From: Junio C Hamano <gitster@pobox.com>
To: Johannes Schindelin <johannes.schindelin@gmx.de>
Cc: git@vger.kernel.org
Subject: Re: [PATCH 3/6] Make sure fsck_commit_buffer() does not run out of the buffer
Date: Thu, 28 Aug 2014 13:59:50 -0700 [thread overview]
Message-ID: <xmqqr4008h4p.fsf@gitster.dls.corp.google.com> (raw)
In-Reply-To: <alpine.DEB.1.00.1408281646450.990@s15462909.onlinehome-server.info> (Johannes Schindelin's message of "Thu, 28 Aug 2014 16:46:49 +0200 (CEST)")
Johannes Schindelin <johannes.schindelin@gmx.de> writes:
> So far, we assumed that the buffer is NUL terminated, but this is not
> a safe assumption, now that we opened the fsck_object() API to pass a
> buffer directly.
>
> So let's make sure that there is at least an empty line in the buffer.
> That way, our checks would fail if the empty line was encountered
> prematurely, and consequently we can get away with the current string
> comparisons even with non-NUL-terminated buffers are passed to
> fsck_object().
>
> Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
> ---
Heh, I probably should have read this one before commenting on 2/6.
It makes me feel somewhat uneasy to insist that there must be a
blank line in the commit object, even though from the very first
implementation of "commit-tree" I think we have always had a blank
there at the end of the header, even when you feed nothing as the
message to it.
I think the new check is OK, but the message should be s/empty
line/end of header/ or something. It is not like we require an
empty line in the log message proper.
> fsck.c | 23 +++++++++++++++++++++++
> 1 file changed, 23 insertions(+)
>
> diff --git a/fsck.c b/fsck.c
> index dd77628..db6aaa4 100644
> --- a/fsck.c
> +++ b/fsck.c
> @@ -237,6 +237,26 @@ static int fsck_tree(struct tree *item, int strict, fsck_error error_func)
> return retval;
> }
>
> +static int must_have_empty_line(const void *data, unsigned long size,
> + struct object *obj, fsck_error error_func)
> +{
> + const char *buffer = (const char *)data;
> + int i;
> +
> + for (i = 0; i < size; i++) {
> + switch (buffer[i]) {
> + case '\0':
> + return error_func(obj, FSCK_ERROR,
> + "invalid message: NUL at offset %d", i);
> + case '\n':
> + if (i + 1 < size && buffer[i + 1] == '\n')
> + return 0;
> + }
> + }
> +
> + return error_func(obj, FSCK_ERROR, "invalid buffer: missing empty line");
> +}
> +
> static int fsck_ident(const char **ident, struct object *obj, fsck_error error_func)
> {
> char *end;
> @@ -284,6 +304,9 @@ static int fsck_commit_buffer(struct commit *commit, const char *buffer,
> unsigned parent_count, parent_line_count = 0;
> int err;
>
> + if (must_have_empty_line(buffer, size, &commit->object, error_func))
> + return -1;
> +
> if (!skip_prefix(buffer, "tree ", &buffer))
> return error_func(&commit->object, FSCK_ERROR, "invalid format - expected 'tree' line");
> if (get_sha1_hex(buffer, tree_sha1) || buffer[40] != '\n')
next prev parent reply other threads:[~2014-08-28 21:00 UTC|newest]
Thread overview: 68+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-08-28 14:46 [PATCH 0/6] Improve tag checking in fsck and with transfer.fsckobjects Johannes Schindelin
2014-08-28 14:46 ` [PATCH 1/6] Refactor type_from_string() to avoid die()ing in case of errors Johannes Schindelin
2014-08-28 20:43 ` Junio C Hamano
2014-08-28 14:46 ` [PATCH 2/6] Accept object data in the fsck_object() function Johannes Schindelin
2014-08-28 20:47 ` Junio C Hamano
2014-08-29 23:10 ` Jeff King
2014-08-29 23:05 ` Jeff King
2014-08-28 14:46 ` [PATCH 3/6] Make sure fsck_commit_buffer() does not run out of the buffer Johannes Schindelin
2014-08-28 20:59 ` Junio C Hamano [this message]
2014-08-29 23:27 ` Jeff King
2014-08-28 14:46 ` [PATCH 4/6] fsck: check tag objects' headers Johannes Schindelin
2014-08-28 21:25 ` Junio C Hamano
2014-08-28 21:36 ` Junio C Hamano
2014-08-29 23:46 ` Jeff King
2014-08-31 22:46 ` Junio C Hamano
2014-09-03 22:29 ` Jeff King
2014-09-03 23:14 ` Junio C Hamano
2014-09-04 2:04 ` Jeff King
2014-08-29 23:43 ` Jeff King
2014-09-02 18:41 ` Junio C Hamano
2014-09-03 21:38 ` Jeff King
2014-08-28 14:46 ` [PATCH 5/6] Add regression tests for stricter tag fsck'ing Johannes Schindelin
2014-08-28 14:47 ` [PATCH 6/6] Make sure that index-pack --strict fails upon invalid tag objects Johannes Schindelin
2014-09-10 13:52 ` [PATCH v2 0/6] Improve tag checking in fsck and with transfer.fsckobjects Johannes Schindelin
2014-09-10 13:58 ` Johannes Schindelin
2014-09-10 21:07 ` Junio C Hamano
2014-09-10 21:31 ` Junio C Hamano
2014-09-11 14:20 ` Johannes Schindelin
2014-09-11 14:26 ` [PATCH v3 " Johannes Schindelin
2014-09-11 14:26 ` [PATCH v3 1/6] Refactor type_from_string() to avoid die()ing in case of errors Johannes Schindelin
2014-09-11 14:26 ` [PATCH v3 2/6] Accept object data in the fsck_object() function Johannes Schindelin
2014-09-11 14:26 ` [PATCH v3 3/6] Make sure fsck_commit_buffer() does not run out of the buffer Johannes Schindelin
2014-09-11 14:26 ` [PATCH v3 4/6] fsck: check tag objects' headers Johannes Schindelin
2014-09-11 14:26 ` [PATCH v3 5/6] Add regression tests for stricter tag fsck'ing Johannes Schindelin
2014-09-11 14:26 ` [PATCH v3 6/6] Make sure that index-pack --strict checks tag objects Johannes Schindelin
2014-09-11 17:58 ` Junio C Hamano
2014-09-11 21:16 ` Junio C Hamano
2014-09-11 21:17 ` [PATCH 0/3] hash-object --literally Junio C Hamano
2014-09-11 21:17 ` [PATCH 1/3] hash-object: reduce file-scope statics Junio C Hamano
2014-09-11 21:17 ` [PATCH 2/3] hash-object: pass 'write_object' as a flag Junio C Hamano
2014-09-11 21:17 ` [PATCH 3/3] hash-object: add --literally option Junio C Hamano
2014-09-12 8:04 ` [PATCH v3 6/6] Make sure that index-pack --strict checks tag objects Johannes Schindelin
2014-09-12 8:07 ` [PATCH v4 0/6] Improve tag checking in fsck and with transfer.fsckobjects Johannes Schindelin
2014-09-12 8:07 ` [PATCH v4 1/6] Refactor type_from_string() to avoid die()ing in case of errors Johannes Schindelin
2014-09-12 8:07 ` [PATCH v4 2/6] Accept object data in the fsck_object() function Johannes Schindelin
2014-09-12 8:07 ` [PATCH v4 3/6] Make sure fsck_commit_buffer() does not run out of the buffer Johannes Schindelin
2014-09-12 8:08 ` [PATCH v4 4/6] fsck: check tag objects' headers Johannes Schindelin
2014-09-12 8:08 ` [PATCH v4 5/6] Add regression tests for stricter tag fsck'ing Johannes Schindelin
2014-09-12 8:08 ` [PATCH v4 6/6] Make sure that index-pack --strict checks tag objects Johannes Schindelin
2014-09-12 18:02 ` [PATCH v4 0/6] Improve tag checking in fsck and with transfer.fsckobjects Junio C Hamano
2014-09-13 9:08 ` Johannes Schindelin
[not found] ` <cover.1410356761.git.johannes.schindelin@gmx.de>
2014-09-10 13:52 ` [PATCH v2 1/6] Refactor type_from_string() to avoid die()ing in case of errors Johannes Schindelin
2014-09-10 13:52 ` [PATCH v2 2/6] Accept object data in the fsck_object() function Johannes Schindelin
2014-09-10 13:52 ` [PATCH v2 3/6] Make sure fsck_commit_buffer() does not run out of the buffer Johannes Schindelin
2014-09-10 17:43 ` Junio C Hamano
2014-09-11 11:59 ` Johannes Schindelin
2014-09-11 16:49 ` Junio C Hamano
2014-09-10 20:45 ` Eric Sunshine
2014-09-10 13:53 ` [PATCH v2 4/6] fsck: check tag objects' headers Johannes Schindelin
2014-09-10 17:52 ` Junio C Hamano
2014-09-10 13:53 ` [PATCH v2 5/6] Add regression tests for stricter tag fsck'ing Johannes Schindelin
2014-09-10 17:56 ` Junio C Hamano
2014-09-11 14:15 ` Johannes Schindelin
2014-09-10 13:53 ` [PATCH v2 6/6] Make sure that index-pack --strict fails upon invalid tag objects Johannes Schindelin
2014-09-10 21:54 ` Junio C Hamano
2014-09-11 14:22 ` Johannes Schindelin
2014-09-11 16:50 ` Junio C Hamano
2014-09-11 17:04 ` Johannes Schindelin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=xmqqr4008h4p.fsf@gitster.dls.corp.google.com \
--to=gitster@pobox.com \
--cc=git@vger.kernel.org \
--cc=johannes.schindelin@gmx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).