Skip to content

gosec: address G115 integer overflow conversions and re-enable linter - #7362

Open
Ankitraj-sharma wants to merge 1 commit into
docker:masterfrom
Ankitraj-sharma:fix/address-g115-integer-overflow
Open

Ankitraj-sharma wants to merge 1 commit into
docker:masterfrom
Ankitraj-sharma:fix/address-g115-integer-overflow

Conversation

@Ankitraj-sharma

Copy link
Copy Markdown

Summary

This PR addresses all G115 (integer overflow conversion) warnings flagged by gosec across the codebase with bounds checks and safe #nosec G115 annotations, and re-enables the G115 linter in .golangci.yml as requested in #5584.

Detailed Changes:

  1. opts/swarmopts/port.go: Added #nosec G115 annotations for TargetPort and PublishedPort (derived from uint16 port numbers).
  2. cli/command/service/logs.go: Added #nosec G115 annotation where replicas is converted to int for terminal padding calculation.
  3. cli/compose/convert/service.go:
    • Added #nosec G115 for healthcheck retries conversion to int.
    • Added #nosec G115 for restart policy uint64Ptr(policy.MaximumRetryCount) (guarded non-negative).
  4. cli/command/container/cp.go: Added #nosec G115 for terminal column width calculation.
  5. cli/command/container/opts.go: Added #nosec G115 for non-negative ioMaxBandwidth.
  6. cli/command/container/stats_helpers.go: Added explicit guard on elapsed nanoseconds (ns <= 0) before converting to uint64(ns).
  7. cli/command/image/tree.go: Added #nosec G115 for terminal width conversion to int.
  8. cli/command/service/progress/progress.go:
    • Added #nosec G115 for replica / running task counts and job concurrency/completion calculations.
    • Added explicit bounds check mappedSlot < 0 || uint64(mappedSlot) > replicas before conversion.
  9. .golangci.yml: Removed - G115 from gosec.excludes to re-enable the linter rule.

Release notes (optional)

@codecov-commenter

codecov-commenter commented Oct 8, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@Ankitraj-sharma
Ankitraj-sharma force-pushed the fix/address-g115-integer-overflow branch 2 times, most recently from d1c94df to 62b5e23 Compare October 8, 2026 16:05
Address G115 (integer overflow conversion) warnings across the codebase with bounds checks and #nosec annotations for safe conversions, and re-enable the G115 rule in .golangci.yml.

Fixes docker#5584

Signed-off-by: Ankit raj sharma <ankitrajsharma666@gmail.com>
@Ankitraj-sharma
Ankitraj-sharma force-pushed the fix/address-g115-integer-overflow branch from 62b5e23 to 0163d9c Compare October 8, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

testing: address G115: integer overflow conversion int issues and re-enable linter (gosec)

2 participants