Skip to content

tlv-account-resolution: error instead of panicking on malformed input - #207

Merged
joncinque merged 2 commits into
solana-program:mainfrom
latent-9:tlv-error-on-malformed-input
Oct 2, 2026
Merged

joncinque merged 2 commits into
solana-program:mainfrom
latent-9:tlv-error-on-malformed-input

Conversation

@latent-9

Copy link
Copy Markdown
Contributor

Problem

ExtraAccountMetaList::check_account_infos panicked in two paths:

  1. TlvStateBorrowed::unpack(data).unwrap() — a malformed validation account (a truncated TLV entry) panicked instead of returning a ProgramError.
  2. account_infos.len() - extra_meta_list.len() — when the caller provided fewer account infos than the validation data's extra accounts, the subtraction underflowed: panic in debug/overflow-checks builds, and a wrap to a huge value in release builds that produced a misleading IncorrectAccount error.

This is reachable from consuming programs' transfer-hook validation, where the account list comes from the transaction author (a crafted transaction with fewer accounts than the hook requires). The AccountResolutionError::NotEnoughAccounts variant existed with its message but was never constructed — the check was clearly intended but omitted. The async sibling add_to_instruction already propagates the unpack error with ?; check_account_infos did not.

Change

  • check_account_infos propagates the validation-data unpack error with ? instead of unwrapping.
  • The initial-accounts-length subtraction is checked with checked_sub and returns AccountResolutionError::NotEnoughAccounts.

Tests

Two new tests: a caller providing fewer account infos than extra metas receives NotEnoughAccounts (previously a panic), and corrupted validation data returns an error (previously a panic). The existing check_account_infos_test passes unchanged (the correct path is untouched). cargo test -p spl-tlv-account-resolution passes (18 tests, run repeatedly) and clippy/fmt are green.

check_account_infos panicked on a malformed validation account (TlvStateBorrowed::unpack(data).unwrap()) and underflowed when the caller provided fewer account infos than the validation data's extra accounts require — a subtraction that wrapped to a huge value in release builds and produced a misleading IncorrectAccount error. The AccountResolutionError::NotEnoughAccounts variant existed but was never constructed. The validation-data unpack now propagates the error, and the subtraction is checked against NotEnoughAccounts.

@joncinque joncinque left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your contribution! This is mostly called in tests and the example transfer hook program, so the panicking isn't a problem, but it doesn't hurt to return errors, since the function already does that.

Just some nits to clean up the unnecessary comments

Comment thread tlv-account-resolution/src/state.rs Outdated
Comment on lines +221 to +222
// Ensure the caller provided enough account infos to hold the extra
// accounts, or the subtraction below underflows.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: can you remove this comment? It doesn't add much information

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed all three, thanks!

Comment thread tlv-account-resolution/src/state.rs Outdated
Comment on lines +1715 to +1717
// A caller (or crafted transaction) providing fewer account infos than
// the validation data's extra accounts must error, not underflow the
// initial-accounts-length subtraction.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: can you remove this comment too?

Comment thread tlv-account-resolution/src/state.rs Outdated
Comment on lines +1746 to +1747
// A corrupted validation account (truncated TLV entry) must error
// instead of panicking on the unpack.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: can you remove this comment too?

@latent-9

latent-9 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@joncinque all three comments removed, pushed to the branch — thanks!

@joncinque joncinque left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@joncinque
joncinque merged commit 4331de4 into solana-program:main Oct 2, 2026
54 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants