Fix crash when loading 4GB+ local files on 32-bit Windows

|total_bytes_to_send| is of type uint64_t, which indicates the size of
the local file (when the Range field is not specified in the headers),
and its value may exceed 4GB. On Windows 32-bit operating systems,
size_t is represented by uint32_t.
`base::checked_cast<size_t>(total_bytes_to_send)` actually checks the
conversion of uint64_t to uint32_t. When the value of
|total_bytes_to_send| exceeds 4GB, it cannot pass the check and will
cause a crash.

Why this change is safe: The maximum data size that
`producer_handle->WriteData` can handle is uint32_t, so the size of
|bytes_to_write| should be guaranteed to be within the range of
uint32_t. We should first take the minimum value of
|bytes_to_write.size()| and |total_bytes_to_send| to ensure that it does
not exceed the size of |bytes_to_write| as the count value of
`bytes_to_write.first`. Finally, the conversion of uint64_t type to
size_t needs to be safety checked, which is reasonable and safe.

Bug: 369739222
Change-Id: I10944479a67f1f9a9c0ca16973ab8de51aac15b6
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/5892980
Reviewed-by: Kenichi Ishibashi <bashi@chromium.org>
Reviewed-by: Erik Staab <estaab@chromium.org>
Reviewed-by: Takashi Toyoshima <toyoshim@chromium.org>
Auto-Submit: 吴金立 <wujinli@bytedance.com>
Commit-Queue: Takashi Toyoshima <toyoshim@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1366682}
3 files changed
tree: 4977cd12b8768df8bf7fddc0c793c63670a071ce
  1. android_webview/
  2. apps/
  3. ash/
  4. base/
  5. build/
  6. build_overrides/
  7. buildtools/
  8. cc/
  9. chrome/
  10. chromecast/
  11. chromeos/
  12. codelabs/
  13. components/
  14. content/
  15. crypto/
  16. dbus/
  17. device/
  18. docs/
  19. extensions/
  20. fuchsia_web/
  21. gin/
  22. google_apis/
  23. google_update/
  24. gpu/
  25. headless/
  26. infra/
  27. ios/
  28. ipc/
  29. media/
  30. mojo/
  31. native_client_sdk/
  32. net/
  33. pdf/
  34. ppapi/
  35. printing/
  36. remoting/
  37. rlz/
  38. sandbox/
  39. services/
  40. skia/
  41. sql/
  42. storage/
  43. styleguide/
  44. testing/
  45. third_party/
  46. tools/
  47. ui/
  48. url/
  49. webkit/
  50. .clang-format
  51. .clang-tidy
  52. .clangd
  53. .git-blame-ignore-revs
  54. .gitallowed
  55. .gitattributes
  56. .gitignore
  57. .gitmodules
  58. .gn
  59. .mailmap
  60. .rustfmt.toml
  61. .vpython3
  62. .yapfignore
  63. ATL_OWNERS
  64. AUTHORS
  65. BUILD.gn
  66. CODE_OF_CONDUCT.md
  67. codereview.settings
  68. CPPLINT.cfg
  69. CRYPTO_OWNERS
  70. DEPS
  71. DIR_METADATA
  72. LICENSE
  73. LICENSE.chromium_os
  74. OWNERS
  75. PRESUBMIT.py
  76. PRESUBMIT_test.py
  77. PRESUBMIT_test_mocks.py
  78. README.md
  79. WATCHLISTS
README.md

Logo Chromium

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.

The project's web site is https://www.chromium.org.

To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.

Documentation in the source is rooted in docs/README.md.

Learn how to Get Around the Chromium Source Code Directory Structure.

For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.

If you found a bug, please file it at https://crbug.com/new.