Re: [PATCH 1/5] compat/posix: introduce writev(3p) wrapper
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Jul 16, 2026, 20:09 UTC
- Message-ID
- <xmqqfr1ig0hv.fsf@gitster.g>
- In-Reply-To
- <a2676ec6-39d5-4220-8549-10a17daec668@hogyros.de>
Simon Richter <Simon.Richter@hogyros.de> writes:
Show 6 quoted lines
> Hi,
>
>> + if (iov[i].iov_len > maximum_signed_value_of_type(ssize_t) ||
>> + iov[i].iov_len + sum > maximum_signed_value_of_type(ssize_t)) {
>
> That feels like it could overflow.Isn't it checking if it would overflow (and dying if so)?
Ah, wait. The addition "(iov[i].iov_len + sum)" can indeed wrap around, and comparing it with the maximum value of ssize_t wouldn't catch that. Is that what you mean?
Would something like this:
if (maximum_signed_value_of_type(ssize_t) < iov[i].iov_len || iov[i].iov_len + sum < iov[i].iov_len || maximum_signed_value_of_type(ssize_t) < iov[i].iov_len + sum)
work better to catch the three cases independently?
(1) The value is already too large on its own.
(2) Adding them together would cause an unsigned wrap-around.
(3) The sum does not wrap around, but it exceeds the maximum
representable value of ssize_t anyway.