Skip to content

Cap Duration-based timeouts exceeding int range in request factories - #37335

Open
minwoo-3 wants to merge 1 commit into
spring-projects:mainfrom
minwoo-3:clamp-large-timeouts
Open

minwoo-3 wants to merge 1 commit into
spring-projects:mainfrom
minwoo-3:clamp-large-timeouts

Conversation

@minwoo-3

Copy link
Copy Markdown

SimpleClientHttpRequestFactory#setConnectTimeout(Duration), SimpleClientHttpRequestFactory#setReadTimeout(Duration) and ReactorClientHttpRequestFactory#setConnectTimeout(Duration) narrow Duration#toMillis() to an int with a plain cast. Above Integer.MAX_VALUE milliseconds (about 24.8 days) the value wraps around:

Duration (int) toMillis() SimpleClientHttpRequestFactory ReactorClientHttpRequestFactory
ofDays(24) 2073600000 24 days 24 days
ofDays(25) -2134967296 timeout silently not applied IllegalArgumentException: Timeout must be a non-negative value
ofDays(50) 25032704 ~7 hours ~7 hours
ofDays(365) 1471228928 ~17 days ~17 days

This caps such values at Integer.MAX_VALUE, the longest timeout the underlying int-based APIs can express. Values within the int range are unaffected. It follows the same spirit as the overflow fix in gh-37208.

SimpleClientHttpRequestFactory#setConnectTimeout(Duration),
SimpleClientHttpRequestFactory#setReadTimeout(Duration) and
ReactorClientHttpRequestFactory#setConnectTimeout(Duration) narrow
Duration#toMillis() to an int with a plain cast. Above
Integer.MAX_VALUE milliseconds (about 24.8 days) the value wraps
around: Duration.ofDays(50) silently becomes a timeout of about
7 hours, while Duration.ofDays(25) becomes negative and is either
ignored (SimpleClientHttpRequestFactory) or rejected as
"Timeout must be a non-negative value" (ReactorClientHttpRequestFactory).

This caps such values at Integer.MAX_VALUE instead.

Signed-off-by: minwoo-3 <[email protected]>
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged or decided on label Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-triage An issue we've not yet triaged or decided on

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants