Skip to content

fix: pad encode_hash_with_base output to fixed length to prevent slice panics#8320

Merged
graphite-app[bot] merged 1 commit intomainfrom
02-13-fix_pad_encode_hash_with_base_output_to_fixed_length_to_prevent_slice_panics
Feb 13, 2026
Merged

fix: pad encode_hash_with_base output to fixed length to prevent slice panics#8320
graphite-app[bot] merged 1 commit intomainfrom
02-13-fix_pad_encode_hash_with_base_output_to_fixed_length_to_prevent_slice_panics

Conversation

@shulaoda
Copy link
Member

@shulaoda shulaoda commented Feb 13, 2026

closes #8270, related to rollup/rollup#5720

Summary

base_encode::to_string performs a true mathematical base conversion (repeated division), which produces variable-length output depending on the numeric magnitude of the input. For a 128-bit xxhash encoded in base 64, the output is typically 21 or 22 characters (~75% chance of 22, ~25% chance of 21), and can be shorter (~0.4% chance) if the least-significant bytes of the hash happen to be zero.

This caused two issues:

  1. Potential panic: Callers slice the hash at fixed offsets (e.g. hash[..placeholder.len()]), which panics if the hash string is shorter than expected.
  2. Incorrect MAX_HASH_SIZE: It was set to 21, but the actual maximum for base 64 is ceil(128/6) = 22, preventing users from using [hash:22].

Additional

For the xxhash use case, the 128-bit hash output is approximately uniformly random. Having 13+ leading zero bytes would require a probability of 1/256¹³ ≈ 10⁻³¹, which is practically impossible. In practice, the output is almost always 21 characters (~75%) or 22 characters (~25%), with an occasional 20 characters (~0.4%).

Copy link
Member Author

shulaoda commented Feb 13, 2026


How to use the Graphite Merge Queue

Add the label graphite: merge-when-ready to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@shulaoda shulaoda changed the title fix: pad encode_hash_with_base output to fixed length to prevent slice panics fix: pad encode_hash_with_base output to fixed length to prevent slice panics Feb 13, 2026
@shulaoda shulaoda marked this pull request as ready for review February 13, 2026 10:07
@shulaoda
Copy link
Member Author

I’ll submit a PR to Rollup later.

@github-actions
Copy link
Contributor

github-actions bot commented Feb 13, 2026

Benchmarks Rust

  • target: 02-13-fix_xxhash_with_base_skips_hashing_when_input_is_exactly_16_bytes(1060b4f)
  • pr: 02-13-fix_pad_encode_hash_with_base_output_to_fixed_length_to_prevent_slice_panics(683a780)
group                                                        pr                                     target
-----                                                        --                                     ------
bundle/bundle@multi-duplicated-top-level-symbol              1.00     70.0±2.43ms        ? ?/sec    1.04     73.0±4.33ms        ? ?/sec
bundle/bundle@multi-duplicated-top-level-symbol-sourcemap    1.01     77.3±2.40ms        ? ?/sec    1.00     76.4±1.77ms        ? ?/sec
bundle/bundle@rome_ts                                        1.02    103.6±5.89ms        ? ?/sec    1.00    101.5±2.14ms        ? ?/sec
bundle/bundle@rome_ts-sourcemap                              1.00    112.0±2.34ms        ? ?/sec    1.01    112.8±2.24ms        ? ?/sec
bundle/bundle@threejs                                        1.00     35.4±0.96ms        ? ?/sec    1.00     35.5±2.23ms        ? ?/sec
bundle/bundle@threejs-sourcemap                              1.00     40.0±0.54ms        ? ?/sec    1.01     40.6±0.91ms        ? ?/sec
bundle/bundle@threejs10x                                     1.02    371.5±4.90ms        ? ?/sec    1.00    365.9±5.59ms        ? ?/sec
bundle/bundle@threejs10x-sourcemap                           1.01    427.9±6.72ms        ? ?/sec    1.00    423.3±4.98ms        ? ?/sec
scan/scan@rome_ts                                            1.00     80.2±2.45ms        ? ?/sec    1.02     82.1±1.79ms        ? ?/sec
scan/scan@threejs                                            1.00     28.5±1.56ms        ? ?/sec    1.00     28.3±1.63ms        ? ?/sec
scan/scan@threejs10x                                         1.00    275.2±2.88ms        ? ?/sec    1.02    280.1±4.11ms        ? ?/sec

@shulaoda shulaoda force-pushed the 02-13-fix_pad_encode_hash_with_base_output_to_fixed_length_to_prevent_slice_panics branch from a5f6a49 to 683a780 Compare February 13, 2026 12:10
Copy link
Member Author

shulaoda commented Feb 13, 2026

Merge activity

  • Feb 13, 12:32 PM UTC: The merge label 'graphite: merge-when-ready' was detected. This PR will be added to the Graphite merge queue once it meets the requirements.
  • Feb 13, 12:35 PM UTC: shulaoda added this pull request to the Graphite merge queue.
  • Feb 13, 12:47 PM UTC: Merged by the Graphite merge queue.

…ice panics (#8320)

closes #8270, related to rollup/rollup#5720

### Summary

`base_encode::to_string` performs a true mathematical base conversion (repeated division), which produces **variable-length output** depending on the numeric magnitude of the input. For a 128-bit xxhash encoded in base 64, the output is typically 21 or 22 characters (~75% chance of 22, ~25% chance of 21), and can be shorter (~0.4% chance) if the least-significant bytes of the hash happen to be zero.

This caused two issues:

1. **Potential panic**: Callers slice the hash at fixed offsets (e.g. `hash[..placeholder.len()]`), which panics if the hash string is shorter than expected.
2. **Incorrect `MAX_HASH_SIZE`**: It was set to 21, but the actual maximum for base 64 is `ceil(128/6) = 22`, preventing users from using `[hash:22]`.

### Additional

For the xxhash use case, the 128-bit hash output is approximately uniformly random. Having 13+ leading zero bytes would require a probability of   `1/256¹³ ≈ 10⁻³¹`, which is practically impossible. In practice, the output is almost always 21 characters (~75%) or 22 characters (~25%), with   an occasional 20 characters (~0.4%).
@graphite-app graphite-app bot force-pushed the 02-13-fix_xxhash_with_base_skips_hashing_when_input_is_exactly_16_bytes branch from 1060b4f to c353b67 Compare February 13, 2026 12:36
@graphite-app graphite-app bot force-pushed the 02-13-fix_pad_encode_hash_with_base_output_to_fixed_length_to_prevent_slice_panics branch from 683a780 to fa8851a Compare February 13, 2026 12:36
Base automatically changed from 02-13-fix_xxhash_with_base_skips_hashing_when_input_is_exactly_16_bytes to main February 13, 2026 12:46
@graphite-app graphite-app bot merged commit fa8851a into main Feb 13, 2026
31 checks passed
@graphite-app graphite-app bot deleted the 02-13-fix_pad_encode_hash_with_base_output_to_fixed_length_to_prevent_slice_panics branch February 13, 2026 12:47
shulaoda pushed a commit that referenced this pull request Feb 18, 2026
## [1.0.0-rc.5] - 2026-02-18

💡 Smarter `entriesAware` Manual Code Splitting                                                                 
                                             
New `entriesAware` and `entriesAwareMergeThreshold` options for `manualCodeSplitting.groups[]` enable              
entry-reachability-based chunk splitting with automatic small chunk merging.                                       
                                                                                                                   
- `entriesAware: true` splits matched modules by entry reachability — modules reached by the same set of entries are grouped together, providing the most precise loading behavior with less over-fetching
- Chunks now get more readable names reflecting their entry associations (e.g. `vendor-entry-a-entry-b.js`) instead of opaque hashes
- `entriesAwareMergeThreshold` sets a byte-size threshold to merge tiny subgroups into the closest sibling with the fewest extra entries, reducing micro-chunk fragmentation while preserving precision
- Recommended to use together with `maxSize`: merge tiny chunks first to reduce request overhead, then cap large chunks to control payload size

```js
manualCodeSplitting: {
  groups: [{
    name: 'vendor',
    test: /node_modules/,
    entriesAware: true,
    entriesAwareMergeThreshold: 28000, // bytes
  }]
}
```

### 🚀 Features

- add `Visitor` to `rolldown/utils` (#8373) by @sapphi-red
- module-info: add `inputFormat` property to `ModuleInfo` (#8329) by @shulaoda
- default `treeshake.invalid_import_side_effects` to `false` (#8357) by @sapphi-red
- rolldown_utils: add `IndexBitSet` (#8343) by @sapphi-red
- rolldown_utils: add more methods and trait impls to BitSet (#8342) by @sapphi-red
- rolldown_plugin_vite_build_import_analysis: add support for `await import().then((m) => m.prop)` (#8328) by @sapphi-red
- rolldown_plugin_vite_reporter: support custom logger for build infos (#7652) by @shulaoda
- rust/mcs: support `entriesAwareMergeThreshold` (#8312) by @hyf0
- mcs: `maxSize` will split the oversized chunk with taking file relevance into account (#8277) by @hyf0
- rolldown_plugin_vite_import_glob: support template literal in glob import patterns (#8298) by @shulaoda
- rolldown_plugin_chunk_import_map: output importmap without spaces (#8297) by @sapphi-red
- add INEFFECTIVE_DYNAMIC_IMPORT warning in core (#8284) by @shulaoda
- mcs: generate more readable name for `entriesAware` chunks (#8275) by @hyf0
- mcs: support `entriesAware` (#8274) by @hyf0

### 🐛 Bug Fixes

- improve circular dependency detection in chunk optimizer (#8371) by @IWANABETHATGUY
- align `minify.compress: true` and `minify.mangle: true` with `minify: true` (#8367) by @sapphi-red
- rolldown_plugin_esm_external_require: apply conversion to UMD and IIFE outputs (#8359) by @sapphi-red
- cjs: bailout treeshaking on cjs modules that have multiple re-exports (#8348) by @hyf0
- handle member expression and this expression in JSX element name rewriting (#8323) by @IWANABETHATGUY
- pad `encode_hash_with_base` output to fixed length to prevent slice panics (#8320) by @shulaoda
- `xxhash_with_base` skips hashing when input is exactly 16 bytes (#8319) by @shulaoda
- complete `ImportKind::try_from` with missing variants and correct `url-import` to `url-token` (#8310) by @shulaoda
- mark Node.js builtin modules as side-effect-free when resolved via `external` config (#8304) by @IWANABETHATGUY
- mcs: `maxSize` should split chunks correctly based on sizes (#8289) by @hyf0

### 🚜 Refactor

- introduce `RawMangleOptions` and `RawCompressOptions` (#8366) by @sapphi-red
- mcs: refactor `apply_manual_code_splitting` into `ManualSplitter` (#8346) by @hyf0
- rolldown_plugin_vite_reporter: simplify hook registration and remove redundant state (#8322) by @shulaoda
- use set to store user defined entry modules (#8315) by @IWANABETHATGUY
- rust/mcs: collect groups into map at first for having clean and performant operations (#8313) by @hyf0
- mcs: introduce newtype `ModuleGroupOrigin` and `ModuleGroupId` (#8311) by @hyf0
- remove unnecessary `FinalizerMutableState` struct (#8303) by @shulaoda
- move module finalization into `finalize_modules` (#8302) by @shulaoda
- extract `apply_transfer_parts_mutation` into its own module (#8301) by @shulaoda
- move ESM format check into `determine_export_mode` (#8294) by @shulaoda
- remove `warnings` field from `GenerateContext` (#8293) by @shulaoda
- extract util function remove clippy supression (#8290) by @IWANABETHATGUY
- move `is_in_node_modules` to `PathExt` trait in `rolldown_std_utils` (#8286) by @shulaoda
- rolldown_plugin_vite_reporter: remove unnecessary ineffective dynamic import detection logic (#8285) by @shulaoda
- dev: inject hmr runtime to `\0rolldown/runtime.js` (#8234) by @hyf0
- improve naming in chunk_optimizer (#8287) by @IWANABETHATGUY
- simplify PostChunkOptimizationOperation from bitflags to enum (#8283) by @IWANABETHATGUY
- optimize BitSet.index_of_one to return iterator instead of Vec (#8282) by @IWANABETHATGUY

### 📚 Documentation

- change default value in `format` JSDoc from `'esm'` to `'es'` (#8372) by @shulaoda
- in-depth: remove `invalidImportSideEffects` option mention from lazy barrel optimization doc (#8355) by @sapphi-red
- mcs: clarify `minSize` constraints (#8279) by @ShroXd

### ⚡ Performance

- use IndexVec for chunk TLA detection (#8341) by @sapphi-red
- only invoke single resolve call for the same specifier and import kind (#8332) by @sapphi-red
- rolldown_plugin_vite_reporter: skip gzip computation when `report_compressed_size` is disabled (#8321) by @shulaoda

### 🧪 Testing

- use `vi.waitFor` and `expect.poll` instead of custom `waitUtil` function (#8369) by @sapphi-red
- rolldown_plugin_esm_external_require_plugin: add tests (#8358) by @sapphi-red
- add watch file tests (#8330) by @sapphi-red
- rolldown_plugin_vite_build_import_analysis: add test for dynamic import treeshaking (#8327) by @sapphi-red

### ⚙️ Miscellaneous Tasks

- prepare-release: skip workflow on forked repositories (#8368) by @shulaoda
- format more files (#8360) by @sapphi-red
- deps: update oxc to v0.114.0 (#8347) by @camc314
- deps: update test262 submodule for tests (#8354) by @sapphi-red
- deps: update crate-ci/typos action to v1.43.5 (#8350) by @renovate[bot]
- deps: update oxc apps (#8351) by @renovate[bot]
- rolldown_plugin_vite_reporter: remove unnecessary README.md (#8334) by @shulaoda
- deps: update npm packages (#8338) by @renovate[bot]
- deps: update rust crates (#8339) by @renovate[bot]
- deps: update dependency oxlint-tsgolint to v0.13.0 (#8337) by @renovate[bot]
- deps: update github-actions (#8336) by @renovate[bot]
- deps: update napi to v3.8.3 (#8331) by @renovate[bot]
- deps: update dependency oxlint-tsgolint to v0.12.2 (#8325) by @renovate[bot]
- remove unnecessary transform.decorator (#8314) by @IWANABETHATGUY
- deps: update dependency rust to v1.93.1 (#8305) by @renovate[bot]
- deps: update dependency oxlint-tsgolint to v0.12.1 (#8300) by @renovate[bot]
- deps: update oxc apps (#8296) by @renovate[bot]
- docs: don't skip for build runs without cache (#8281) by @sapphi-red
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Panic]: byte index 21 is out of bounds of AQZUku11Kfs-GgIXiQXV

3 participants