Skip to content

fix: reject a duration sum that wraps past 2^64 - #312

Merged
fredbi merged 1 commit into
go-openapi:masterfrom
SashaMIT:fix/duration-sum-overflow
Oct 2, 2026
Merged

fredbi merged 1 commit into
go-openapi:masterfrom
SashaMIT:fix/duration-sum-overflow

Conversation

@SashaMIT

@SashaMIT SashaMIT commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

ParseDuration("9223372036854775808ns 9223372036854775808ns") returned 0s. Each token is 1<<63 nanoseconds. The uint64 sum wraps to 0, and 0 is not greater than maxUint64 (1<<63), so the range check accepts it. The negative pair returned 0s as well.

A single 9223372036854775808ns still errors. -9223372036854775808ns stays the minimum duration. 9000000000000ms 9000000000000ms still errors.

Red: parsed as 0s. Green: go test .

@fredbi

fredbi commented Oct 2, 2026

Copy link
Copy Markdown
Member

Thanks. Will review this later today

@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.13%. Comparing base (2c2378a) to head (3a19273).
⚠️ Report is 2 commits behind head on master.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #312   +/-   ##
=======================================
  Coverage   89.13%   89.13%           
=======================================
  Files          24       24           
  Lines        2926     2928    +2     
=======================================
+ Hits         2608     2610    +2     
  Misses        317      317           
  Partials        1        1           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@fredbi fredbi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. Good catch

1<<63 ns plus 1<<63 ns wraps the uint64 total to 0, and that 0 passes the range check. ParseDuration returned 0s.

Signed-off-by: Sasha Mitchell <sash.t.mitchell@gmail.com>
@fredbi
fredbi force-pushed the fix/duration-sum-overflow branch from 5a1a8db to 3a19273 Compare October 2, 2026 19:40
@fredbi
fredbi merged commit 9cf99be into go-openapi:master Oct 2, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants