| From 0eceb2b0053beaee207218d6d4c45c58b6d53705 Mon Sep 17 00:00:00 2001 |
| From: Chris Rauer <crauer@google.com> |
| Date: Thu, 21 May 2026 00:32:45 +0000 |
| Subject: [PATCH 08/12] [dhcp-relay] Fix integer wrap-around logic flaw in |
| converted_length |
| |
| In converted_length (omapip/convert.c), the loop used to determine the character |
| length of an integer in a given base relied on: |
| newcolumn = column * base; |
| ... |
| while (newcolumn > column); |
| |
| to detect unsigned 32-bit integer overflow. However, for certain values (e.g. |
| large numbers in base 10), the wrapped value (column * base) % 2^32 can still |
| be larger than the previous 'column' value. This caused the loop to continue |
| unexpectedly, inflating the calculated length ('power'). |
| |
| This inflated length subsequently caused binary_to_ascii to emit over-long |
| strings (with unexpected leading '0's) and potentially led to incorrect buffer |
| size calculations in callers. |
| |
| This CL fixes the issue by implementing a reliable division-based overflow |
| check: |
| if (newcolumn / base != column) |
| return power; |
| |
| This safely terminates the loop immediately when the column boundary exceeds |
| the 32-bit unsigned integer limit, returning the correct length. |
| |
| BUG=510454340 |
| TAG=agy |
| CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27 |
| --- |
| omapip/convert.c | 2 ++ |
| 1 file changed, 2 insertions(+) |
| |
| diff --git a/omapip/convert.c b/omapip/convert.c |
| index de6c7c86..9b264262 100644 |
| --- a/omapip/convert.c |
| +++ b/omapip/convert.c |
| @@ -141,6 +141,8 @@ int converted_length (buf, base, width) |
| return power; |
| power++; |
| newcolumn = column * base; |
| + if (newcolumn / base != column) |
| + return power; |
| /* If we wrap around, it must be the next power of two up. */ |
| } while (newcolumn > column); |
| |
| -- |
| 2.54.0.669.g59709faab0-goog |
| |