alhudz opened a new pull request, #1779:
URL: https://github.com/apache/commons-lang/pull/1779
Repro: call any `Conversion` array/hex/binary converter with a large count
or position, e.g. `Conversion.binaryToInt(new boolean[]{true}, 0, 0,
Integer.MAX_VALUE, 2)`, `Conversion.byteArrayToInt(new byte[]{1}, 0, 0, 0,
Integer.MAX_VALUE)`, or `Conversion.intToHex(0, 0, "", 0, Integer.MAX_VALUE)`.
Cause: each method documents `@throws IllegalArgumentException` when the
requested count and position exceed the destination width (`nBools - 1 + dstPos
>= 32`, `(nBytes - 1) * 8 + dstPos >= 32`, and so on) and evaluates that guard
first, but in `int`. For a large count
(`nBools`/`nBytes`/`nHex`/`nInts`/`nShorts`) or a large `srcPos`/`dstPos` the
expression overflows and wraps negative, so the guard is skipped.
Fix: widen the leading operand of each guard to `long` (`(long) nBools - 1 +
dstPos`, `((long) nBytes - 1) * 8 + dstPos`, ...) so the documented condition
holds. Small valid inputs are unchanged.
Without the fix the reading methods throw an undocumented
`ArrayIndexOutOfBoundsException`/`StringIndexOutOfBoundsException` from the
loop, and the hex writers (`intToHex`/`longToHex`/`shortToHex`/`byteToHex`)
skip the guard entirely and build a several-hundred-million-char `String`.
Applied to all 28 guard sites in the class;
`ConversionTest.testLargeCountThrowsIllegalArgumentException` exercises each
and fails before the change.
- [x] Read the [contribution guidelines](CONTRIBUTING.md) for this project.
- [ ] Read the [ASF Generative Tooling
Guidance](https://www.apache.org/legal/generative-tooling.html) if you use
Artificial Intelligence (AI).
- [ ] I used AI to create any part of, or all of, this pull request. Which
AI tool was used to create this pull request, and to what extent did it
contribute?
- [x] Run a successful build using the default
[Maven](https://maven.apache.org/) goal with `mvn`; that's `mvn` on the command
line by itself.
- [x] Write unit tests that match behavioral changes, where the tests fail
if the changes to the runtime are not applied. This may not always be possible,
but it is a best practice.
- [x] Write a pull request description that is detailed enough to understand
what the pull request does, how, and why.
- [x] Each commit in the pull request should have a meaningful subject line
and body.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]