize { > > + let mut buf = *bufp; > > + let mut c = *buf; > > + let mut val = usize::from(c & 127); > > + > > + buf = buf.add(1); > > + > > + while (c & 128) != 0 { > > + val += 1; > > + if val == 0 || val.leading_zeros() < 7 { > > + return 0; // overflow > > Hm. I thought overflows panic in debug builds, in which case checking > afterwards is too late? Does unsafe change that? I've added a test now and made this an explicit `wrapping_add()`. Patrick