Skip to content

FunC crashes with fatal assertion when tensor exceeds 254 elements #1682

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
Gusarich opened this issue May 21, 2025 · 0 comments
Open

FunC crashes with fatal assertion when tensor exceeds 254 elements #1682

Gusarich opened this issue May 21, 2025 · 0 comments

Comments

@Gusarich
Copy link

The FunC compiler crashes with a fatal internal assertion if a tensor exceeds 254 elements. The parser and type checker currently allow tensors of arbitrary size without checks, but an internal analyzer asserts a maximum size, causing a sudden crash instead of a proper user-facing error.

Minimal Example:

() main() {
    var x = (
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
        0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0
    );
}

Compiler crash (observed output):

fatal: Assertion failed at analyzer.cpp:46: k <= 254 && n <= 0x7fff00

Cause:
split_vars() in crypto/func/analyzer.cpp enforces a tensor component limit (max 254 elements) using an internal assertion. Since no earlier check exists, larger tensors trigger this assertion, resulting in an abrupt crash.

Expected behavior:
The compiler should detect overly large tensors during parsing or type-checking, rejecting them gracefully with a clear user-facing compilation error instead of crashing.


LLM Fuzzing discovery (see tact-lang/tact#3123)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant