Skip to content

decompress: add optional -fbounds-safety annotations for ZSTD_inBuffer/outBuffer - #4783

Open
LaptopsPlural wants to merge 1 commit into
facebook:devfrom
LaptopsPlural:local/iobuf-fbounds-safety
Open

decompress: add optional -fbounds-safety annotations for ZSTD_inBuffer/outBuffer#4783
LaptopsPlural wants to merge 1 commit into
facebook:devfrom
LaptopsPlural:local/iobuf-fbounds-safety

Conversation

@LaptopsPlural

@LaptopsPlural LaptopsPlural commented Sep 11, 2026

Copy link
Copy Markdown

Summary

Secure-by-design memory-safety hardening. Annotates streaming ZSTD_inBuffer / ZSTD_outBuffer with optional Clang -fbounds-safety / sized-by-style macros. Default builds unchanged (opt-in OFF).

Contributor: Jeff Bindel via LaptopsPlural. Not a vulnerability PoC.

Test plan

  • Default build / tests
  • Optional bounds-safety ON with supporting Clang (maintainers)

…r/outBuffer

Introduce inert ZSTD_SIZED_BY*_ macros (OFF by default) and annotate the
streaming buffer structs used by ZSTD_decompressStream. Capacity-first
assign in ZSTD_decompressStream_simpleArgs. Default builds unchanged;
ENABLE_FBOUNDS_SAFETY / ZSTD_ENABLE_FBOUNDS_SAFETY opt-in for experimental
Clang toolchains.
@meta-cla

meta-cla Bot commented Sep 11, 2026

Copy link
Copy Markdown

Hi @LaptopsPlural!

Thank you for your pull request and welcome to our community.

Action Required

In order to merge any pull request (code, docs, etc.), we require contributors to sign our Contributor License Agreement, and we don't seem to have one on file for you.

Process

In order for us to review and merge your suggested changes, please sign at https://code.facebook.com/cla. If you are contributing on behalf of someone else (eg your employer), the individual CLA may not be sufficient and your employer may need to sign the corporate CLA.

Once the CLA is signed, our tooling will perform checks and validations. Afterwards, the pull request will be tagged with CLA signed. The tagging process may take up to 1 hour after signing. Please give it that time before contacting us about it.

If you have received this in error or have any questions, please contact us at cla@meta.com. Thanks!

@meta-cla meta-cla Bot added the CLA Signed label Sep 11, 2026
@meta-cla

meta-cla Bot commented Sep 11, 2026

Copy link
Copy Markdown

Thank you for signing our Contributor License Agreement. We can now accept your code for this (and any) Meta Open Source project. Thanks!

@LaptopsPlural
LaptopsPlural force-pushed the local/iobuf-fbounds-safety branch from b7bc7e8 to 02a330b Compare September 12, 2026 03:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant