Changes for version 0.03 - 2026-10-09
- Security and correctness fixes:
- SZARU-01: Fix use-after-free / double-free in TopEstimator::estimate by returning SV* with single refcount ownership and removing unsafe sv_2mortal.
- SZARU-02: Fix uninitialized memory read, out-of-bounds read, and shift UB in UniqueEstimatorImpl::Estimate.
- SZARU-03: Value-initialize SzlSketch weights array to prevent reading uninitialized memory.
- SZARU-04: Prevent min_buffer_id < 0 index[-1] heap corruption and infinite loop in QuantileEstimator::ComputeQuantiles.
- SZARU-05: Guard av_extend(..., size()-1) on empty vectors against size_t underflow in TopEstimator::estimate and typemaps.
- SZARU-06: Fix SzlSketch::Estimate pointer assignment bug (*est = *mid) and restore ReplaceSmallest in Top-N estimator.
- SZARU-07: Fix bit shift undefined behaviors across szlquantile, szlsketch, szlunique, and hashutils.
- SZARU-08: Add strict constructor parameter validation for bounds and type correctness on TopEstimator, QuantileEstimator, and UniqueEstimator.
- SZARU-09: Reject NaN and Inf values in add_elem, add_elems, add_weighted_elem, and add_weighted_elems to protect heap invariants.
- SZARU-10: Safely check for NULL object pointers and non-object invocants in all XS methods and typemaps.
- SZARU-11: Replace unaligned pun_cast pointer dereferencing in hashutils with safe memcpy and length checks.
- SZARU-12: Delete copy constructors and copy assignment operators on PTopEstimator and PQuantileEstimator (rule of three).
- SZARU-13: Make Build.PL config.h inclusion non-destructive using a compiler -iquote include shim.
Modules
Perl wrapper for the SZaru C++ library
Quantile estimation based on Munro-Paterson algorithm
Statistical estimator of the 'top N' items based on CountSketch algorithm
Statistical estimator for total number of unique items