Skip to content

Guard Go allocation capacities against integer overflow - #65653

Merged
pelikhan merged 3 commits into
mainfrom
copilot/aw-top-10-fix-allocation-overflow-alerts
Oct 4, 2026
Merged

pelikhan merged 3 commits into
mainfrom
copilot/aw-top-10-fix-allocation-overflow-alerts

Conversation

Copilot AI commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Allocation-size overflow alerts recur where input-derived lengths are combined for slice or map capacity. Use checked capacity arithmetic for those sums and avoid explicit input-sized preallocation at flagged call sites.

  • Checked sums: Route capacity calculations in MCP setup, MCP CLI prompt generation, AI execution steps, and code-scanning upload steps through typeutil.SafeAllocationCapacity.
  • Input-sized allocations: Remove explicit capacity hints from flagged experiment-analysis and GitHub configuration slices; append behavior and output remain unchanged.
  • Boundary coverage: Reuse the shared helper’s existing tests for MaxInt, overflow, and negative inputs.
steps := make([]string, 0,
    typeutil.SafeAllocationCapacity(len(tokenMintSteps), len(uploadSteps)))

Copilot AI linked an issue Oct 4, 2026 that may be closed by this pull request
2 tasks
Copilot AI and others added 2 commits October 4, 2026 20:46
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix CodeQL allocation overflow alerts with safe-capacity helper Guard Go allocation capacities against integer overflow Oct 4, 2026
Copilot AI requested a review from pelikhan October 4, 2026 20:47
@pelikhan
pelikhan marked this pull request as ready for review October 4, 2026 20:48
Copilot AI balanced review requested due to automatic review settings October 4, 2026 20:48
@pelikhan
pelikhan merged commit 0607713 into main Oct 4, 2026
3 checks passed
@pelikhan
pelikhan deleted the copilot/aw-top-10-fix-allocation-overflow-alerts branch October 4, 2026 20:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The schema change breaks supported expression-valued concurrency queue configurations and an existing test.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Hardens Go allocation capacity calculations against integer overflow using the shared typeutil helper.

Changes:

  • Applies checked arithmetic to combined capacity hints.
  • Removes selected input-sized preallocations.
  • Incidentally restricts expression-valued concurrency queues.
File Description
pkg/​workflow/​schemas/​github-workflow.json Restricts concurrency queue values.
pkg/​workflow/​mcp_setup_generator.go Safely sizes copied tool maps.
pkg/​workflow/​mcp_github_config.go Hardens or removes capacity hints.
pkg/​workflow/​mcp_cli_mount.go Safely sizes prompt lines.
pkg/​workflow/​create_code_scanning_alert.go Safely combines upload steps.
pkg/​workflow/​compiler_yaml_ai_execution.go Safely sizes injected execution steps.
pkg/​cli/​experiments_command.go Removes experiment-result preallocation.

Comment on lines +45 to +46
"type": "string",
"enum": ["single", "max"],
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AW Top 10] 03 Burn down CodeQL allocation overflow alerts

3 participants