If clock_gettime(CLOCK_MONOTONIC, ...) is called infrequently (minutes or hours apart), the tv_sec difference multiplied by 1 billion could overflow long long (max ~9.2e18). At ~300 years of difference, the multiply alone would overflow. While unlikely in practice, a long-running transfer paused for a very long time could trigger this.
Additionally, the token refill calculation on line 41:
Uses floating point in a timing-sensitive code path, and double may lose precision for very large values of io_bwlimit * elapsed_ns.
Location
src/shared/protocol.c:37-57
Suggested Fix
Cap the elapsed time to a reasonable interval (e.g., 1 second)
Avoid floating point by using integer arithmetic:
longlongmax_elapsed=1000000000LL;// cap to 1 second
if(elapsed_ns>max_elapsed)elapsed_ns=max_elapsed;
Severity
Low
Category
Quality
## Description
In `src/shared/protocol.c` lines 37-57, the bandwidth throttling uses `long long` for timing calculations:
```c
long long elapsed_ns =
(now.tv_sec - bw_last_refill.tv_sec) * 1000000000LL + (now.tv_nsec - bw_last_refill.tv_nsec);
```
If `clock_gettime(CLOCK_MONOTONIC, ...)` is called infrequently (minutes or hours apart), the `tv_sec` difference multiplied by 1 billion could overflow `long long` (max ~9.2e18). At ~300 years of difference, the multiply alone would overflow. While unlikely in practice, a long-running transfer paused for a very long time could trigger this.
Additionally, the token refill calculation on line 41:
```c
long long tokens_to_add = (long long)((double)io_bwlimit * elapsed_ns / 1000000000.0);
```
Uses floating point in a timing-sensitive code path, and `double` may lose precision for very large values of `io_bwlimit * elapsed_ns`.
## Location
`src/shared/protocol.c:37-57`
## Suggested Fix
1. Cap the elapsed time to a reasonable interval (e.g., 1 second)
2. Avoid floating point by using integer arithmetic:
```c
long long max_elapsed = 1000000000LL; // cap to 1 second
if (elapsed_ns > max_elapsed)
elapsed_ns = max_elapsed;
```
## Severity
Low
## Category
Quality
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In
src/shared/protocol.clines 37-57, the bandwidth throttling useslong longfor timing calculations:If
clock_gettime(CLOCK_MONOTONIC, ...)is called infrequently (minutes or hours apart), thetv_secdifference multiplied by 1 billion could overflowlong long(max ~9.2e18). At ~300 years of difference, the multiply alone would overflow. While unlikely in practice, a long-running transfer paused for a very long time could trigger this.Additionally, the token refill calculation on line 41:
Uses floating point in a timing-sensitive code path, and
doublemay lose precision for very large values ofio_bwlimit * elapsed_ns.Location
src/shared/protocol.c:37-57Suggested Fix
Severity
Low
Category
Quality