4 ms·
I bet somewhere in the source there is a line which looks like: if (inclusiveEnd + 1 > size) { return ERR_INVALID; } HTTP ranges are inclusive
by pslam 11y ago
I bet somewhere in the source there is a line which looks like:
if (inclusiveEnd + 1 > size) {
return ERR_INVALID;
}
HTTP ranges are inclusive, and most likely implemented here with unsigned 64 bit integers. My guess is the author converted to exclusive range, then compared with size, as a form of validation. It passes the check, because 18446744073709551615 + 1 results in wraparound to 0.
The general solution is instead to use something like:
if (size < offset || start > size - offset) {
... // range violated
}
But you hardly ever see people do that.
- TheLoneWolfling 11y agoNote that that solution won't work with signed values, and compilers will happily optimize out the check in that case.