core:encoding/base64 currently decodes leniently: it infers padding from the
last one or two bytes, accepts missing/extra/interior padding, and does not
check the trailing padding bits required by RFC 4648 Section 3.5.
Go exposes canonical decoding as `Encoding.Strict()`; Odin has no equivalent,
so downstream ports (e.g. age) have to reimplement base64 from scratch.
This adds opt-in strict decoding through a `Decode_Options` bit set.
Existing calls and behavior are unchanged.
`constant: U : value` produced a constant of the wrong type:
lb_const_value took its union-lowering branch only when
`is_type_union_constantable(type)` held, so for a union with a variant
that whitelist rejects (`union{bool, ^int}`) the value fell through to
the scalar branch and reached `LLVMConstInt(lb_type(m, union_type),
...)`. The constant emitted there does not match the union's type:
bytes that change between runs for `true`, a compiler crash for `1.0`,
an `is_type_string` assertion for a string literal.
The checker already resolves which variant a constant represents and
records it in `ExactValue::variant_type` - the variant type, tag index,
payload and padding the union branch needs - so that branch is now also
taken when the value pins a variant this backend can build as a
constant. The type-level whitelist was re-guessing information the
value already carries; variant types this backend cannot build as
constants (`any`) stay excluded.
lb_build_static_variables had the same defect in another place: it
lowered an initializer with the expression's type instead of the
declared type, so `@(static) s: U` emitted a payload-only constant and
LLVM rejected the module with “Global variable initializer type does not
match global variable type!”. It now passes the declared type and gives
the global the constant's layout-compatible type, the way the file-scope
path already does.
Blast radius: every union-typed constant, i.e. typed constants, global
static initializers, @(static)/@(thread_local)/@(rodata), default
parameters and constant aggregate elements. Unions whose variants are
all constantable keep the previous path.
Step 4 (t0 = x^0xc) passed x^1 (&xx) instead of x^3 (out1), producing
an incorrect exponent and rejecting valid quadratic residues. This broke
compressed SEC1 P-256 point decoding via pt_set_sec_bytes.
unquote_string replaces each byte that is not valid UTF-8 with U+FFFD,
which is three bytes for one, but sized its buffer as len(s) + 2*UTF_MAX:
slack for a single replacement, not for one per invalid byte. A string
holding several ran the write cursor past the end, an out-of-range slice
under bounds checking and a memory-safety bug without it.
Count the invalid bytes in the remainder up front and size for them. The
escape sequences never grow their input, so they need no allowance.
`check_scope_decls` iterates a scope's entity map while
`check_entity_decl` can insert into that same scope: a procedure alias
(`f :: e`) goes through `override_entity_in_scope`, which calls
`scope_map_insert`. The map grows at 75% load (12 of 16 slots, then 24
of 32), and `scope_map_insert` grows before it probes for the key, so
even an alias that only replaces an existing value rehashes and
reallocates the table in the middle of the iteration.
`ScopeMapIterator` re-read its map on every step while `end` had
captured the capacity at loop start, so the walk continued over the new
table under the old sentinel: it ran past the end of the reallocated
table and dereferenced whatever followed it as an `Entity *` - a nullptr
dereference for a procedure scope holding exactly 12 or 24 entities - or
it stopped at the stale end index and silently skipped every declaration
that the rehash had moved behind it, which left unused declarations
without any diagnostic at all.
The iterator now snapshots the table pointer and capacity when it is
constructed, so iteration is invariant under any insert or grow and
cannot leave the table it began on. A scope that does not grow behaves
exactly as before: the snapshot points at the same table.
Refs #7598