Git development
 help / color / mirror / Atom feed
From: "Pablo Sabater" <pabloosabaterr@gmail.com>
To: "Chandra Pratap" <chandrapratap3519@gmail.com>,
	"Pablo Sabater" <pabloosabaterr@gmail.com>
Cc: <git@vger.kernel.org>, <karthik.188@gmail.com>, <gitster@pobox.com>
Subject: Re: [PATCH GSoC 2/5] fetch-object-info: parse type from server response
Date: Wed, 29 Jul 2026 14:05:49 +0200	[thread overview]
Message-ID: <DKB1II4Z88SG.38KG7RAF9Q7VW@gmail.com> (raw)
In-Reply-To: <CA+J6zkSQYuK-ZJoiQkEJDS9fBypOrBEmgYZRj1yYU00ws2u_HA@mail.gmail.com>

On Wed Jul 29, 2026 at 11:57 AM CEST, Chandra Pratap wrote:
> On Sat, 25 Jul 2026 at 17:25, Pablo Sabater <pabloosabaterr@gmail.com> wrote:
>>
>> The server can handle type requests but does not advertise the
>> capability yet. Prepare the client to know how to parse the server
>> response once the server advertises the capability.
>>
>> Mentored-by: Karthik Nayak <karthik.188@gmail.com>
>> Mentored-by: Chandra Pratap <chandrapratap3519@gmail.com>
>> Signed-off-by: Pablo Sabater <pabloosabaterr@gmail.com>
>> ---
>>  fetch-object-info.c | 12 +++++++++++-
>>  1 file changed, 11 insertions(+), 1 deletion(-)
>>
>> diff --git a/fetch-object-info.c b/fetch-object-info.c
>> index ba7e179c44..cf6b94afb8 100644
>> --- a/fetch-object-info.c
>> +++ b/fetch-object-info.c
>> @@ -50,6 +50,7 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>>                       const int stateless_rpc, const int fd_out)
>>  {
>>         int size_index = -1;
>> +       int type_index = -1;
>>
>>         switch (version) {
>>         case protocol_v2:
>> @@ -101,8 +102,13 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>>                         for (size_t j = 0; j < args->oids->nr; j++)
>>                                 object_info_data[j].sizep =
>>                                         xcalloc(1, sizeof(*object_info_data[j].sizep));
>> +               } else if (!strcmp(reader->line, "type")) {
>> +                       type_index = (int)i;
>> +                       for (size_t j = 0; j < args->oids->nr; j++)
>> +                               object_info_data[j].typep =
>> +                                       xcalloc(1, sizeof(*object_info_data[j].typep));
>>                 } else {
>> -                       BUG("only size is supported");
>> +                       BUG("unexpected object-info option: %s", reader->line);
>>                 }
>>         }
>>
>> @@ -148,6 +154,10 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>>                             object_info_values.items[0].string,
>>                             object_info_values.items[size_index + 1].string);
>>
>> +               if (type_index >= 0)
>> +                       *object_info_data[i].typep =
>> +                               type_from_string(object_info_values.items[type_index + 1].string);
>> +
>>                 string_list_clear(&object_info_values, 0);
>
> Is there a risk of an out-of-bounds array access here if the server
> responds with a truncated or malformed packet?
>
> If object_info_values.nr <= type_index + 1, this will segfault.

This shouldn't be a possible case because of:

fetch_object_info()

	for (size_t i = 0; i < args->object_info_options->nr; i++) {

		[snip]

		} else if (!strcmp(reader->line, "type")) {
			type_index = (int)i;

		[snip]

type_index is set based of the range of object_info_options->nr so:
  type_index < object_info_options->nr

and a few lines below:

	if (args->object_info_options->nr + 1 != object_info_values.nr)
		die("object-info: unexpected number of attributes: %s",
		    reader->line);

so we also know that type_index + 1 < object_info_values.nr.
After that we get to those lines that this patch introduced:


 +               if (type_index >= 0)
 +                       *object_info_data[i].typep =
 +                               type_from_string(object_info_values.items[type_index + 1].string);

 And because type_index + 1 < object_info_values.nr we can be sure that
 this cannot segfault once we reach this code.

>
> If there isn't a bounds check slightly higher up in this loop, we should
> add one. Either way, we should definitely add a test using a mocked
> server response (e.g., via test-tool pkt-line) to ensure the client
> gracefully dies with a protocol error rather than segfaulting when it
> receives a malformed packet.

Ok, that's sounds a good test, I think there's none where a malicious
server is simulated, in part because I don't know how and I think I
haven't seen a test that does that yet.
test-tool and pkt-line are used for the opposite: simulating the
client to test the real server.

I'll see what I can do about it.

Thanks for the feedback,
Pablo


  reply	other threads:[~2026-07-29 12:05 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-25 11:55 [PATCH GSoC 0/5] cat-file: extend remote-object-info to support %(objecttype) Pablo Sabater
2026-07-25 11:55 ` [PATCH GSoC 1/5] protocol-caps: add type support to object-info Pablo Sabater
2026-07-29  9:53   ` Chandra Pratap
2026-07-29 11:18     ` Pablo Sabater
2026-07-29 15:40     ` Junio C Hamano
2026-07-25 11:55 ` [PATCH GSoC 2/5] fetch-object-info: parse type from server response Pablo Sabater
2026-07-29  9:57   ` Chandra Pratap
2026-07-29 12:05     ` Pablo Sabater [this message]
2026-07-29 17:06       ` Chandra Pratap
2026-07-25 11:55 ` [PATCH GSoC 3/5] fetch-object-info: request all supported options dynamically Pablo Sabater
2026-07-29  9:57   ` Chandra Pratap
2026-07-29 12:07     ` Pablo Sabater
2026-07-25 11:55 ` [PATCH GSoC 4/5] serve: advertise type capability Pablo Sabater
2026-07-29  9:58   ` Chandra Pratap
2026-07-29 12:15     ` Pablo Sabater
2026-07-25 11:55 ` [PATCH GSoC 5/5] cat-file: unify default format Pablo Sabater
2026-07-29  9:59   ` Chandra Pratap
2026-07-29 12:23     ` Pablo Sabater
2026-07-29  9:52 ` [PATCH GSoC 0/5] cat-file: extend remote-object-info to support %(objecttype) Chandra Pratap
2026-07-29 12:34   ` Pablo Sabater

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKB1II4Z88SG.38KG7RAF9Q7VW@gmail.com \
    --to=pabloosabaterr@gmail.com \
    --cc=chandrapratap3519@gmail.com \
    --cc=git@vger.kernel.org \
    --cc=gitster@pobox.com \
    --cc=karthik.188@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox