Worst-case binding_t slot count for a node cross-join: one row per * (existing binding × extra node), plus — for an OPTIONAL join with no extra * nodes — one fallback row per existing binding, plus a trailing sentinel slot. * * The plain-int product bind_count * extra_count overflows to a negative/garbage * malloc size on large graphs (the failure mode fixed for cross_join_with_rels), * so t
| 4536 | * *out_n on success, CBM_NOT_FOUND on overflow. Non-static so the arithmetic |
| 4537 | * boundary can be unit-tested directly. */ |
| 4538 | int cbm_cypher_cross_join_alloc(int bind_count, int extra_count, bool opt, size_t *out_n) { |
| 4539 | size_t per_binding = extra_count > 0 ? (size_t)extra_count : (opt ? (size_t)SKIP_ONE : 0U); |
| 4540 | size_t rows = (size_t)bind_count * per_binding; |
| 4541 | if (rows > (size_t)INT_MAX) { |
| 4542 | return CBM_NOT_FOUND; /* new_count would not fit the int binding counter */ |
| 4543 | } |
| 4544 | size_t n = rows + SKIP_ONE; |
| 4545 | if (n > SIZE_MAX / sizeof(binding_t)) { |
| 4546 | return CBM_NOT_FOUND; /* alloc_n * sizeof(binding_t) would overflow size_t */ |
| 4547 | } |
| 4548 | *out_n = n; |
| 4549 | return 0; |
| 4550 | } |
| 4551 | |
| 4552 | /* Cross-join node-only pattern into existing bindings. Returns 0 on success, |
| 4553 | * CBM_NOT_FOUND when the allocation is refused (overflow) or fails (OOM); the |
no outgoing calls
no test coverage detected