From: Jeff King <peff@peff.net>
To: Patrick Steinhardt <ps@pks.im>
Cc: git@vger.kernel.org, Elijah Newren <newren@gmail.com>
Subject: Re: [PATCH 5/5] xdiff: NUL-terminate buffers read by read_mmfile()
Date: Wed, 30 Sep 2026 18:49:35 -0400 [thread overview]
Message-ID: <20260930224935.GB765052@coredump.intra.peff.net> (raw)
In-Reply-To: <ar0rp1cSIKuCMZyQ@pks.im>
On Wed, Sep 30, 2026 at 05:32:55PM +0200, Patrick Steinhardt wrote:
> > This one is obviously optional, which is why I put it last.
>
> Hm, I'm somewhat indifferent here. It always feels a bit weird to be
> this defensive because "programming errors", as the next question then
> is "but what about all the other errors where we're not defensive?" But
> the xdiff code is complex enough with a bunch of pointer arithmetics, so
> maybe it's not even that bad of an idea.
>
> That being said, I feel like a better course of action could be to use a
> fuzzer for this code, because as far as I'm aware we have none yet, and
> that would potentially shake out a bunch of bugs. But that still doesn't
> really help us to catch platform-specific bugs due to different integer
> sizes.
I look at it as: why not do both?
Mostly the lack of extra NUL surprised me, as we routinely add one in
most other places (and it has prevented some memory bugs in the past).
> The counterargument is that before your 3/5 we used to use xmallocz, so
> you're essentially just reinstating the previous safety guards.
Yes, though I did confirm that those guards were doing nothing. This is
less about protecting the new ll_ext_merge() caller and more about all
of the _other_ callers of read_mmfile().
But yeah, it is obviously a lot easier to explain if this patch comes
first. I just wasn't sure if we'd want to drop it or not (though yeah,
we probably should explain in the earlier patch that the lack of NUL
termination is OK).
I'll re-roll with this patch earlier in the series.
> > diff --git a/xdiff-interface.c b/xdiff-interface.c
> > index bc340d5a8a..b3e9f1952b 100644
> > --- a/xdiff-interface.c
> > +++ b/xdiff-interface.c
> > @@ -166,7 +166,7 @@ int read_mmfile(mmfile_t *ptr, const char *filename)
> > if (!(f = fopen(filename, "rb")))
> > return error_errno("Could not open %s", filename);
> > sz = xsize_t(st.st_size);
> > - ptr->ptr = xmalloc(sz ? sz : 1);
> > + ptr->ptr = xmallocz(sz);
>
> I was staring at this code a while before I noticed the added `z` at the
> end of this function.
Heh, fair. I'll say something more explicit in the commit message when
re-rolling.
-Peff
next prev parent reply other threads:[~2026-09-30 22:49 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 6:49 [PATCH 0/5] use size_t for xdiff mmfile_t Jeff King
2026-09-29 6:51 ` [PATCH 1/5] xdiff: clean up read_mmfile() allocations on error Jeff King
2026-09-29 18:37 ` Junio C Hamano
2026-09-29 6:52 ` [PATCH 2/5] xdiff: replace mmbuffer_t with mmfile_t Jeff King
2026-09-29 11:08 ` D. Ben Knoble
2026-09-29 18:39 ` Junio C Hamano
2026-09-30 15:32 ` Patrick Steinhardt
2026-09-30 22:46 ` Jeff King
2026-10-01 15:40 ` Junio C Hamano
2026-09-29 6:54 ` [PATCH 3/5] xdiff: use size_t for buffer sizes Jeff King
2026-09-29 6:54 ` [PATCH 4/5] merge-ll: use read_mmfile() to read external merge results Jeff King
2026-09-29 19:22 ` Junio C Hamano
2026-09-29 20:11 ` Jeff King
2026-09-29 20:41 ` Jeff King
2026-09-29 20:43 ` [PATCH 6/5] merge-ll: handle external driver status before reading result Jeff King
2026-09-29 20:44 ` [PATCH 7/5] merge-ll: report an error when reading external merge results fails Jeff King
2026-09-29 21:19 ` Junio C Hamano
2026-09-29 21:49 ` Jeff King
2026-09-30 18:01 ` Junio C Hamano
2026-09-30 22:41 ` Jeff King
2026-10-01 15:37 ` Junio C Hamano
2026-09-30 15:33 ` [PATCH 4/5] merge-ll: use read_mmfile() to read external merge results Patrick Steinhardt
2026-09-30 22:50 ` Jeff King
2026-09-29 6:55 ` [PATCH 5/5] xdiff: NUL-terminate buffers read by read_mmfile() Jeff King
2026-09-30 15:32 ` Patrick Steinhardt
2026-09-30 19:59 ` Junio C Hamano
2026-09-30 22:49 ` Jeff King [this message]
2026-09-30 23:43 ` [PATCH v2 0/7] use size_t for xdiff mmfile_t Jeff King
2026-09-30 23:44 ` [PATCH v2 1/7] xdiff: clean up read_mmfile() allocations on error Jeff King
2026-09-30 23:44 ` [PATCH v2 2/7] xdiff: replace mmbuffer_t with mmfile_t Jeff King
2026-09-30 23:44 ` [PATCH v2 3/7] xdiff: use size_t for buffer sizes Jeff King
2026-09-30 23:44 ` [PATCH v2 4/7] xdiff: NUL-terminate buffers read by read_mmfile() Jeff King
2026-10-01 13:15 ` Patrick Steinhardt
2026-09-30 23:44 ` [PATCH v2 5/7] merge-ll: use read_mmfile() to read external merge results Jeff King
2026-10-01 13:15 ` Patrick Steinhardt
2026-09-30 23:44 ` [PATCH v2 6/7] merge-ll: handle external driver status before reading result Jeff King
2026-09-30 23:44 ` [PATCH v2 7/7] merge-ll: report an error when reading external merge results fails Jeff King
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930224935.GB765052@coredump.intra.peff.net \
--to=peff@peff.net \
--cc=git@vger.kernel.org \
--cc=newren@gmail.com \
--cc=ps@pks.im \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox