From 976d05e1ddf58ba8b247507853f6e71f7f28c06d Mon Sep 17 00:00:00 2001 From: KBS Date: Wed, 16 Sep 2026 00:45:33 +0900 Subject: [PATCH] rc: fix rc API accepting an out of range number and overflowing 64 bits float64(math.MaxInt64) rounds up to 2^63, so x > math.MaxInt64 in GetInt64 lets 2^63 through to int64(x), which is out of range. --- fs/rc/params.go | 3 ++- fs/rc/params_test.go | 4 ++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/fs/rc/params.go b/fs/rc/params.go index ce4e71370..e3f37b18f 100644 --- a/fs/rc/params.go +++ b/fs/rc/params.go @@ -167,7 +167,8 @@ func (p Params) GetInt64(key string) (int64, error) { case int64: return x, nil case float64: - if x > math.MaxInt64 || x < math.MinInt64 { + // float64(math.MaxInt64) rounds up to 2**63 which doesn't fit in an int64 + if x >= math.MaxInt64 || x < math.MinInt64 { return 0, ErrParamInvalid{fmt.Errorf("key %q (%v) overflows int64 ", key, value)} } return int64(x), nil diff --git a/fs/rc/params_test.go b/fs/rc/params_test.go index d8b9b7e51..b1afc44e3 100644 --- a/fs/rc/params_test.go +++ b/fs/rc/params_test.go @@ -3,6 +3,7 @@ package rc import ( "errors" "fmt" + "math" "net/http" "net/http/httptest" "testing" @@ -120,6 +121,9 @@ func TestParamsGetInt64(t *testing.T) { {float64(14), 14, ""}, {float64(9.3e18), 0, "overflows int64"}, {float64(-9.3e18), 0, "overflows int64"}, + {float64(math.MaxInt64), 0, "overflows int64"}, + {math.Nextafter(float64(math.MaxInt64), 0), 9223372036854774784, ""}, + {float64(math.MinInt64), math.MinInt64, ""}, } { t.Run(fmt.Sprintf("%T=%v", test.value, test.value), func(t *testing.T) { in := Params{