GH-31076: [C++] Reject overflowing STL allocation sizes - #51477
Merged
pitrou merged 1 commit intoOct 1, 2026
Merged
Conversation
Reject element counts before multiplying them into size_t bytes or converting the result to the int64_t MemoryPool interface. Add regression cases whose unchecked products wrap to zero and eight bytes. Generated-by: OpenAI Codex
|
|
|
|
pitrou
approved these changes
Oct 1, 2026
Member
|
Thanks for this @aikhanjum . This looks good to merge, I'll wait for CI to run now. |
Member
|
CI failures are unrelated. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rationale for this change
The STL allocator computes
n * sizeof(T)without checking for overflow. On a 64-bit platform, requesting2^61uint64_t elements wraps the byte count to zero. Requesting one more element wraps it to eight. Both allocations incorrectly succeed on upstream commit5448aa7a916e73116ccc009454e3c19572dd5aad, returning less storage than requested.What changes are included in this PR?
Check the element count before multiplication against both the size_t limit and the int64_t limit used by MemoryPool. Reject oversized requests with the existing BadAlloc exception, which derives from std::bad_alloc.
Add one regression test covering wraparound to zero and eight bytes. The test frees any unexpectedly successful allocation before reporting the missing exception.
Are these changes tested?
Yes, by additional unit test.
Are there any user-facing changes?
Just a bugfix.
Was AI used for this PR?
PR code and description written by
Reviewed before submission by
OpenAI Codex researched the issue and related PRs, wrote the reproducer, regression test, fix, and this description, ran the listed checks, and reviewed the diff with another AI agent. Grok was used for preliminary X research. No external implementation was copied into the patch.
The human author reviewed the complete patch, discussed the overflow checks and regression test, and takes responsibility for the change.