From cc1932136bf67cfd97aeed9f941778158ce4824c Mon Sep 17 00:00:00 2001 From: Perplexity Computer Date: Sat, 4 Jul 2026 13:46:01 +0000 Subject: [PATCH] feat(wire): delegate parse-path u32 reassembly to auto-gen u32_be MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Replace `u32::from_be_bytes(b[2..6].try_into().ok()?)` (and the dst-slot equivalent) with `u32_be(b[2], b[3], b[4], b[5])` — the auto-generated function produced by t27c from specs/wire.t27. Byte-order equivalence: - `u32::from_be_bytes([b0,b1,b2,b3])` = (b0<<24)|(b1<<16)|(b2<<8)|b3. - t27c-generated `u32_be(b0,b1,b2,b3)` = same expression (see gen/rust/wire.rs). - `try_into().ok()?` on a 4-byte slice never returns None post the length check on line 82; removing it eliminates a dead error path. Consequence: the parse-side arithmetic now lives under the SSOT contract. spec-drift-guard CI (workflow spec-drift-guard.yml, merged in #35) is the enforcement mechanism — any drift between specs/wire.t27 and gen/rust/wire.rs now covers this reassembly path as well. Closes weak-spot audit finding #5 (post-#33 loop): src/wire.rs still used std::from_be_bytes rather than delegating to the auto-gen equivalent, so the parse-path was outside the SSOT umbrella even though the serialize-path (header_byte + be_byte) was inside. Also re-exports `be_byte` and `u32_be` from the `gen` module for symmetry with the other spec-driven helpers. Verification (local): - `cargo build`: clean. - `cargo test --lib`: 101 passed / 0 failed. In particular `wire::tests::header_roundtrips` still passes, confirming byte-order equivalence end-to-end. Anchor: phi^2 + phi^-2 = 3. --- src/wire.rs | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/src/wire.rs b/src/wire.rs index 271943f2..d45375e1 100644 --- a/src/wire.rs +++ b/src/wire.rs @@ -26,7 +26,8 @@ pub mod gen { } pub use gen::{ - frame_kind_valid, header_byte, parse_accepts, HEADER_LEN, KIND_DATA, KIND_HELLO, VERSION, + be_byte, frame_kind_valid, header_byte, parse_accepts, u32_be, HEADER_LEN, KIND_DATA, + KIND_HELLO, VERSION, }; #[derive(Clone, Copy, Debug, PartialEq, Eq)] @@ -87,8 +88,12 @@ impl Header { } Some(Self { kind: FrameKind::from_u8(b[1])?, - src: u32::from_be_bytes(b[2..6].try_into().ok()?), - dst: u32::from_be_bytes(b[6..10].try_into().ok()?), + // SSOT: reassemble big-endian u32 via the auto-generated u32_be from + // specs/wire.t27 (byte-order equivalent to u32::from_be_bytes; see + // docs/T27_FIRST_MIGRATION.md). Keeps the parse-path arithmetic under + // the spec-drift-guard CI umbrella. + src: u32_be(b[2], b[3], b[4], b[5]), + dst: u32_be(b[6], b[7], b[8], b[9]), ttl: b[10], }) }