Skip to content

decompress: use uint64_t for literal_length to prevent 32-bit overflow (fixes #266) - #269

Open
jdymitarai wants to merge 1 commit into
google:mainfrom
jdymitarai:fix-literal-length-u32-overflow-266
Open

jdymitarai wants to merge 1 commit into
google:mainfrom
jdymitarai:fix-literal-length-u32-overflow-266

Conversation

@jdymitarai

@jdymitarai jdymitarai commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Root Cause

In commit 7406111, size_t{1} was used to prevent literal_length of 2^32 from wrapping to 0. On 32-bit platforms (e.g., i386, armhf), sizeof(size_t) == 4, so 0xffffffff + size_t{1} still overflows to 0, causing the decompressor to silently bypass the poison literal without error.

Fix

Promote literal_length to uint64_t and use uint64_t{1} for the addition so that extended literal lengths are 64 bits across all architectures. Add static_cast<size_t> where needed for buffer sizing and pointer arithmetic to prevent compiler warnings on 32-bit targets.

Verification

Fixes the regression reported in #266, allowing Snappy.LiteralLengthU32Overflow to properly reject invalid 2^32-byte literal spans on 32-bit architectures as intended.

fixes google#266)

In commit 7406111, size_t{1} was added to ExtractLowBytes(...) to prevent literal lengths of 2^32 from wrapping to 0. However, on 32-bit platforms (e.g., i386, armhf), sizeof(size_t) == 4, so 0xffffffff + size_t{1} still overflows to 0. This causes Snappy.LiteralLengthU32Overflow to fail on 32-bit systems because the poison literal is bypassed.

Change literal_length to uint64_t and promote the addition with uint64_t{1} so that extended literal lengths are 64 bits across all architectures. Add static_cast<size_t> when passing length to TryFastAppend, Append, and pointer arithmetic to ensure clean compilation on 32-bit targets.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant