Skip to content

Conversation

@kevinAlbs
Copy link
Collaborator

Cherry-picks b498496 and reformats.

@kevinAlbs kevinAlbs requested a review from a team as a code owner October 22, 2025 19:40

// `inlen` is a string length (excluding trailing NULL).
// Cyrus-SASL passes an `out` buffer of size `out_max + 1`. Assume `out_max` is the max to be safe.
if (inlen + 1 >= out_max) {
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Didn't notice in the previous, but may or may not be relevant: Do we know that inline + 1 cannot overflow?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great catch. Created #2159 as a precaution.

@vector-of-bool vector-of-bool self-requested a review October 22, 2025 20:46
Copy link
Contributor

@vector-of-bool vector-of-bool left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM with update to arithmetic

@kevinAlbs kevinAlbs merged commit d2519ea into mongodb:r2.1 Oct 24, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants