git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/5] compat/posix: introduce writev(3p) wrapper

From
Junio C Hamano <gitster@pobox.com>
Date
Jul 16, 2026, 20:44 UTC
Message-ID
<xmqqwluuekbh.fsf@gitster.g>
In-Reply-To
<xmqqfr1ig0hv.fsf@gitster.g>
Junio C Hamano <gitster@pobox.com> writes:
Show 27 quoted lines
> Simon Richter <Simon.Richter@hogyros.de> writes:
>
>> Hi,
>>
>>> +		if (iov[i].iov_len > maximum_signed_value_of_type(ssize_t) ||
>>> +		    iov[i].iov_len + sum > maximum_signed_value_of_type(ssize_t)) {
>>
>> That feels like it could overflow.
>
> Isn't it checking if it would overflow (and dying if so)?
>
> Ah, wait.  The addition "(iov[i].iov_len + sum)" can indeed wrap
> around, and comparing it with the maximum value of ssize_t wouldn't
> catch that.  Is that what you mean?
>
> Would something like this:
>
>     if (maximum_signed_value_of_type(ssize_t) < iov[i].iov_len ||
> 	iov[i].iov_len + sum < iov[i].iov_len ||
> 	maximum_signed_value_of_type(ssize_t) < iov[i].iov_len + sum)
>
> work better to catch the three cases independently?
>
>  (1) The value is already too large on its own.
>  (2) Adding them together would cause an unsigned wrap-around.
>  (3) The sum does not wrap around, but it exceeds the maximum
>      representable value of ssize_t anyway.

Actually, looking at it again, I think the original code is safe after all, because:

 * "sum", even though it is a size_t, is checked inside the loop to
   ensure it stays below the maximum value of ssize_t each time it
   gets a new value.
 * iov[i].iov_len is checked to ensure it does not exceed the
   maximum value of ssize_t by the first part of the condition.

If both values are less than or equal to the maximum value of ssize_t, their sum is at most twice that limit. For an N-bit size_t, this sum is at most (2^N - 2), which can be computed safely without any unsigned wrap-around.

So...?
Previous: Junio C HamanoNext: Patrick Steinhardt
Message 5 of 27 in “Reintroduce writev(3p)”
  1. 0/5 Reintroduce writev(3p)Patrick Steinhardt, Jul 16, 2026
  2. 1/5 compat/posix: introduce writev(3p) wrapperPatrick Steinhardt, Jul 16, 2026
  3. Simon RichterJul 16, 2026
  4. Junio C HamanoJul 16, 2026
  5. Junio C HamanoJul 16, 2026
  6. Patrick SteinhardtAug 5, 2026
  7. 2/5 wrapper: introduce writev(3p) wrappersPatrick Steinhardt, Jul 16, 2026
  8. 3/5 wrapper: properly handle MAX_IO_SIZE in writev(3p)Patrick Steinhardt, Jul 16, 2026
  9. 4/5 sideband: use writev(3p) to send pktlinesPatrick Steinhardt, Jul 16, 2026
  10. 5/5 fast-import: use writev(3p) to send cat-blob responsesPatrick Steinhardt, Jul 16, 2026
  11. Johannes SixtJul 16, 2026
  12. Junio C HamanoJul 27, 2026
  13. Patrick SteinhardtAug 5, 2026
  14. Junio C HamanoAug 5, 2026
  15. Johannes SixtAug 5, 2026
  16. Junio C HamanoAug 5, 2026
  17. Johannes SixtAug 5, 2026
  18. Junio C HamanoAug 5, 2026
  19. Patrick SteinhardtAug 6, 2026
  20. Junio C HamanoAug 6, 2026
  21. Patrick SteinhardtAug 7, 2026
  22. 0/5 Reintroduce writev(3p)Patrick Steinhardt, Aug 7, 2026
  23. 1/5 compat/posix: introduce writev(3p) wrapperPatrick Steinhardt, Aug 7, 2026
  24. 2/5 wrapper: introduce writev(3p) wrappersPatrick Steinhardt, Aug 7, 2026
  25. 3/5 wrapper: properly handle MAX_IO_SIZE in writev(3p)Patrick Steinhardt, Aug 7, 2026
  26. 4/5 sideband: use writev(3p) to send pktlinesPatrick Steinhardt, Aug 7, 2026
  27. 5/5 fast-import: use writev(3p) to send cat-blob responsesPatrick Steinhardt, Aug 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.