Hmbown/CodeWhale · error · Error

Rust public key byte out of range

Error message

Rust public key byte out of range

What it means

After splitting the public_key literal into byte pieces and converting with Number(), each byte must be an integer in 0–255. This throws when a piece converts to a non-integer or out-of-range value — typically a value >255 (bad hex/decimal conversion) or a negative number inside the Rust array.

Solutions

  1. Find the offending byte (each must satisfy 0 ≤ b ≤ 255 and be integral).
  2. Regenerate the 32-byte array programmatically from the canonical key (e.g. base64 → bytes → Rust literal) instead of by hand.
  3. Verify against the TypeScript source-of-truth key used by check-cloud-facts.

Example fix

// before (Rust)
public_key: [256, 12, ...],
// after
public_key: [0x1_00 → fix: 0x00, 12, ...], // every byte 0..=255
Defensive patterns

Strategy: validation

Validate before calling

const bytes = parts.map(Number); if (bytes.some(b => !Number.isInteger(b) || b < 0 || b > 255)) throw new Error("byte out of range before calling parser");

Type guard

const isByte = (n) => Number.isInteger(n) && n >= 0 && n <= 255;

Try / catch

try { parseRustKeys(src); } catch (e) { if (e.message.includes("out of range")) logOffendingBytes(src); throw e; }

Prevention

When it happens

Trigger: A byte literal in the Rust public_key array is negative, greater than 255, or a value like 0x1FF that exceeds one byte.

Common situations: Hand-converting a base64 key to bytes and making an arithmetic mistake; concatenating bytes wrong; copy/paste from a different key length encoding.

Understand the failure class

Background: "value must be between 0 and 1" / "out of range" / "must not be negative" errors: fixing range-validation failures across open-source libraries — this error's family across 42 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/3be2bde8a100d7ee. Report an issue: GitHub.

Appendix: source

Thrown at web/scripts/check-cloud-facts.mjs:22

import { fileURLToPath } from "node:url";
import { validateSource, verifyEnvelope, parseTsKeys, validateTrustedKeys, readBoundedFile } from "./facts-publish.mjs";

const WEB_ROOT = resolve(dirname(fileURLToPath(import.meta.url)), "..");
const REPO_ROOT = resolve(WEB_ROOT, "..");
export { parseTsKeys };

export function parseRustKeys(text) {
  const source = text.replace(/\/\*[\s\S]*?\*\//g, "").replace(/^\s*\/\/.*$/gm, "");
  const tables = [...source.matchAll(/^\s*pub\s+const\s+TRUSTED_KEYS\s*:\s*&\s*\[TrustedKey\]\s*=\s*&\s*\[([\s\S]*?)\]\s*;/gm)];
  if (tables.length !== 1) throw new Error("cannot parse exactly one Rust TRUSTED_KEYS table");
  const table = tables[0];
  const body = table[1].replace(/^\s*\/\/.*$/gm, "");
  const keys = [];
  const remainder = body.replace(/TrustedKey\s*\{\s*key_id:\s*"([^"]+)",\s*public_key:\s*\[([^\]]*)\],\s*status:\s*KeyStatus::(Active|Retired)\s*,?\s*\}/g, (_, keyId, encoded, status) => {
    const pieces = encoded.split(",").map((piece) => piece.trim()).filter(Boolean);
    if (pieces.length !== 32 || pieces.some((piece) => !/^(?:\d+|0x[0-9a-fA-F]+)$/.test(piece))) throw new Error("Rust public key must contain 32 literal bytes");
    const bytes = pieces.map(Number);
    if (bytes.some((byte) => !Number.isInteger(byte) || byte < 0 || byte > 255)) throw new Error("Rust public key byte out of range");
    keys.push({ keyId, publicKey: Buffer.from(bytes).toString("base64"), status: status.toLowerCase() });
    return "";
  });
  if (remainder.replace(/[\s,]/g, "")) throw new Error("unparsed Rust TRUSTED_KEYS entry");
  return validateTrustedKeys(keys);
}

function text(path) { return readBoundedFile(path).toString("utf8"); }
function json(path) { return JSON.parse(text(path)); }

export function checkCloudFacts() {
  const failures = [];
  const source = json(resolve(REPO_ROOT, "docs/cloud-facts/stable.json"));
  for (const error of validateSource(source)) failures.push(`stable.json: ${error}`);
  if (source.channel !== "stable") failures.push("stable.json: channel must be stable");
  const latest = json(resolve(WEB_ROOT, "data/latest-published-release.json"));
  if (source.release?.latest !== latest.version) failures.push("stable.json release.latest differs from latest-published-release.json");
  if (source.release?.release_url && source.release.release_url !== latest.url) failures.push("stable.json release.release_url differs from latest-published-release.json");

View on GitHub (pinned to 433685b202)