From: Junio C Hamano Date: Tue, 10 Mar 2026 16:59:36 GMT Subject: Re: [PATCH v3 05/10] compat/posix: introduce writev(3p) wrapper Message-ID: In-Reply-To: <20260310-pks-upload-pack-write-contention-v3-5-8bc97aa3e267@pks.im> Patrick Steinhardt writes: > +ssize_t git_writev(int fd, const struct iovec *iov, int iovcnt) > +{ > + size_t total_written = 0; > + size_t sum = 0; > + > + /* > + * According to writev(3p), the syscall shall error with EINVAL in case > + * the sum of `iov_len` overflows `ssize_t`. > + */ > + for (int i = 0; i < iovcnt; i++) { > + if (iov[i].iov_len > maximum_signed_value_of_type(ssize_t) || > + iov[i].iov_len + sum > maximum_signed_value_of_type(ssize_t)) { This made me pause, but I think you cannot wrap-around size_t and end up with a small positive result that would fit in ssize_t by adding two quantities that are smaller than the max_ssize_t so this check should be sufficient. > + errno = EINVAL; > + return -1; > + }