crytic / crytic/slither

[Bug-Candidate]: slither fails to handle overflow literal operations

Open
#2,646 0 comments 0 reactions 0 assignees View on GitHub
bug-candidate
Dominant language
Python
Stars
6.4k
Forks
1.1k
PR merge metrics
No merged PRs in 30d

Description

### Describe the issue:

Tests were conducted using solc versions 0.8.27 and 0.8.28, and both failed to generate IR. The bug persists in the latest release.

I believe there should be more robust handling here, as mentioned in the [Solidity documentation](https://docs.soliditylang.org/en/latest/types.html):

Number literal expressions retain arbitrary precision until they are converted to a non-literal type (i.e. by using them together with anything other than a number literal expression (like boolean literals) or by explicit conversion). This means that computations do not overflow and divisions do not truncate in number literal expressions.

Code:

```solidity
contract C {
function test() public returns(int) {
return (-1) ** 1e100;
}
}
```

Run slither: `slither a.sol`

Output:

```
ERROR:SlitherSolcParsing:
Failed to generate IR for C.test. Please open an issue https://github.com/crytic/slither/issues.
C.test (a.sol#3-5):
(- 1) ** 1e100
Traceback (most recent call last):
...
ERROR:root:Error:
ERROR:root:1e100 is too large to fit in any Solidity integer size
ERROR:root:Please report an issue to https://github.com/crytic/slither/issues
```

### Code example to reproduce the issue:

```solidity
contract C {
function test() public returns(int) {
return (-1) ** 1e100;
}
}

```

### Version:

0.11.0

### Relevant log output:

```shell

```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.