blob: 154311b91ba0b606d0544be0e2d89d60ea09a540 [file]
From 0eceb2b0053beaee207218d6d4c45c58b6d53705 Mon Sep 17 00:00:00 2001
From: Chris Rauer <crauer@google.com>
Date: Thu, 21 May 2026 00:32:45 +0000
Subject: [PATCH 08/12] [dhcp-relay] Fix integer wrap-around logic flaw in
converted_length
In converted_length (omapip/convert.c), the loop used to determine the character
length of an integer in a given base relied on:
newcolumn = column * base;
...
while (newcolumn > column);
to detect unsigned 32-bit integer overflow. However, for certain values (e.g.
large numbers in base 10), the wrapped value (column * base) % 2^32 can still
be larger than the previous 'column' value. This caused the loop to continue
unexpectedly, inflating the calculated length ('power').
This inflated length subsequently caused binary_to_ascii to emit over-long
strings (with unexpected leading '0's) and potentially led to incorrect buffer
size calculations in callers.
This CL fixes the issue by implementing a reliable division-based overflow
check:
if (newcolumn / base != column)
return power;
This safely terminates the loop immediately when the column boundary exceeds
the 32-bit unsigned integer limit, returning the correct length.
BUG=510454340
TAG=agy
CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27
---
omapip/convert.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/omapip/convert.c b/omapip/convert.c
index de6c7c86..9b264262 100644
--- a/omapip/convert.c
+++ b/omapip/convert.c
@@ -141,6 +141,8 @@ int converted_length (buf, base, width)
return power;
power++;
newcolumn = column * base;
+ if (newcolumn / base != column)
+ return power;
/* If we wrap around, it must be the next power of two up. */
} while (newcolumn > column);
--
2.54.0.669.g59709faab0-goog