diff --git a/verify/fuzz.go b/verify/fuzz.go index 0fae1ca..d52ad26 100644 --- a/verify/fuzz.go +++ b/verify/fuzz.go @@ -221,7 +221,10 @@ func genDualArgs(rng *rand.Rand, sig funcSig, argSize int) (gasmArgs, goArgs []b } else { declaredLen = n + 512 } - bufBytes := (declaredLen+16)*elemSize + 128 + // Allocate a buffer comfortably larger than declaredLen*elemSize so + // that SIMD over-reads and functions that write slightly past len + // (e.g. decoders that trust len(src)) never touch unmapped memory. + bufBytes := declaredLen*elemSize + 8192 // Two independent buffers with identical random content. buf1 := make([]byte, bufBytes) buf2 := make([]byte, bufBytes) @@ -230,6 +233,8 @@ func genDualArgs(rng *rand.Rand, sig funcSig, argSize int) (gasmArgs, goArgs []b bufs = append(bufs, buf1, buf2) putPtr(gasmArgs, off, unsafe.Pointer(&buf1[0])) putPtr(goArgs, off, unsafe.Pointer(&buf2[0])) + // len and cap both equal declaredLen — the buffer is guaranteed + // to hold at least declaredLen elements plus safety margin. putU64(gasmArgs, off+8, uint64(declaredLen)) putU64(gasmArgs, off+16, uint64(declaredLen)) putU64(goArgs, off+8, uint64(declaredLen))