Skip to content

GH-31076: [C++] Reject overflowing STL allocation sizes - #51477

Merged
pitrou merged 1 commit into
apache:mainfrom
aikhanjum:codex/gh-31076-stl-allocation-overflow
Oct 1, 2026
Merged

pitrou merged 1 commit into
apache:mainfrom
aikhanjum:codex/gh-31076-stl-allocation-overflow

Conversation

@aikhanjum

@aikhanjum aikhanjum commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Rationale for this change

The STL allocator computes n * sizeof(T) without checking for overflow. On a 64-bit platform, requesting 2^61 uint64_t elements wraps the byte count to zero. Requesting one more element wraps it to eight. Both allocations incorrectly succeed on upstream commit 5448aa7a916e73116ccc009454e3c19572dd5aad, returning less storage than requested.

What changes are included in this PR?

Check the element count before multiplication against both the size_t limit and the int64_t limit used by MemoryPool. Reject oversized requests with the existing BadAlloc exception, which derives from std::bad_alloc.

Add one regression test covering wraparound to zero and eight bytes. The test frees any unexpectedly successful allocation before reporting the missing exception.

Are these changes tested?

Yes, by additional unit test.

Are there any user-facing changes?

Just a bugfix.

Was AI used for this PR?

PR code and description written by

  • Human
  • AI

Reviewed before submission by

  • Human
  • AI
  • Not reviewed

OpenAI Codex researched the issue and related PRs, wrote the reproducer, regression test, fix, and this description, ran the listed checks, and reviewed the diff with another AI agent. Grok was used for preliminary X research. No external implementation was copied into the patch.

The human author reviewed the complete patch, discussed the overflow checks and regression test, and takes responsibility for the change.

Reject element counts before multiplying them into size_t bytes or converting the result to the int64_t MemoryPool interface. Add regression cases whose unchecked products wrap to zero and eight bytes.

Generated-by: OpenAI Codex
@github-actions github-actions Bot added the awaiting review Awaiting review label Sep 24, 2026
@github-actions

Copy link
Copy Markdown

⚠️ GitHub issue #31076 has been automatically assigned in GitHub to PR creator.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ GitHub issue #31076 has been automatically assigned in GitHub to PR creator.

@pitrou

pitrou commented Oct 1, 2026

Copy link
Copy Markdown
Member

Thanks for this @aikhanjum . This looks good to merge, I'll wait for CI to run now.

@github-actions github-actions Bot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Oct 1, 2026
@pitrou

pitrou commented Oct 1, 2026

Copy link
Copy Markdown
Member

CI failures are unrelated.

@pitrou
pitrou merged commit ccfcdd2 into apache:main Oct 1, 2026
59 of 66 checks passed
@pitrou pitrou removed the awaiting committer review Awaiting committer review label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants