11b9ebde
c_runtime: strict-decode parity with pure-Lua codec (rc8)
The C decoder accepted wire types 6/7, field number 0, field numbers beyond 29 bits, overlong tag varints, invalid UTF-8 in string fields, and unmatched proto2 SGROUPs — each of which the pure-Lua decoder already rejected. It also replaced (instead of merged) when a singular message field appeared more than once on the wire, dropping sub-message scalars from the prior occurrence. decode_body: reject wt 6/7 / field 0 / fn > 2^29-1 / overlong tag varint up front; track egroup_seen so a group body that runs off the end of the buffer fails loudly. dec_push_kind STRING: port wire.lua's RFC 3629 validator (utf8.len equivalent) — covers singular, repeated, oneof, map-key, and map-value via the same code path. Singular message dispatch in decode_body and decode_extension_into: look up an existing prev table at result[name] and merge via the new merge_subresult_into, which ports codec.lua's merge_message (recursive sub-message, repeated concat, map last-wins per key, skip for WKT custom-decode). Regression coverage in test/conformance_test.lua's conformance.core group: pre-existing tests already pinned the wire-type, tag, UTF-8 (singular/repeated/oneof), and merge cases — those now also exercise the C path under PB_ENABLE_C=1. Two gaps remained — map-key/value UTF-8 and proto2 group balancing — both covered now via four new tests, with proto2 routed through a TestAllTypesProto2 helper. PB_ENABLE_C=1 just test: 1043/1043 (baseline 1039 + 4 new). PB_ENABLE_C=1 just conformance-c: 0 unexpected failures (was 77). just conformance (pure-Lua path): unchanged — no regression. Closes rc8
Eugene Blikh <bigbes@gmail.com> — 2026-05-23 19:52:05 UTC
Commit 11b9ebde83fd05574699fd26b0fd3c82117ab6bb —
view raw patch
Parent(s):
1eb062c1
| File | Status | + | − |
|---|---|---|---|
runtime/pb/c/c_runtime.c
|
M | +276 | -5 |
test/conformance_test.lua
|
M | +65 |