fix: validate builtin arity before argument access
This commit is contained in:
@@ -9,6 +9,21 @@ This file is the beginner-safe status map for the current package. It separates
|
||||
- **Experimental/planned**: do not rely on it in beginner lessons yet.
|
||||
- **Historical**: kept for release history, not current instructions.
|
||||
|
||||
## Security and correctness review progress
|
||||
|
||||
The v1.18.26 review identified missing-argument reads in standard-library built-ins. The current runtime now validates required argument counts centrally before any builtin indexes `args[]`. Covered calls include `math.abs`, `math.clamp`, `random.seed`, `random.int`, text helpers, CSV helpers, path helpers, and collection helpers. Missing arguments produce a beginner-facing `needs N arguments` runtime error.
|
||||
|
||||
Focused regression coverage: `tests/38_builtin_arity.claro`.
|
||||
|
||||
Verified in this checkout on 2026-09-22:
|
||||
|
||||
- `gcc -std=c99 -O0 -g -fsanitize=address,undefined src/claro.c -o /tmp/claro-asan -lm` plus `ASAN_OPTIONS=detect_leaks=0 /tmp/claro-asan tests/38_builtin_arity.claro`: no AddressSanitizer or UndefinedBehaviorSanitizer report; LeakSanitizer still reports the pre-existing interpreter-wide cleanup backlog when leak detection is enabled.
|
||||
- `./claro test`: `PASS: 0 failure(s)`.
|
||||
- `./claro doctor`: all checks `OK`.
|
||||
- `./claro validate`: validation passed.
|
||||
|
||||
This slice does not yet fix inverted `random.int` ranges, recursion depth, memory cleanup, `LASTEXIT`, HTTP buffering/status handling, or other review findings. Claro remains a trusted-script interpreter, not a sandbox.
|
||||
|
||||
## Feature matrix
|
||||
|
||||
### Beginner scripting core
|
||||
|
||||
Reference in New Issue
Block a user