Description
NumPy fixed-width integer types such as int8, int16, int32 and int64 may wrap when a value exceeds their range. Without validation, calculations of amounts, sizes or iteration counts may produce unintended values.
Potential impact
- Size or count calculations may produce smaller values than expected, causing limits to work incorrectly.
- Negative or wrapped values may disrupt payment, allocation or numerical processing logic.
Remediation
- Check the permitted range with
np.iinfo(dtype)before calculating. - Use Python
intor a sufficiently large type where accuracy is required, and validate the result's range again.
Examples
This example checks the result range for nonnegative integers. When external input can request large powers, also bound input size and the exponent to limit memory use and processing time.
Before
python
result = np.power(number, pow_value, dtype=np.int64)
After
python
limit = np.iinfo(np.int64).max
base = int(number)
exponent = int(pow_value)
if base < 0 or exponent < 0:
raise ValueError("unsupported input")
result = base ** exponent
if result > limit:
raise ValueError("too large")
Explanation:
- Before: Arithmetic with fixed-width NumPy dtypes such as int8, int16, int32 and int64 may wrap outside their range, unlike Python int.
- After: Calculates with Python
intand checks that the result fits the fixed-width dtype, preventing a wrapped NumPy integer from being used in later calculations.