From: "Pablo Sabater" <pabloosabaterr@gmail.com>
To: "Chandra Pratap" <chandrapratap3519@gmail.com>,
"Pablo Sabater" <pabloosabaterr@gmail.com>
Cc: <git@vger.kernel.org>, <karthik.188@gmail.com>, <gitster@pobox.com>
Subject: Re: [PATCH GSoC 2/5] fetch-object-info: parse type from server response
Date: Wed, 29 Jul 2026 14:05:49 +0200 [thread overview]
Message-ID: <DKB1II4Z88SG.38KG7RAF9Q7VW@gmail.com> (raw)
In-Reply-To: <CA+J6zkSQYuK-ZJoiQkEJDS9fBypOrBEmgYZRj1yYU00ws2u_HA@mail.gmail.com>
On Wed Jul 29, 2026 at 11:57 AM CEST, Chandra Pratap wrote:
> On Sat, 25 Jul 2026 at 17:25, Pablo Sabater <pabloosabaterr@gmail.com> wrote:
>>
>> The server can handle type requests but does not advertise the
>> capability yet. Prepare the client to know how to parse the server
>> response once the server advertises the capability.
>>
>> Mentored-by: Karthik Nayak <karthik.188@gmail.com>
>> Mentored-by: Chandra Pratap <chandrapratap3519@gmail.com>
>> Signed-off-by: Pablo Sabater <pabloosabaterr@gmail.com>
>> ---
>> fetch-object-info.c | 12 +++++++++++-
>> 1 file changed, 11 insertions(+), 1 deletion(-)
>>
>> diff --git a/fetch-object-info.c b/fetch-object-info.c
>> index ba7e179c44..cf6b94afb8 100644
>> --- a/fetch-object-info.c
>> +++ b/fetch-object-info.c
>> @@ -50,6 +50,7 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>> const int stateless_rpc, const int fd_out)
>> {
>> int size_index = -1;
>> + int type_index = -1;
>>
>> switch (version) {
>> case protocol_v2:
>> @@ -101,8 +102,13 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>> for (size_t j = 0; j < args->oids->nr; j++)
>> object_info_data[j].sizep =
>> xcalloc(1, sizeof(*object_info_data[j].sizep));
>> + } else if (!strcmp(reader->line, "type")) {
>> + type_index = (int)i;
>> + for (size_t j = 0; j < args->oids->nr; j++)
>> + object_info_data[j].typep =
>> + xcalloc(1, sizeof(*object_info_data[j].typep));
>> } else {
>> - BUG("only size is supported");
>> + BUG("unexpected object-info option: %s", reader->line);
>> }
>> }
>>
>> @@ -148,6 +154,10 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>> object_info_values.items[0].string,
>> object_info_values.items[size_index + 1].string);
>>
>> + if (type_index >= 0)
>> + *object_info_data[i].typep =
>> + type_from_string(object_info_values.items[type_index + 1].string);
>> +
>> string_list_clear(&object_info_values, 0);
>
> Is there a risk of an out-of-bounds array access here if the server
> responds with a truncated or malformed packet?
>
> If object_info_values.nr <= type_index + 1, this will segfault.
This shouldn't be a possible case because of:
fetch_object_info()
for (size_t i = 0; i < args->object_info_options->nr; i++) {
[snip]
} else if (!strcmp(reader->line, "type")) {
type_index = (int)i;
[snip]
type_index is set based of the range of object_info_options->nr so:
type_index < object_info_options->nr
and a few lines below:
if (args->object_info_options->nr + 1 != object_info_values.nr)
die("object-info: unexpected number of attributes: %s",
reader->line);
so we also know that type_index + 1 < object_info_values.nr.
After that we get to those lines that this patch introduced:
+ if (type_index >= 0)
+ *object_info_data[i].typep =
+ type_from_string(object_info_values.items[type_index + 1].string);
And because type_index + 1 < object_info_values.nr we can be sure that
this cannot segfault once we reach this code.
>
> If there isn't a bounds check slightly higher up in this loop, we should
> add one. Either way, we should definitely add a test using a mocked
> server response (e.g., via test-tool pkt-line) to ensure the client
> gracefully dies with a protocol error rather than segfaulting when it
> receives a malformed packet.
Ok, that's sounds a good test, I think there's none where a malicious
server is simulated, in part because I don't know how and I think I
haven't seen a test that does that yet.
test-tool and pkt-line are used for the opposite: simulating the
client to test the real server.
I'll see what I can do about it.
Thanks for the feedback,
Pablo
next prev parent reply other threads:[~2026-07-29 12:05 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-25 11:55 [PATCH GSoC 0/5] cat-file: extend remote-object-info to support %(objecttype) Pablo Sabater
2026-07-25 11:55 ` [PATCH GSoC 1/5] protocol-caps: add type support to object-info Pablo Sabater
2026-07-29 9:53 ` Chandra Pratap
2026-07-29 11:18 ` Pablo Sabater
2026-07-29 15:40 ` Junio C Hamano
2026-07-25 11:55 ` [PATCH GSoC 2/5] fetch-object-info: parse type from server response Pablo Sabater
2026-07-29 9:57 ` Chandra Pratap
2026-07-29 12:05 ` Pablo Sabater [this message]
2026-07-29 17:06 ` Chandra Pratap
2026-07-25 11:55 ` [PATCH GSoC 3/5] fetch-object-info: request all supported options dynamically Pablo Sabater
2026-07-29 9:57 ` Chandra Pratap
2026-07-29 12:07 ` Pablo Sabater
2026-07-25 11:55 ` [PATCH GSoC 4/5] serve: advertise type capability Pablo Sabater
2026-07-29 9:58 ` Chandra Pratap
2026-07-29 12:15 ` Pablo Sabater
2026-07-25 11:55 ` [PATCH GSoC 5/5] cat-file: unify default format Pablo Sabater
2026-07-29 9:59 ` Chandra Pratap
2026-07-29 12:23 ` Pablo Sabater
2026-07-29 9:52 ` [PATCH GSoC 0/5] cat-file: extend remote-object-info to support %(objecttype) Chandra Pratap
2026-07-29 12:34 ` Pablo Sabater
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DKB1II4Z88SG.38KG7RAF9Q7VW@gmail.com \
--to=pabloosabaterr@gmail.com \
--cc=chandrapratap3519@gmail.com \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
--cc=karthik.188@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox