Negative slice underflow panics instead of clamping

perfloop/grol · EXTENT MISMATCH

https://perfloop.ai/t/oss/case_fqwmqe5agg

Verdict

VERIFIED · settled 2026-09-26 · pull request opened as grol-io/grol#544

What happened: The assertion is violated on the comparison and satisfied with this change.

Hypothesis

An array slice starting farther left than its length panics, while a slice reaching beyond its end is clamped. The panic aborts an inline evaluation instead of returning a bounded slice. The same normalization path serves strings and maps; their boundary results remain to be checked.

At revision b9b1d44, `State.evalIndexRangeExpression` adds the object's length to a negative index, rejects `l > r`, then applies only `min(index, length)` before slicing. For a three-element array, `[-20:]` leaves `l = -17` and `r = 3`. It passes the ordering check and panics when indexing `object.Elements(left)[l:r]`, before `NewArray` can produce a result. `repl.EvalOne` catches that panic as a script error. A lower-bound precondition is not applied on this supported path.

The reproducible check `go run . -no-auto -quiet -c 'x=[1,2,3]; x[-20:]'` reported `slice bounds out of range [-17:]` and exited with an error. The control `x[0:20]` returned `[1,2,3]`, demonstrating the existing upper clamp. A Case should evaluate underflowing and valid negative ranges, upper overflows, reversed bounds, and empty inputs through `repl.EvalString` for arrays, strings, and maps. Bounded results without a panic, with existing valid slices and ordering errors unchanged, would confirm the correction.

Change to test: Bound both translated slice endpoints to the logical range, including a zero lower bound, before slicing strings, arrays, or maps. Preserve valid negative-relative indexing, the existing upper-bound clamp, and the explicit error for reversed endpoints.

Where it lives

perfloop/grol · repl/repl.go

Evidence

The assertion is violated on the comparison and satisfied with this change: `For the declared integer slice expressions on built-in arrays, strings, and maps, repl.EvalString returns the expected bounded results without evaluation errors for negative underflow, valid negative-relative ranges, and upper overruns; it preserves the existing range-index error for reversed bounds and returns empty results for empty inputs.`

Checks: 3 of 3 passed. Verification: no defect found.

Timeline