{"record":{"id":"72f8140c9bbc3d1b","repo":"vectordotdev/vector","slug":"max-future-ms-validated-to-fit-in-i64-in-aggregate-new","errorCode":null,"errorMessage":"max_future_ms validated to fit in i64 in Aggregate::new","messagePattern":"max_future_ms validated to fit in i64 in Aggregate::new","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/transforms/aggregate/event_time.rs","lineNumber":72,"sourceCode":"        let ts = match timestamp {\n            Some(ts) => ts,\n            None => match event_time.missing_timestamp {\n                MissingTimestamp::UseSystemTime => now,\n                MissingTimestamp::Drop => {\n                    emit!(AggregateEventDropped {\n                        reason: \"Event missing timestamp required for event-time aggregation.\"\n                    });\n                    return None;\n                }\n            },\n        };\n        // Preserve (or synthesize) the timestamp in the stored metric so that\n        // event-time \"latest\" selection can compare timestamps reliably.\n        data.time.timestamp = Some(ts);\n\n        if event_time.max_future_ms > 0 {\n            let max_future_ms = i64::try_from(event_time.max_future_ms)\n                .expect(\"max_future_ms validated to fit in i64 in Aggregate::new\");\n            let drift_ms = ts.timestamp_millis().saturating_sub(now_ms);\n            if drift_ms > max_future_ms {\n                emit!(AggregateEventDropped {\n                    reason: \"Event timestamp too far in the future.\"\n                });\n                return None;\n            }\n        }\n\n        let bucket_key = self.bucket_key(ts);\n\n        if self.was_bucket_flushed(bucket_key) {\n            emit!(AggregateEventDropped {\n                reason: \"Event timestamp is too late; bucket already flushed.\"\n            });\n            return None;\n        }\n","sourceCodeStart":54,"sourceCodeEnd":90,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/src/transforms/aggregate/event_time.rs#L54-L90","documentation":"`record_event_time` converts `event_time.max_future_ms` (u64) to i64 and expects it to fit, claiming validation in `Aggregate::new`. If `max_future_ms` exceeds `i64::MAX`, `try_from` fails and the process panics per-event. The expect encodes an invariant established at construction time.","triggerScenarios":"An `Aggregate` constructed without validating `max_future_ms <= i64::MAX` (or a config value above i64::MAX reaching record_event_time), then processing a metric event with `max_future_ms > 0`.","commonSituations":"Extremely large `max_future_ms` values in config (e.g. hand-written huge numbers) bypassing the constructor validation in a fork or older version.","solutions":["Set `max_future_ms` to a sane value below i64::MAX (e.g. milliseconds-hours/days)","Ensure `Aggregate::new` validates and rejects over-large `max_future_ms` at config load","Run `vector validate` on the config to reject the value before runtime","File a bug if a within-limits config still triggers the panic"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// reject oversized max_future_ms before building\nif cfg.event_time.max_future_ms > i64::MAX as u64 {\n    return Err(\"max_future_ms too large\".into());\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep durations in config within practical ranges","Validate u64 millis fit i64 at config parse time","Enforce `Aggregate::new` range checks in CI tests","Run `vector validate` pre-deploy"],"tags":["rust","panic","integer-overflow","transforms"],"backgroundTag":"value-out-of-range","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}