Skip to content

Fix BITFIELD session disposal on empty subcommand list and max-offset GET - #2120

Merged
Vasileios Zois (vazois) merged 2 commits into
microsoft:mainfrom
foobar:fix/bitfield-robustness
Sep 10, 2026
Merged

Vasileios Zois (vazois) merged 2 commits into
microsoft:mainfrom
foobar:fix/bitfield-robustness

Conversation

@foobar

Copy link
Copy Markdown
Contributor

Two session-killing crashes in BITFIELD/BITFIELD_RO:

  1. A key with no subcommands (BITFIELD key, BITFIELD key OVERFLOW SAT) indexed an empty subcommand list and disposed the session.
    Zero-op commands now reply with an empty array, matching Redis's
    *0 for string and missing keys.

  2. BITFIELD GET with offset + encoding == 2^32 (e.g.
    GET u1 4294967295) called Index(offset + encoding) from
    GetValue, which throws past the 2^32-1 bit-offset cap and disposed
    the session whenever the bitmap reached the field. The call was
    part of an unread local; removed.

Known parity gap: Redis returns WRONGTYPE for zero-op BITFIELD on
non-string keys; Garnet replies *0.

BitFieldMaxOffsetGetAsync allocates a 512 MB bitmap — the smallest
value that reaches the fixed path.

… GET

Zero-subcommand BITFIELD indexed an empty subcommand list, and
BITFIELD GET with offset + encoding == 2^32 called Index past the
2^32-1 bit-offset cap; both threw and disposed the session. Zero-op
commands now reply with an empty array instead of crashing.
Copilot AI balanced review requested due to automatic review settings September 9, 2026 17:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused fixes are correct and include regression coverage for both reported failures.

Pull request overview

Fixes two BITFIELD/BITFIELD_RO crashes while preserving RESP session availability.

Changes:

  • Returns an empty array when no executable subcommands are supplied.
  • Removes an invalid maximum-offset calculation.
  • Adds regression tests for both crash scenarios.
File summaries
File Description
BitmapCommands.cs Handles empty subcommand lists safely.
BitmapManagerBitfield.cs Removes the out-of-range unused index calculation.
GarnetBitmapTests.cs Tests empty commands and maximum-offset GET behavior.
Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@vazois
Vasileios Zois (vazois) merged commit ba5e2eb into microsoft:main Sep 10, 2026
328 of 333 checks passed
@foobar
Tristan Su (foobar) deleted the fix/bitfield-robustness branch September 10, 2026 03:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants