From 5cf3a35287163f79a302a15db66f0fa386d94d10 Mon Sep 17 00:00:00 2001 From: Daniel Kuts Date: Thu, 24 Sep 2026 21:43:26 +0300 Subject: [PATCH] llama-grammar: fix numeric truncation for token_id parsing (#29382) --- src/llama-grammar.cpp | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/src/llama-grammar.cpp b/src/llama-grammar.cpp index deffec8c07..0a8a61e7e8 100644 --- a/src/llama-grammar.cpp +++ b/src/llama-grammar.cpp @@ -194,7 +194,11 @@ static std::pair parse_token(const llama_vocab * vocab, if (*pos == '[') { pos++; const char * int_end = parse_int(pos); - uint32_t token_id = std::stoul(std::string(pos, int_end - pos)); + unsigned long id = std::stoul(std::string(pos, int_end - pos)); + if (id > std::numeric_limits::max()) { + throw std::runtime_error(std::string("parsed token id is too big at ") + pos); + } + uint32_t token_id = static_cast(id); pos = int_end; if (*pos != ']') { throw std::runtime_error(std::string("expecting ']' at ") + pos);