{"thread":{"id":"27830","subject":"[PATCH] remote-curl: Add a format check to parsing of info/refs","startedAt":"2011-07-16T18:23:51Z","lastAt":"2011-07-16T18:23:51Z","messageCount":1,"participants":["Julian Phillips"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"171487","messageId":"20110716182352.85371.18215.julian@quantumfyre.co.uk","threadId":"27830","inReplyTo":null,"subject":"[PATCH] remote-curl: Add a format check to parsing of info/refs","fromName":"Julian Phillips","fromEmail":"julian@quantumfyre.co.uk","sentAt":"2011-07-16T18:23:51Z","receivedAt":"2011-07-16T18:23:51Z","isPatch":true,"sender":{"key":"julian@quantumfyre.co.uk","avatar":"https://avatars.githubusercontent.com/u/948888?v=4"},"body":"When parsing info/refs, no checks were applied that the file was in\nthe requried format.  Since the file is read from a remote webserver,\nthis isn't guarenteed to be true.  Add a check that the file at least\nonly contains lines that consist of 40 characters followed by a tab\nand then the ref name.\n\nSigned-off-by: Julian Phillips <julian@quantumfyre.co.uk>\n---\n\nIf you happen to try, for example, git ls-remote http://example.com/foo, when\nhttp://example.com/foo/info/refs exists - but isn't part of a git repository you\nget a very strange response as remote-curl.c attempts to parse refs out of the\nfile.  This may be an unlikely situtation, but that doesn't mean it can't be\nhanlded a little better.\n\nJulian\n\n remote-curl.c |    2 ++\n 1 files changed, 2 insertions(+), 0 deletions(-)\n\ndiff --git a/remote-curl.c b/remote-curl.c\nindex b5be25c..8ac5028 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -227,6 +227,8 @@ static struct ref *parse_info_refs(struct discovery *heads)\n \t\tif (data[i] == '\\t')\n \t\t\tmid = &data[i];\n \t\tif (data[i] == '\\n') {\n+\t\t\tif (mid - start != 40)\n+\t\t\t\tdie(\"%sinfo/refs not valid: is this a git repository?\", url);\n \t\t\tdata[i] = 0;\n \t\t\tref_name = mid + 1;\n \t\t\tref = xmalloc(sizeof(struct ref) +\n-- \n1.7.6\n"}]}