Skip to content

fix: guard make() capacity against integer overflow#401

Merged
josegonzalez merged 1 commit into
mainfrom
guard-allocation-size-overflow
Jul 18, 2026
Merged

fix: guard make() capacity against integer overflow#401
josegonzalez merged 1 commit into
mainfrom
guard-allocation-size-overflow

Conversation

@josegonzalez

Copy link
Copy Markdown
Member

CodeQL's go/allocation-size-overflow query opened five high-severity alerts (3-7) against make() calls whose capacity hint adds a small constant to, or doubles, the length of an in-memory collection - patterns like len(base)+4 and len(pairs)*2. Because those lengths are bounded by available memory they cannot approach math.MaxInt, so the overflow is unreachable in practice, but CodeQL cannot prove that and the warnings recur on every scan.

Each capacity computation now goes through a small safeCap helper that returns the sum unless it would overflow, in which case it falls back to the base length, so the hint is unchanged for every realistic input while the arithmetic is provably non-overflowing. The same idiom in tasks/format.go that CodeQL had not yet flagged is folded in so the treatment stays consistent.

Resolves code scanning alerts 3-7.

CodeQL's go/allocation-size-overflow flagged several make() capacity hints that add a small constant to, or double, the length of an in-memory collection, where it cannot prove the size arithmetic will not overflow. Those lengths are bounded by available memory so the overflow is unreachable in practice, but the arithmetic is now guarded so it is provably safe and the alerts no longer fire.
@josegonzalez
josegonzalez merged commit 7bc6d2e into main Jul 18, 2026
19 checks passed
@josegonzalez
josegonzalez deleted the guard-allocation-size-overflow branch July 18, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant