From ac1b2685d5ed224b36c2ded94694c1ff8350ca1d Mon Sep 17 00:00:00 2001 From: xirvik Date: Thu, 20 Aug 2026 05:00:29 +0000 Subject: [PATCH] Guard the value suffixes against negative overflow. The k, m and g guards only checked the positive side, so -4611686018427387904K became 0. --- src/rpc/parse.cc | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/src/rpc/parse.cc b/src/rpc/parse.cc index e9407bdc..e49dde66 100644 --- a/src/rpc/parse.cc +++ b/src/rpc/parse.cc @@ -102,6 +102,12 @@ parse_whole_value_nothrow(const char* src, int64_t* value, int base, int unit) { return true; } +static bool +value_fits_shifted(int64_t value, int shift) { + return value <= (std::numeric_limits::max() >> shift) && + value >= (std::numeric_limits::min() >> shift); +} + const char* parse_value_nothrow(const char* src, int64_t* value, int base, int unit) { if (unit <= 0) @@ -124,15 +130,15 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) { case 'B': ++last; break; case 'k': case 'K': - if (*value > (int64_t)0x1FFFFFFFFFFFFF) return src; // overflow guard + if (!value_fits_shifted(*value, 10)) return src; // overflow guard *value = *value << 10; ++last; break; case 'm': case 'M': - if (*value > (int64_t)0x7FFFFFFFFFF) return src; // overflow guard + if (!value_fits_shifted(*value, 20)) return src; // overflow guard *value = *value << 20; ++last; break; case 'g': case 'G': - if (*value > (int64_t)0x1FFFFFFFF) return src; // overflow guard + if (!value_fits_shifted(*value, 30)) return src; // overflow guard *value = *value << 30; ++last; break; // case ' ': // case '\0': *value = *value * unit; break;