rc: fix rc API accepting an out of range number and overflowing 64 bits

float64(math.MaxInt64) rounds up to 2^63, so x > math.MaxInt64 in
GetInt64 lets 2^63 through to int64(x), which is out of range.
This commit is contained in:
KBS authored and GitHub committed 2026-09-15 16:45:33 +01:00
1 parent b1a10fe17e
commit 976d05e1dd
2 files changed
+6 -1

No files matched your search

+2 -1
View File
@@ -167,7 +167,8 @@ func (p Params) GetInt64(key string) (int64, error) {
case int64:
return x, nil
case float64:
if x > math.MaxInt64 || x < math.MinInt64 {
// float64(math.MaxInt64) rounds up to 2**63 which doesn't fit in an int64
if x >= math.MaxInt64 || x < math.MinInt64 {
return 0, ErrParamInvalid{fmt.Errorf("key %q (%v) overflows int64 ", key, value)}
}
return int64(x), nil
+4
View File
@@ -3,6 +3,7 @@ package rc
import (
"errors"
"fmt"
"math"
"net/http"
"net/http/httptest"
"testing"
@@ -120,6 +121,9 @@ func TestParamsGetInt64(t *testing.T) {
{float64(14), 14, ""},
{float64(9.3e18), 0, "overflows int64"},
{float64(-9.3e18), 0, "overflows int64"},
{float64(math.MaxInt64), 0, "overflows int64"},
{math.Nextafter(float64(math.MaxInt64), 0), 9223372036854774784, ""},
{float64(math.MinInt64), math.MinInt64, ""},
} {
t.Run(fmt.Sprintf("%T=%v", test.value, test.value), func(t *testing.T) {
in := Params{