Skip to content

[audit][C015] Indexed mirror estimates omit mixed sum-carrier key widths #912

Description

@QuantumExplorer

Audit group: C015. Classification: correctness. Provisional severity: low.

The indexed mirror key-size helper includes sum-carrying item/reference widths for homogeneous descriptions but ignores those fields in Mix. Secondary keys include the primary key, so the omission conflicts with the helper documentation and homogeneous behavior. An existing test explicitly asserts the zero-width outcome for sum-carrier-only Mix; actual stored data and mutation logic are unaffected.

Expected contract and correction: Confirm the intended sizing contract. If estimates derive primary-key widths as documented, include both mixed fields and replace the deliberate-omission expectation with mixed/homogeneous consistency checks. Otherwise document the caller restriction explicitly. Version any cost behavior change required for replay.

Validation to complete

  • Resolve/document the intended contract for sum-carrier-only and mixed layers.
  • Verify homogeneous and equivalent Mix descriptions derive consistent key widths under that contract.
  • Check mirror estimate sensitivity to primary key width and preserve historical versions.

Limits and existing work

  • Maintainer intent remains an open question because an existing test deliberately pins the behavior.
  • Retained as low correctness, not a proved fee bypass.

Related tracking: PR #674 (merged).

Scope: saved GroveDB worktree with revision context 2fa0f133877420a0d9c91ba7bc51b1775ab8c783. This report does not establish that current develop or any deployed application is affected. Focused runtime validation remains outstanding.

Audit source and canonical finding identifiers

Source status: snapshot-backed (git_worktree); plain source locations are used because this is not a sealed commit-only scan.

Audited revision context: 2fa0f133877420a0d9c91ba7bc51b1775ab8c783.

The findings were manually reconciled from a preserved scan bundle. The native scan ended before final completion; these are provisional source-review findings, not a completed native scan certification.

Canonical finding ID: csf_80daffbc50aea53fa1dd8a12

Primary fingerprint: codex-security/v1:sha256:32d476f284c0a4eea3fa57aa61a2bb62a9022fdcb4ac9a55732effcf6015a091

Source locations:

  • Location (root_control): grovedb/src/estimated_costs/average_case_costs.rs:444-486
  • Location (sink): grovedb/src/estimated_costs/average_case_costs.rs:531-577
  • Location (counterevidence): grovedb/src/tests/coverage_misc_tests.rs:358-380

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:parsing-costsC groups: decoding, storage accounting, cost estimation and serialization.audit:2026-09Reconciled September 2026 GroveDB audit; audited worktree at 2fa0f133.audit:needs-validationSaved source evidence reviewed; focused runtime and deployment validation outstanding.bugSomething isn't workingseverity:low-provisionalLow impact in the audited scenario; provisional static assessment.type:correctnessAudit reports incorrect library behavior or accounting without proven security impact.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions