From 40eef914f35208ee3f34faf063e2e5bdb94cc034 Mon Sep 17 00:00:00 2001 From: Luca Boccassi Date: Wed, 8 Apr 2026 00:59:48 +0100 Subject: [PATCH] limits-util: use MUL_SAFE for physical memory calculation Coverity flags (uint64_t)sc * (uint64_t)ps as a potential overflow. Use MUL_SAFE which Coverity understands via __builtin_mul_overflow. Physical page count times page size cannot realistically overflow uint64_t, but this makes it provable to static analyzers. CID#1548042 Follow-up for 09bb6448ae221c09a00d1f4a9b45ce8535003319 --- src/basic/limits-util.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/src/basic/limits-util.c b/src/basic/limits-util.c index 02fbe92cc77..732d0c6a6f4 100644 --- a/src/basic/limits-util.c +++ b/src/basic/limits-util.c @@ -28,9 +28,9 @@ uint64_t physical_memory(void) { assert(sc > 0); ps = page_size(); - /* Silence static analyzers */ - assert((uint64_t) sc <= UINT64_MAX / (uint64_t) ps); - mem = (uint64_t) sc * (uint64_t) ps; + /* Physical page count times page size cannot realistically overflow uint64_t, + * but use MUL_SAFE to make this obvious to static analyzers. */ + assert_se(MUL_SAFE(&mem, (uint64_t) sc, (uint64_t) ps)); r = cg_get_root_path(&root); if (r < 0) { -- 2.47.3