decompress: use uint64_t for literal_length to prevent 32-bit overflow (fixes #266) - #269
Open
jdymitarai wants to merge 1 commit into
Open
jdymitarai wants to merge 1 commit into
jdymitarai wants to merge 1 commit into
Conversation
fixes google#266) In commit 7406111, size_t{1} was added to ExtractLowBytes(...) to prevent literal lengths of 2^32 from wrapping to 0. However, on 32-bit platforms (e.g., i386, armhf), sizeof(size_t) == 4, so 0xffffffff + size_t{1} still overflows to 0. This causes Snappy.LiteralLengthU32Overflow to fail on 32-bit systems because the poison literal is bypassed. Change literal_length to uint64_t and promote the addition with uint64_t{1} so that extended literal lengths are 64 bits across all architectures. Add static_cast<size_t> when passing length to TryFastAppend, Append, and pointer arithmetic to ensure clean compilation on 32-bit targets.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Root Cause
In commit 7406111,
size_t{1}was used to preventliteral_lengthof 2^32 from wrapping to 0. On 32-bit platforms (e.g., i386, armhf),sizeof(size_t) == 4, so0xffffffff + size_t{1}still overflows to 0, causing the decompressor to silently bypass the poison literal without error.Fix
Promote
literal_lengthtouint64_tand useuint64_t{1}for the addition so that extended literal lengths are 64 bits across all architectures. Addstatic_cast<size_t>where needed for buffer sizing and pointer arithmetic to prevent compiler warnings on 32-bit targets.Verification
Fixes the regression reported in #266, allowing
Snappy.LiteralLengthU32Overflowto properly reject invalid 2^32-byte literal spans on 32-bit architectures as intended.