The chunk_size field in Config is unsigned long long (64-bit), but config_send() serializes it via send_int() which only sends an int (32-bit on most platforms):
And config_receive() reads it back as int then casts: File:src/shared/config.c:188
config->chunk_size=(unsignedlonglong)tmp;
This means chunk sizes larger than 2 GB will be silently truncated, potentially causing data corruption or incorrect chunking behavior on very large transfers.
Fix: Use send_n_data / receive_n_data with sizeof(unsigned long long) instead of send_int/receive_int for the chunk_size field.
Severity: high
The `chunk_size` field in `Config` is `unsigned long long` (64-bit), but `config_send()` serializes it via `send_int()` which only sends an `int` (32-bit on most platforms):
**File:** `src/shared/config.c:113`
```c
if (!send_int(file_descriptor, (int)config->chunk_size))
```
And `config_receive()` reads it back as `int` then casts:
**File:** `src/shared/config.c:188`
```c
config->chunk_size = (unsigned long long)tmp;
```
This means chunk sizes larger than 2 GB will be silently truncated, potentially causing data corruption or incorrect chunking behavior on very large transfers.
**Fix:** Use `send_n_data` / `receive_n_data` with `sizeof(unsigned long long)` instead of `send_int`/`receive_int` for the chunk_size field.
**Severity:** high
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The
chunk_sizefield inConfigisunsigned long long(64-bit), butconfig_send()serializes it viasend_int()which only sends anint(32-bit on most platforms):File:
src/shared/config.c:113And
config_receive()reads it back asintthen casts:File:
src/shared/config.c:188This means chunk sizes larger than 2 GB will be silently truncated, potentially causing data corruption or incorrect chunking behavior on very large transfers.
Fix: Use
send_n_data/receive_n_datawithsizeof(unsigned long long)instead ofsend_int/receive_intfor the chunk_size field.Severity: high