Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 16 additions & 2 deletions languages/golang/stackencrypt/context.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
package stackencrypt

import (
"bytes"
"errors"
"fmt"
)
Expand All @@ -20,6 +21,9 @@ import (
// left, so NewContext("users/age").With(uint64(7)) is the context a row
// sealed with encrypt_into_with_context(row, 7u64) binds for that field.
// A one-element list is not the bare part, and this type cannot spell one.
//
// A Context owns its parts: a byte-slice part is copied in, so a caller's
// buffer reused once the Context is built does not change it.
type Context struct {
node any
}
Expand All @@ -41,7 +45,7 @@ func NewContext(part any) (Context, error) {
if err := checkRootNonEmpty(part); err != nil {
return Context{}, err
}
return Context{node: part}, nil
return Context{node: ownPart(part)}, nil
}

// MustContext is [NewContext] for a part known to be valid; it panics
Expand All @@ -63,7 +67,17 @@ func (c Context) With(part any) (Context, error) {
if err := checkPart(part); err != nil {
return Context{}, err
}
return Context{node: []any{c.node, part}}, nil
return Context{node: []any{c.node, ownPart(part)}}, nil
}

// ownPart is part as a context stores it: a byte slice is copied, so
// neither a Context nor an option that extends one ([ExtendContext])
// aliases a caller's buffer. Every other part type is a value.
func ownPart(part any) any {
if b, ok := part.([]byte); ok {
return bytes.Clone(b)
}
return part
}

// value renders the context in the guest's grammar: a scalar or nested
Expand Down
6 changes: 1 addition & 5 deletions languages/golang/stackencrypt/record.go
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
package stackencrypt

import (
"bytes"
"context"
"errors"
"fmt"
Expand Down Expand Up @@ -158,10 +157,7 @@ func (e contextExtension) applyTerm(o *termOptions) { e.appendTo(&o.extension) }
func ExtendContext(parts ...any) Option {
owned := make([]any, len(parts))
for i, part := range parts {
if b, ok := part.([]byte); ok {
part = bytes.Clone(b)
}
owned[i] = part
owned[i] = ownPart(part)
}
return contextExtension{parts: owned}
}
Expand Down
26 changes: 26 additions & 0 deletions languages/golang/stackencrypt/unit_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -128,6 +128,32 @@ func TestSelectorsSpellEveryVariant(t *testing.T) {
}
}

// A Context owns its parts, as an option does: NewContext and With copy a
// byte-slice part in, so a caller's buffer reused once the context is
// built does not change it.
func TestContextOwnsItsByteParts(t *testing.T) {
root, ext := []byte("users/email"), []byte("eu")
c, err := NewContext(root)
if err != nil {
t.Fatal(err)
}
if c, err = c.With(ext); err != nil {
t.Fatal(err)
}
copy(root, "users/phone")
copy(ext, "us")
parts, ok := c.value().([]any)
if !ok || len(parts) != 2 {
t.Fatalf("context value is %#v, want a two-part list", c.value())
}
if got := string(parts[0].([]byte)); got != "users/email" {
t.Errorf("root part is %q after the caller's buffer changed, want \"users/email\"", got)
}
if got := string(parts[1].([]byte)); got != "eu" {
t.Errorf("extension part is %q after the caller's buffer changed, want \"eu\"", got)
}
}

func TestContextNestsToTheLeft(t *testing.T) {
c := MustContext("users/age")
if got := c.value(); got != "users/age" {
Expand Down
Loading