From: tnyman@openai.com
To: git@vger.kernel.org
Cc: Ted Nyman <tnyman@openai.com>, Derrick Stolee <stolee@gmail.com>,
Taylor Blau <me@ttaylorr.com>, Jeff King <peff@peff.net>,
Victoria Dye <vdye@github.com>
Subject: [PATCH 1/2] pathspec: use match for sparse-index expansion checks
Date: Mon, 20 Jul 2026 15:31:20 -0700 [thread overview]
Message-ID: <20260720223118.62821-5-tnyman@openai.com> (raw)
In-Reply-To: <20260720223118.62821-4-tnyman@openai.com>
From: Ted Nyman <tnyman@openai.com>
The pathspec parser computes `len` and `nowildcard_len` from
`item.match`, which includes any prefix added when a command is run
from a subdirectory. `item.original` can still contain the shorter,
unprefixed argument.
Using `item.original + item.nowildcard_len` in
`pathspec_needs_expanded_index()` can therefore read past the end of
the allocation. AddressSanitizer reports a heap-buffer-overflow for
prefixed wildcard pathspecs passed to `git rm` and `git reset` with a
sparse index.
The mismatch dates back to 4d1cfc1351 ("reset: make --mixed
sparse-aware", 2021-11-29), which introduced the helper using
`item.original`. b29ad38322 ("pathspec.h: move
pathspec_needs_expanded_index() from reset.c to here", 2022-08-07)
later moved it to `pathspec.c` and preserved the affected comparisons.
Use `item.match` consistently when checking whether a pathspec can
match a sparse-directory entry. Add coverage for prefixed wildcard
pathspecs so both commands keep the index sparse.
Signed-off-by: Ted Nyman <tnyman@openai.com>
---
pathspec.c | 12 ++++++------
t/t1092-sparse-checkout-compatibility.sh | 7 +++++++
2 files changed, 13 insertions(+), 6 deletions(-)
diff --git a/pathspec.c b/pathspec.c
index f78b22709ccb67..281858f21f9c59 100644
--- a/pathspec.c
+++ b/pathspec.c
@@ -847,9 +847,9 @@ int pathspec_needs_expanded_index(struct index_state *istate,
* - not-in-cone/bar*: may need expanded index
* - **.c: may need expanded index
*/
- if (strspn(item.original + item.nowildcard_len, "*") ==
+ if (strspn(item.match + item.nowildcard_len, "*") ==
(unsigned int)(item.len - item.nowildcard_len) &&
- path_in_cone_mode_sparse_checkout(item.original, istate))
+ path_in_cone_mode_sparse_checkout(item.match, istate))
continue;
for (pos = 0; pos < istate->cache_nr; pos++) {
@@ -865,7 +865,7 @@ int pathspec_needs_expanded_index(struct index_state *istate,
*/
if ((unsigned int)item.nowildcard_len >
ce_namelen(ce) &&
- !strncmp(item.original, ce->name,
+ !strncmp(item.match, ce->name,
ce_namelen(ce))) {
res = 1;
break;
@@ -876,13 +876,13 @@ int pathspec_needs_expanded_index(struct index_state *istate,
* directory and the pathspec does not match the whole
* directory, need to expand the index.
*/
- if (!strncmp(item.original, ce->name, item.nowildcard_len) &&
- wildmatch(item.original, ce->name, 0)) {
+ if (!strncmp(item.match, ce->name, item.nowildcard_len) &&
+ wildmatch(item.match, ce->name, 0)) {
res = 1;
break;
}
}
- } else if (!path_in_cone_mode_sparse_checkout(item.original, istate) &&
+ } else if (!path_in_cone_mode_sparse_checkout(item.match, istate) &&
!matches_skip_worktree(pathspec, i, &skip_worktree_seen))
res = 1;
diff --git a/t/t1092-sparse-checkout-compatibility.sh b/t/t1092-sparse-checkout-compatibility.sh
index 9814431cd74aff..d0b42371663f9d 100755
--- a/t/t1092-sparse-checkout-compatibility.sh
+++ b/t/t1092-sparse-checkout-compatibility.sh
@@ -2119,6 +2119,13 @@ test_expect_success 'sparse index is not expanded: rm' '
ensure_not_expanded rm -r deep
'
+test_expect_success 'sparse index is not expanded: prefixed wildcard pathspec' '
+ init_repos &&
+
+ ensure_not_expanded -C deep rm --dry-run -- "a*" &&
+ ensure_not_expanded -C deep reset base -- "a*"
+'
+
test_expect_success 'grep with and --cached' '
init_repos &&
next prev parent reply other threads:[~2026-07-20 22:31 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 22:31 [PATCH 0/2] stash: avoid sparse-index expansion for in-cone paths tnyman
2026-07-20 22:31 ` tnyman [this message]
2026-07-20 23:53 ` [PATCH 1/2] pathspec: use match for sparse-index expansion checks Taylor Blau
2026-07-20 22:31 ` [PATCH 2/2] stash: avoid sparse-index expansion for in-cone paths tnyman
2026-07-20 23:54 ` Taylor Blau
2026-07-21 19:34 ` Junio C Hamano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720223118.62821-5-tnyman@openai.com \
--to=tnyman@openai.com \
--cc=git@vger.kernel.org \
--cc=me@ttaylorr.com \
--cc=peff@peff.net \
--cc=stolee@gmail.com \
--cc=vdye@github.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox