Repository navigation
Conversation
ScaleDouble scales rep_hi and rep_lo separately. rep_lo is never negative, so for a negative Duration with a subsecond part the two partial results have opposite signs, and once the rep_lo part overflows a double the sum is either an infinity of the wrong sign or a NaN that is then converted to int64_t. Saturate with the sign of the exact result as soon as either partial result is not finite.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scaling a Duration by a double goes through ScaleDouble, which multiplies or divides the seconds and subsecond parts of the representation separately and then adds the two partial results back together. The subsecond part is never negative, so for a negative duration that is not a whole number of seconds the two partials have opposite signs. Once the factor is large enough (around 1e299 for half a second) or the divisor small enough (around 1e-299), the subsecond partial overflows to infinity, and the sum is then either an infinity of the wrong sign or, when both partials overflow, a NaN that gets converted to int64_t. In practice absl::Milliseconds(-500) * 1e300 comes back as +InfiniteDuration rather than -InfiniteDuration, and absl::Milliseconds(-500) / denorm_min trips UBSan at the cast in SafeAddRepHi and returns ZeroDuration on arm64, so a negative remaining time scaled this way can turn into an unbounded wait. It came up while reading ScaleDouble: the existing tests for extreme factors only use whole-second durations, so the mixed-sign case is never exercised. I think the least intrusive fix is to saturate with the sign of the exact result as soon as either partial is not finite, which can only happen when the true value is far outside the Duration range, so in-range results should be unchanged. The new cases in InfinityMultiplication and InfinityDivision fail without the change and pass with it.