Skip to content

Check for integer overflow when narrowing Query skip - #5244

Open
anjeongkyun wants to merge 1 commit into
spring-projects:mainfrom
anjeongkyun:skip-int-overflow
Open

anjeongkyun wants to merge 1 commit into
spring-projects:mainfrom
anjeongkyun:skip-int-overflow

Conversation

@anjeongkyun

Copy link
Copy Markdown
  • You have read the Spring Data contribution guidelines.
  • You use the code formatters provided here and have them applied to your changes. Don’t submit any formatting related changes.
  • You submit test cases (unit or integration tests) that back your changes.
  • You added yourself as author in the headers of the classes you touched.

Motivation

Query.skip takes a long and Pageable.getOffset() returns a long, but the driver and the wire protocol take an int. Three places narrowed with a plain cast:

// QueryOperations
if (query.getSkip() > 0) {
    options.skip((int) query.getSkip());
}

// MongoTemplate
cursorToUse = cursorToUse.skip((int) skip);

// ReactiveMongoTemplate
findPublisherToUse = findPublisherToUse.skip((int) skip);

The > 0 check passes for a large skip, and the cast then wraps it to a negative that goes straight to the driver. PageRequest.of(500_000, 5_000) carries an offset of 2,500,000,000, which arrives as -1,794,967,296, and SliceUtils.limitResult feeds exactly that into Query.skip.

Change

The three sites share a check that reports the offending value rather than wrapping it. skip values inside the range behave as before.

I put the helper on QueryOperations since two of the three callers already reach for it; say the word if you would rather have it somewhere else, or inline at each site.

QueryOperationsUnitTests, MongoTemplateUnitTests and ReactiveMongoTemplateUnitTests pass (356 tests). The new test fails without the change.

There is no ticket for this one, happy to add the GH- reference to the tests if you open one.

Query.skip takes a long and Pageable.getOffset() is a long, but the driver and
the wire protocol take an int. A skip above Integer.MAX_VALUE wrapped to a
negative and was handed to the driver as such: PageRequest.of(500_000, 5_000)
carries an offset of 2_500_000_000, which arrived as -1_794_967_296.

The three narrowing sites now go through a shared check that reports the value
instead.

Signed-off-by: anjeongkyun <anwjdrbs123@gmail.com>
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Sep 16, 2026
@mp911de mp911de added type: task A general task and removed status: waiting-for-triage An issue we've not yet triaged labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: task A general task

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants