{"thread":{"id":"62325","subject":"[PATCH 0/3] R atoi","startedAt":"2024-10-12T23:09:37Z","lastAt":"2024-11-06T16:03:28Z","messageCount":94,"participants":["Usman Akinyemi via GitGitGadget","Usman Akinyemi","Phillip Wood","Kristoffer Haugsbakk","Patrick Steinhardt","phillip.wood123@gmail.com","Taylor Blau"],"isPatch":true,"patchVersion":1,"patchTotal":3},"messages":[{"id":"504930","messageId":"pull.1810.git.git.1728774574.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":null,"subject":"[PATCH 0/3] R atoi","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-12T23:09:31Z","receivedAt":"2024-10-12T23:09:37Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"parse: replace atoi() with strtoul_ui() and strtol_i()\n\nUsman Akinyemi (3):\n  t3404: avoid losing exit status with focus on `git show` and `git\n    cat-file`\n  t3404: replace test with test_line_count()\n  parse: replace atoi() with strtoul_ui() and strtol_i()\n\n daemon.c                      | 14 ++++---\n imap-send.c                   | 13 +++---\n merge-ll.c                    |  6 +--\n t/t3404-rebase-interactive.sh | 75 +++++++++++++++++++++++------------\n 4 files changed, 69 insertions(+), 39 deletions(-)\n\n\nbase-commit: 90fe3800b92a49173530828c0a17951abd30f0e1\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1810%2FUnique-Usman%2Fr_atoi-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1810/Unique-Usman/r_atoi-v1\nPull-Request: https://github.com/git/git/pull/1810\n-- \ngitgitgadget\n"},{"id":"504931","messageId":"bfff7937cd20737bb5a8791dc7492700b1d7881f.1728774574.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.git.git.1728774574.gitgitgadget@gmail.com","subject":"[PATCH 1/3] t3404: avoid losing exit status with focus on `git show` and `git cat-file`","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-12T23:09:32Z","receivedAt":"2024-10-12T23:09:38Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nThe exit code of the preceding command in a pipe is disregarded. So\nif that preceding command is a Git command that fails, the test would\nnot fail. Instead, by saving the output of that Git command to a file,\nand removing the pipe, we make sure the test will fail if that Git\ncommand fails. This particular patch focuses on all `git show` and\nsome instances of `git cat-file`.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n t/t3404-rebase-interactive.sh | 71 +++++++++++++++++++++++------------\n 1 file changed, 48 insertions(+), 23 deletions(-)\n\ndiff --git a/t/t3404-rebase-interactive.sh b/t/t3404-rebase-interactive.sh\nindex f171af3061d..96a65783c47 100755\n--- a/t/t3404-rebase-interactive.sh\n+++ b/t/t3404-rebase-interactive.sh\n@@ -319,7 +319,8 @@ test_expect_success 'retain authorship' '\n \tGIT_AUTHOR_NAME=\"Twerp Snog\" git commit -m \"different author\" &&\n \tgit tag twerp &&\n \tgit rebase -i --onto primary HEAD^ &&\n-\tgit show HEAD | grep \"^Author: Twerp Snog\"\n+\tgit show HEAD >actual &&\n+\tgrep \"^Author: Twerp Snog\" actual\n '\n \n test_expect_success 'retain authorship w/ conflicts' '\n@@ -360,7 +361,8 @@ test_expect_success 'squash' '\n '\n \n test_expect_success 'retain authorship when squashing' '\n-\tgit show HEAD | grep \"^Author: Twerp Snog\"\n+\tgit show HEAD >actual &&\n+\tgrep \"^Author: Twerp Snog\" actual\n '\n \n test_expect_success '--continue tries to commit' '\n@@ -374,7 +376,8 @@ test_expect_success '--continue tries to commit' '\n \t\tFAKE_COMMIT_MESSAGE=\"chouette!\" git rebase --continue\n \t) &&\n \ttest_cmp_rev HEAD^ new-branch1 &&\n-\tgit show HEAD | grep chouette\n+\tgit show HEAD >actual &&\n+\tgrep chouette actual\n '\n \n test_expect_success 'verbose flag is heeded, even after --continue' '\n@@ -397,7 +400,9 @@ test_expect_success 'multi-squash only fires up editor once' '\n \t\t\tgit rebase -i $base\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n-\ttest 1 = $(git show | grep ONCE | wc -l)\n+\tgit show >output &&\n+\tcount=$(grep ONCE output | wc -l) &&\n+\ttest 1 = $count\n '\n \n test_expect_success 'multi-fixup does not fire up editor' '\n@@ -410,7 +415,9 @@ test_expect_success 'multi-fixup does not fire up editor' '\n \t\t\tgit rebase -i $base\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n-\ttest 0 = $(git show | grep NEVER | wc -l) &&\n+\tgit show >output &&\n+\tcount=$(grep NEVER output | wc -l) &&\n+\ttest 0 = $count &&\n \tgit checkout @{-1} &&\n \tgit branch -D multi-fixup\n '\n@@ -428,7 +435,9 @@ test_expect_success 'commit message used after conflict' '\n \t\t\tgit rebase --continue\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n-\ttest 1 = $(git show | grep ONCE | wc -l) &&\n+\tgit show >output &&\n+\tcount=$(grep ONCE output | wc -l) &&\n+\ttest 1 = $count &&\n \tgit checkout @{-1} &&\n \tgit branch -D conflict-fixup\n '\n@@ -446,7 +455,9 @@ test_expect_success 'commit message retained after conflict' '\n \t\t\tgit rebase --continue\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n-\ttest 2 = $(git show | grep TWICE | wc -l) &&\n+\tgit show >output &&\n+\tcount=$(grep TWICE output | wc -l) &&\n+\ttest 2 = $count &&\n \tgit checkout @{-1} &&\n \tgit branch -D conflict-squash\n '\n@@ -470,10 +481,10 @@ test_expect_success 'squash and fixup generate correct log messages' '\n \t) &&\n \tgit cat-file commit HEAD | sed -e 1,/^\\$/d > actual-squash-fixup &&\n \ttest_cmp expect-squash-fixup actual-squash-fixup &&\n-\tgit cat-file commit HEAD@{2} |\n-\t\tgrep \"^# This is a combination of 3 commits\\.\"  &&\n-\tgit cat-file commit HEAD@{3} |\n-\t\tgrep \"^# This is a combination of 2 commits\\.\"  &&\n+\tgit cat-file commit HEAD@{2} >actual &&\n+\tgrep \"^# This is a combination of 3 commits\\.\" actual &&\n+\tgit cat-file commit HEAD@{3} >actual &&\n+\tgrep \"^# This is a combination of 2 commits\\.\" actual  &&\n \tgit checkout @{-1} &&\n \tgit branch -D squash-fixup\n '\n@@ -489,7 +500,9 @@ test_expect_success 'squash ignores comments' '\n \t\t\tgit rebase -i $base\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n-\ttest 1 = $(git show | grep ONCE | wc -l) &&\n+\tgit show >output &&\n+\tcount=$(grep ONCE output | wc -l) &&\n+\ttest 1 = $count &&\n \tgit checkout @{-1} &&\n \tgit branch -D skip-comments\n '\n@@ -505,7 +518,9 @@ test_expect_success 'squash ignores blank lines' '\n \t\t\tgit rebase -i $base\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n-\ttest 1 = $(git show | grep ONCE | wc -l) &&\n+\tgit show >output &&\n+\tcount=$(grep ONCE output | wc -l) &&\n+\ttest 1 = $count &&\n \tgit checkout @{-1} &&\n \tgit branch -D skip-blank-lines\n '\n@@ -572,7 +587,8 @@ test_expect_success '--continue tries to commit, even for \"edit\"' '\n \t\tFAKE_COMMIT_MESSAGE=\"chouette!\" git rebase --continue\n \t) &&\n \ttest edited = $(git show HEAD:file7) &&\n-\tgit show HEAD | grep chouette &&\n+\tgit show HEAD >actual &&\n+\tgrep chouette actual &&\n \ttest $parent = $(git rev-parse HEAD^)\n '\n \n@@ -757,19 +773,23 @@ test_expect_success 'reword' '\n \t\tset_fake_editor &&\n \t\tFAKE_LINES=\"1 2 3 reword 4\" FAKE_COMMIT_MESSAGE=\"E changed\" \\\n \t\t\tgit rebase -i A &&\n-\t\tgit show HEAD | grep \"E changed\" &&\n+\t\tgit show HEAD >actual &&\n+\t\tgrep \"E changed\" actual &&\n \t\ttest $(git rev-parse primary) != $(git rev-parse HEAD) &&\n \t\ttest_cmp_rev primary^ HEAD^ &&\n \t\tFAKE_LINES=\"1 2 reword 3 4\" FAKE_COMMIT_MESSAGE=\"D changed\" \\\n \t\t\tgit rebase -i A &&\n-\t\tgit show HEAD^ | grep \"D changed\" &&\n+\t\tgit show HEAD^ >actual &&\n+\t\tgrep \"D changed\" actual &&\n \t\tFAKE_LINES=\"reword 1 2 3 4\" FAKE_COMMIT_MESSAGE=\"B changed\" \\\n \t\t\tgit rebase -i A &&\n-\t\tgit show HEAD~3 | grep \"B changed\" &&\n+\t\tgit show HEAD~3 >actual &&\n+\t\tgrep \"B changed\" actual &&\n \t\tFAKE_LINES=\"1 r 2 pick 3 p 4\" FAKE_COMMIT_MESSAGE=\"C changed\" \\\n \t\t\tgit rebase -i A\n \t) &&\n-\tgit show HEAD~2 | grep \"C changed\"\n+\tgit show HEAD~2 >actual &&\n+\tgrep \"C changed\" actual\n '\n \n test_expect_success 'no uncommitted changes when rewording and the todo list is reloaded' '\n@@ -1003,8 +1023,10 @@ test_expect_success 'rebase -i --root retain root commit author and message' '\n \t\tset_fake_editor &&\n \t\tFAKE_LINES=\"2\" git rebase -i --root\n \t) &&\n-\tgit cat-file commit HEAD | grep -q \"^author Twerp Snog\" &&\n-\tgit cat-file commit HEAD | grep -q \"^different author$\"\n+\tgit cat-file commit HEAD >output &&\n+\tgrep -q \"^author Twerp Snog\" output &&\n+\tgit cat-file commit HEAD >actual &&\n+\tgrep -q \"^different author$\" actual\n '\n \n test_expect_success 'rebase -i --root temporary sentinel commit' '\n@@ -1013,7 +1035,8 @@ test_expect_success 'rebase -i --root temporary sentinel commit' '\n \t\tset_fake_editor &&\n \t\ttest_must_fail env FAKE_LINES=\"2\" git rebase -i --root\n \t) &&\n-\tgit cat-file commit HEAD | grep \"^tree $EMPTY_TREE\" &&\n+\tgit cat-file commit HEAD >actual &&\n+\tgrep \"^tree $EMPTY_TREE\" actual &&\n \tgit rebase --abort\n '\n \n@@ -1036,7 +1059,8 @@ test_expect_success 'rebase -i --root reword original root commit' '\n \t\tFAKE_LINES=\"reword 1 2\" FAKE_COMMIT_MESSAGE=\"A changed\" \\\n \t\t\tgit rebase -i --root\n \t) &&\n-\tgit show HEAD^ | grep \"A changed\" &&\n+\tgit show HEAD^ >actual &&\n+\tgrep \"A changed\" actual &&\n \ttest -z \"$(git show -s --format=%p HEAD^)\"\n '\n \n@@ -1048,7 +1072,8 @@ test_expect_success 'rebase -i --root reword new root commit' '\n \t\tFAKE_LINES=\"reword 3 1\" FAKE_COMMIT_MESSAGE=\"C changed\" \\\n \t\tgit rebase -i --root\n \t) &&\n-\tgit show HEAD^ | grep \"C changed\" &&\n+\tgit show HEAD^ >actual &&\n+\tgrep \"C changed\" actual &&\n \ttest -z \"$(git show -s --format=%p HEAD^)\"\n '\n \n-- \ngitgitgadget\n\n"},{"id":"504932","messageId":"e2cae7f3a510027864303fe91dcf447f63eb0873.1728774574.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.git.git.1728774574.gitgitgadget@gmail.com","subject":"[PATCH 2/3] t3404: replace test with test_line_count()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-12T23:09:33Z","receivedAt":"2024-10-12T23:09:39Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nRefactor t3404 to replace instances of `test` with `test_line_count()`\nfor checking line counts. This improves readability and aligns with Git's\ncurrent test practices.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n t/t3404-rebase-interactive.sh | 28 ++++++++++++++--------------\n 1 file changed, 14 insertions(+), 14 deletions(-)\n\ndiff --git a/t/t3404-rebase-interactive.sh b/t/t3404-rebase-interactive.sh\nindex 96a65783c47..2ab660ef30f 100755\n--- a/t/t3404-rebase-interactive.sh\n+++ b/t/t3404-rebase-interactive.sh\n@@ -281,8 +281,9 @@ test_expect_success 'stop on conflicting pick' '\n \ttest_cmp expect2 file1 &&\n \ttest \"$(git diff --name-status |\n \t\tsed -n -e \"/^U/s/^U[^a-z]*//p\")\" = file1 &&\n-\ttest 4 = $(grep -v \"^#\" < .git/rebase-merge/done | wc -l) &&\n-\ttest 0 = $(grep -c \"^[^#]\" < .git/rebase-merge/git-rebase-todo)\n+\tgrep -v \"^#\" <.git/rebase-merge/done >actual &&\n+\ttest_line_count = 4 actual &&\n+\ttest 0 = $(grep -c \"^[^#]\" <.git/rebase-merge/git-rebase-todo)\n '\n \n test_expect_success 'show conflicted patch' '\n@@ -401,8 +402,8 @@ test_expect_success 'multi-squash only fires up editor once' '\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n \tgit show >output &&\n-\tcount=$(grep ONCE output | wc -l) &&\n-\ttest 1 = $count\n+\tgrep ONCE output >actual &&\n+\ttest_line_count = 1 actual\n '\n \n test_expect_success 'multi-fixup does not fire up editor' '\n@@ -416,8 +417,7 @@ test_expect_success 'multi-fixup does not fire up editor' '\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n \tgit show >output &&\n-\tcount=$(grep NEVER output | wc -l) &&\n-\ttest 0 = $count &&\n+\t! grep NEVER output &&\n \tgit checkout @{-1} &&\n \tgit branch -D multi-fixup\n '\n@@ -436,8 +436,8 @@ test_expect_success 'commit message used after conflict' '\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n \tgit show >output &&\n-\tcount=$(grep ONCE output | wc -l) &&\n-\ttest 1 = $count &&\n+\tgrep ONCE output >actual &&\n+\ttest_line_count = 1 actual &&\n \tgit checkout @{-1} &&\n \tgit branch -D conflict-fixup\n '\n@@ -456,8 +456,8 @@ test_expect_success 'commit message retained after conflict' '\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n \tgit show >output &&\n-\tcount=$(grep TWICE output | wc -l) &&\n-\ttest 2 = $count &&\n+\tgrep TWICE output >actual &&\n+\ttest_line_count = 2 actual &&\n \tgit checkout @{-1} &&\n \tgit branch -D conflict-squash\n '\n@@ -501,8 +501,8 @@ test_expect_success 'squash ignores comments' '\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n \tgit show >output &&\n-\tcount=$(grep ONCE output | wc -l) &&\n-\ttest 1 = $count &&\n+\tgrep ONCE output >actual &&\n+\ttest_line_count = 1 actual &&\n \tgit checkout @{-1} &&\n \tgit branch -D skip-comments\n '\n@@ -519,8 +519,8 @@ test_expect_success 'squash ignores blank lines' '\n \t) &&\n \ttest $base = $(git rev-parse HEAD^) &&\n \tgit show >output &&\n-\tcount=$(grep ONCE output | wc -l) &&\n-\ttest 1 = $count &&\n+\tgrep ONCE output >actual &&\n+\ttest_line_count = 1 actual &&\n \tgit checkout @{-1} &&\n \tgit branch -D skip-blank-lines\n '\n-- \ngitgitgadget\n\n"},{"id":"504933","messageId":"c93bc2d81ffb33a2a61dda2878fa3b9987545e0b.1728774574.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.git.git.1728774574.gitgitgadget@gmail.com","subject":"[PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-12T23:09:34Z","receivedAt":"2024-10-12T23:09:40Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace unsafe uses of atoi() with strtoul_ui() for unsigned integers\nand strtol_i() for signed integers across multiple files. This change\nimproves error handling and prevents potential integer overflow issues.\n\nThe following files were updated:\n- daemon.c: Update parsing of --timeout, --init-timeout, and\n  --max-connections\n- imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n  tags\n- merge-ll.c: Enhance parsing of marker size in ll_merge and\n  ll_merge_marker_size\n\nThis change allows for better error detection when parsing integer\nvalues from command-line arguments and IMAP responses, making the code\nmore robust and secure.\n\nThis is a #leftoverbit discussed here:\n https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nCc: gitster@pobox.com\nCc: Patrick Steinhardt <ps@pks.im>\nCc: phillip.wood123@gmail.com\nCc: Christian Couder <christian.couder@gmail.com>\nCc: Eric Sunshine <sunshine@sunshineco.com>\nCc: Taylor Blau <me@ttaylorr.com>\n---\n daemon.c    | 14 +++++++++-----\n imap-send.c | 13 ++++++++-----\n merge-ll.c  |  6 ++----\n 3 files changed, 19 insertions(+), 14 deletions(-)\n\ndiff --git a/daemon.c b/daemon.c\nindex cb946e3c95f..3fdb6e83c40 100644\n--- a/daemon.c\n+++ b/daemon.c\n@@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n-\t\t\ttimeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &timeout) < 0) {\n+\t\t\t\tdie(\"'%s': not a valid integer for --timeout\", v);\n+\t\t\t}\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n-\t\t\tinit_timeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &init_timeout) < 0) {\n+\t\t\t\tdie(\"'%s': not a valid integer for --init-timeout\", v);\n+\t\t\t}\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n-\t\t\tmax_connections = atoi(v);\n-\t\t\tif (max_connections < 0)\n-\t\t\t\tmax_connections = 0;\t        /* unlimited */\n+\t\t\tif (strtol_i(v, 10, &max_connections) != 0 || max_connections < 0) {\n+\t\t\t\tmax_connections = 0;  /* unlimited */\n+\t\t\t}\n \t\t\tcontinue;\n \t\t}\n \t\tif (!strcmp(arg, \"--strict-paths\")) {\ndiff --git a/imap-send.c b/imap-send.c\nindex ec68a066877..33b74dfded7 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\treturn RESP_BAD;\n \t}\n \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) != 0) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) != 0) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\tfor (; isspace((unsigned char)*p); p++);\n \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n-\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) != 0) ||\n+\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) != 0)) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n \t\t\tif (!tcmd)\n \t\t\t\treturn DRV_OK;\n \t\t} else {\n-\t\t\ttag = atoi(arg);\n+\t\t\tif (strtol_i(arg, 10, &tag) != 0) {\n+\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n+\t\t\t\treturn RESP_BAD;\n+\t\t\t}\n \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n \t\t\t\tif (cmdp->tag == tag)\n \t\t\t\t\tgoto gottag;\ndiff --git a/merge-ll.c b/merge-ll.c\nindex 8e63071922b..2bfee0f2c6b 100644\n--- a/merge-ll.c\n+++ b/merge-ll.c\n@@ -427,8 +427,7 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n \tgit_check_attr(istate, path, check);\n \tll_driver_name = check->items[0].value;\n \tif (check->items[1].value) {\n-\t\tmarker_size = atoi(check->items[1].value);\n-\t\tif (marker_size <= 0)\n+\t\tif (strtol_i(check->items[1].value, 10, &marker_size) != 0 || marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\n \tdriver = find_ll_merge_driver(ll_driver_name);\n@@ -454,8 +453,7 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n \tgit_check_attr(istate, path, check);\n \tif (check->items[0].value) {\n-\t\tmarker_size = atoi(check->items[0].value);\n-\t\tif (marker_size <= 0)\n+\t\tif (strtol_i(check->items[0].value, 10, &marker_size) != 0 || marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\n \treturn marker_size;\n-- \ngitgitgadget\n"},{"id":"504943","messageId":"CAPSxiM-V1qOB9QXUY3aDh+_nGdDHBWXJZ54U9p_XxKfHoODu7A@mail.gmail.com","threadId":"62325","inReplyTo":"c93bc2d81ffb33a2a61dda2878fa3b9987545e0b.1728774574.git.gitgitgadget@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-13T09:42:41Z","receivedAt":"2024-10-13T09:42:54Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n<gitgitgadget@gmail.com> wrote:\n>\n> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>\n> Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> and strtol_i() for signed integers across multiple files. This change\n> improves error handling and prevents potential integer overflow issues.\n>\n> The following files were updated:\n> - daemon.c: Update parsing of --timeout, --init-timeout, and\n>   --max-connections\n> - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n>   tags\n> - merge-ll.c: Enhance parsing of marker size in ll_merge and\n>   ll_merge_marker_size\n>\n> This change allows for better error detection when parsing integer\n> values from command-line arguments and IMAP responses, making the code\n> more robust and secure.\n>\n> This is a #leftoverbit discussed here:\n>  https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n>\n> Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>\n> Cc: gitster@pobox.com\n> Cc: Patrick Steinhardt <ps@pks.im>\n> Cc: phillip.wood123@gmail.com\n> Cc: Christian Couder <christian.couder@gmail.com>\n> Cc: Eric Sunshine <sunshine@sunshineco.com>\n> Cc: Taylor Blau <me@ttaylorr.com>\n> ---\n>  daemon.c    | 14 +++++++++-----\n>  imap-send.c | 13 ++++++++-----\n>  merge-ll.c  |  6 ++----\n>  3 files changed, 19 insertions(+), 14 deletions(-)\n>\n> diff --git a/daemon.c b/daemon.c\n> index cb946e3c95f..3fdb6e83c40 100644\n> --- a/daemon.c\n> +++ b/daemon.c\n> @@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n>                         continue;\n>                 }\n>                 if (skip_prefix(arg, \"--timeout=\", &v)) {\n> -                       timeout = atoi(v);\n> +                       if (strtoul_ui(v, 10, &timeout) < 0) {\n> +                               die(\"'%s': not a valid integer for --timeout\", v);\n> +                       }\n>                         continue;\n>                 }\n>                 if (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> -                       init_timeout = atoi(v);\n> +                       if (strtoul_ui(v, 10, &init_timeout) < 0) {\n> +                               die(\"'%s': not a valid integer for --init-timeout\", v);\n> +                       }\n>                         continue;\n>                 }\n>                 if (skip_prefix(arg, \"--max-connections=\", &v)) {\n> -                       max_connections = atoi(v);\n> -                       if (max_connections < 0)\n> -                               max_connections = 0;            /* unlimited */\n> +                       if (strtol_i(v, 10, &max_connections) != 0 || max_connections < 0) {\n> +                               max_connections = 0;  /* unlimited */\n> +                       }\n>                         continue;\n>                 }\n>                 if (!strcmp(arg, \"--strict-paths\")) {\n> diff --git a/imap-send.c b/imap-send.c\n> index ec68a066877..33b74dfded7 100644\n> --- a/imap-send.c\n> +++ b/imap-send.c\n> @@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n>                 return RESP_BAD;\n>         }\n>         if (!strcmp(\"UIDVALIDITY\", arg)) {\n> -               if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n> +               if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) != 0) {\n>                         fprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n>                         return RESP_BAD;\n>                 }\n>         } else if (!strcmp(\"UIDNEXT\", arg)) {\n> -               if (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n> +               if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) != 0) {\n>                         fprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n>                         return RESP_BAD;\n>                 }\n> @@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n>                 for (; isspace((unsigned char)*p); p++);\n>                 fprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n>         } else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n> -               if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n> -                   !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n> +               if (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) != 0) ||\n> +                       !(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) != 0)) {\n>                         fprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n>                         return RESP_BAD;\n>                 }\n> @@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n>                         if (!tcmd)\n>                                 return DRV_OK;\n>                 } else {\n> -                       tag = atoi(arg);\n> +                       if (strtol_i(arg, 10, &tag) != 0) {\n> +                               fprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n> +                               return RESP_BAD;\n> +                       }\n>                         for (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n>                                 if (cmdp->tag == tag)\n>                                         goto gottag;\n> diff --git a/merge-ll.c b/merge-ll.c\n> index 8e63071922b..2bfee0f2c6b 100644\n> --- a/merge-ll.c\n> +++ b/merge-ll.c\n> @@ -427,8 +427,7 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n>         git_check_attr(istate, path, check);\n>         ll_driver_name = check->items[0].value;\n>         if (check->items[1].value) {\n> -               marker_size = atoi(check->items[1].value);\n> -               if (marker_size <= 0)\n> +               if (strtol_i(check->items[1].value, 10, &marker_size) != 0 || marker_size <= 0)\n>                         marker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n>         }\n>         driver = find_ll_merge_driver(ll_driver_name);\n> @@ -454,8 +453,7 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n>                 check = attr_check_initl(\"conflict-marker-size\", NULL);\n>         git_check_attr(istate, path, check);\n>         if (check->items[0].value) {\n> -               marker_size = atoi(check->items[0].value);\n> -               if (marker_size <= 0)\n> +               if (strtol_i(check->items[0].value, 10, &marker_size) != 0 || marker_size <= 0)\n>                         marker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n>         }\n>         return marker_size;\n> --\n> gitgitgadget\n\nI also want to ask if this is the right way to send another patch as I\nnoticed that it is showing my previous patch which is not related to\nthis. Thank you.\n"},{"id":"504975","messageId":"14db295a-0049-434b-8747-09f82e511bb9@gmail.com","threadId":"62325","inReplyTo":"CAPSxiM-V1qOB9QXUY3aDh+_nGdDHBWXJZ54U9p_XxKfHoODu7A@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-14T09:00:10Z","receivedAt":"2024-10-14T09:00:17Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Usman\n\nOn 13/10/2024 10:42, Usman Akinyemi wrote:\n> On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n> \n> I also want to ask if this is the right way to send another patch as I\n> noticed that it is showing my previous patch which is not related to\n> this. Thank you.\n\nWhen you start working on a new patch series you should create a new \nbranch from origin/master with\n\n     git switch -c my-new-branch origin/master\n\nthat way your new work will be based on Junio's master branch rather \nthan your other patch series. You can use\n\n     git branch --set-upstream-to origin/master\n     git rebase HEAD^\n\nto drop the first two patches and set the correct upstream for your branch.\n\nBest Wishes\n\nPhillip\n\n"},{"id":"504977","messageId":"6875cb49-becc-4562-ace8-9f07848a345c@gmail.com","threadId":"62325","inReplyTo":"c93bc2d81ffb33a2a61dda2878fa3b9987545e0b.1728774574.git.gitgitgadget@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-14T09:49:20Z","receivedAt":"2024-10-14T09:49:27Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Usman\n\nOn 13/10/2024 00:09, Usman Akinyemi via GitGitGadget wrote:\n> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> \n> Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> and strtol_i() for signed integers across multiple files. This change\n> improves error handling and prevents potential integer overflow issues.\n\nThis paragraph is good as it explains why you are making this change\n\n> The following files were updated:\n> - daemon.c: Update parsing of --timeout, --init-timeout, and\n>    --max-connections\n> - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n>    tags\n> - merge-ll.c: Enhance parsing of marker size in ll_merge and\n>    ll_merge_marker_size\n\nThis information is not really needed in the commit message as it is \nshown in the diff.\n\n> This change allows for better error detection when parsing integer\n> values from command-line arguments and IMAP responses, making the code\n> more robust and secure.\n\nGreat\n\n> This is a #leftoverbit discussed here:\n>   https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> \n> Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> \n> Cc: gitster@pobox.com\n> Cc: Patrick Steinhardt <ps@pks.im>\n> Cc: phillip.wood123@gmail.com\n> Cc: Christian Couder <christian.couder@gmail.com>\n> Cc: Eric Sunshine <sunshine@sunshineco.com>\n> Cc: Taylor Blau <me@ttaylorr.com>\n\nWe do not tend to use Cc: footers on this list. Also note that as there \nis a blank line between the Signed-off-by: line and this paragraph the \nSigned-off-by: will be ignored by git-interpret-trailers.\n\n> ---\n>   daemon.c    | 14 +++++++++-----\n>   imap-send.c | 13 ++++++++-----\n>   merge-ll.c  |  6 ++----\n>   3 files changed, 19 insertions(+), 14 deletions(-)\n> \n> diff --git a/daemon.c b/daemon.c\n> index cb946e3c95f..3fdb6e83c40 100644\n> --- a/daemon.c\n> +++ b/daemon.c\n> @@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n>   \t\t\tcontinue;\n>   \t\t}\n>   \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n> -\t\t\ttimeout = atoi(v);\n> +\t\t\tif (strtoul_ui(v, 10, &timeout) < 0) {\n\nFor functions that return 0 or -1 to indicate success or error \nrespectively we use \"if (func(args))\" to check for errors.\n\n> +\t\t\t\tdie(\"'%s': not a valid integer for --timeout\", v);\n\n\"-1\" is a valid integer but it is not a valid timeout, maybe we could \nsay something like \"invalid timeout '%s', expecting a non-negative integer\".\n\n> +\t\t\t}\n>   \t\t\tcontinue;\n>   \t\t}\n>   \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> -\t\t\tinit_timeout = atoi(v);\n> +\t\t\tif (strtoul_ui(v, 10, &init_timeout) < 0) {\n> +\t\t\t\tdie(\"'%s': not a valid integer for --init-timeout\", v);\n\nThe comments for --timeout apply here as well\n\n> +\t\t\t}\n>   \t\t\tcontinue;\n>   \t\t}\n>   \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n> -\t\t\tmax_connections = atoi(v);\n> -\t\t\tif (max_connections < 0)\n> -\t\t\t\tmax_connections = 0;\t        /* unlimited */\n> +\t\t\tif (strtol_i(v, 10, &max_connections) != 0 || max_connections < 0) {\n\nThis is a faithful translation but if the aim of this series is to \ndetect errors then I think we want to do something like\n\n\tif (strtol_i(v, 10, &max_connections))\n\t\tdie(...)\n\tif (max_connections < 0)\n\t\tmax_connections = 0; /* unlimited */\n\n> +\t\t\t\tmax_connections = 0;  /* unlimited */\n> +\t\t\t}\n>   \t\t\tcontinue;\n>   \t\t}\n>   \t\tif (!strcmp(arg, \"--strict-paths\")) {\n> diff --git a/imap-send.c b/imap-send.c\n> index ec68a066877..33b74dfded7 100644\n> --- a/imap-send.c\n> +++ b/imap-send.c\n> @@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n>   \t\treturn RESP_BAD;\n>   \t}\n>   \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n> -\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n> +\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) != 0) {\n\nThe original is checking for a zero return from atoi() which indicates \nan error or that the parsed value was zero. To do that with strtol_i() \nwe need to do\n\n\t|| (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity)\n\nThe IMAP RFC[1] specifies that UIDVALIDITY should be a non-zero, \nnon-negative 32bit integer but I'm not sure we want to start change it's \ntype and using strtoul_ui here.\n\n[1] https://www.rfc-editor.org/rfc/rfc3501#section-2.3.1.1\n\n>   \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n>   \t\t\treturn RESP_BAD;\n>   \t\t}\n>   \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n> -\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n> +\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) != 0) {\n\nThe comments above apply here\n\n>   \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n>   \t\t\treturn RESP_BAD;\n>   \t\t}\n> @@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n>   \t\tfor (; isspace((unsigned char)*p); p++);\n>   \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n>   \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n> -\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n> -\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n> +\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) != 0) ||\n> +\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) != 0)) {\n\nAnd here\n\n>   \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n>   \t\t\treturn RESP_BAD;\n>   \t\t}\n> @@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n>   \t\t\tif (!tcmd)\n>   \t\t\t\treturn DRV_OK;\n>   \t\t} else {\n> -\t\t\ttag = atoi(arg);\n> +\t\t\tif (strtol_i(arg, 10, &tag) != 0) {\n\nTo check for an error just use (strtol_i(arg, 10, &tag))\n\n> +\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n> +\t\t\t\treturn RESP_BAD;\n\nThis matches the error below so I assume it's good.\n\n> +\t\t\t}\n>   \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n>   \t\t\t\tif (cmdp->tag == tag)\n>   \t\t\t\t\tgoto gottag;\n> diff --git a/merge-ll.c b/merge-ll.c\n> index 8e63071922b..2bfee0f2c6b 100644\n> --- a/merge-ll.c\n> +++ b/merge-ll.c\n> @@ -427,8 +427,7 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n>   \tgit_check_attr(istate, path, check);\n>   \tll_driver_name = check->items[0].value;\n>   \tif (check->items[1].value) {\n> -\t\tmarker_size = atoi(check->items[1].value);\n> -\t\tif (marker_size <= 0)\n> +\t\tif (strtol_i(check->items[1].value, 10, &marker_size) != 0 || marker_size <= 0)\n\nHere I think we want to return an error if we cannot parse the marker \nsize and then set the default if the marker size is <= 0 like we do for \nthe max_connections code in daemon.c above.\n\n>   \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n>   \t}\n>   \tdriver = find_ll_merge_driver(ll_driver_name);\n> @@ -454,8 +453,7 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n>   \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n>   \tgit_check_attr(istate, path, check);\n>   \tif (check->items[0].value) {\n> -\t\tmarker_size = atoi(check->items[0].value);\n> -\t\tif (marker_size <= 0)\n> +\t\tif (strtol_i(check->items[0].value, 10, &marker_size) != 0 || marker_size <= 0)\n\nAnd the same here\n\nThanks for working on this, it will be a useful improvement to our \ninteger parsing. I think you've got the basic idea, it just needs a bit \nof polish\n\nPhillip\n\n"},{"id":"504978","messageId":"63b3f6e1-d076-4522-9dee-79516200b8c3@app.fastmail.com","threadId":"62325","inReplyTo":"6875cb49-becc-4562-ace8-9f07848a345c@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Kristoffer Haugsbakk","fromEmail":"kristofferhaugsbakk@fastmail.com","sentAt":"2024-10-14T10:06:12Z","receivedAt":"2024-10-14T10:06:36Z","isPatch":true,"sender":{"key":"kristofferhaugsbakk@fastmail.com","avatar":null},"body":">> Cc: gitster@pobox.com\n>> Cc: Patrick Steinhardt <ps@pks.im>\n>> Cc: phillip.wood123@gmail.com\n>> Cc: Christian Couder <christian.couder@gmail.com>\n>> Cc: Eric Sunshine <sunshine@sunshineco.com>\n>> Cc: Taylor Blau <me@ttaylorr.com>\n>\n> We do not tend to use Cc: footers on this list. Also note that as there\n> is a blank line between the Signed-off-by: line and this paragraph the\n> Signed-off-by: will be ignored by git-interpret-trailers.\n\nI thought that gitgitgadget checked for missing sign-off.  I’ve seen\nthat message before at least.\n"},{"id":"504981","messageId":"Zwz4B4osJnYJw6pd@pks.im","threadId":"62325","inReplyTo":"CAPSxiM-V1qOB9QXUY3aDh+_nGdDHBWXJZ54U9p_XxKfHoODu7A@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-14T10:53:01Z","receivedAt":"2024-10-14T10:53:07Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Sun, Oct 13, 2024 at 09:42:41AM +0000, Usman Akinyemi wrote:\n> On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n> <gitgitgadget@gmail.com> wrote:\n> >\n> > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> > and strtol_i() for signed integers across multiple files. This change\n> > improves error handling and prevents potential integer overflow issues.\n> >\n> > The following files were updated:\n> > - daemon.c: Update parsing of --timeout, --init-timeout, and\n> >   --max-connections\n> > - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n> >   tags\n> > - merge-ll.c: Enhance parsing of marker size in ll_merge and\n> >   ll_merge_marker_size\n\nTo me it's always an indicator that something should be split up across\nmultiple commits once you have a bulleted list of changes in your commit\nmessage.\n\n> > This change allows for better error detection when parsing integer\n> > values from command-line arguments and IMAP responses, making the code\n> > more robust and secure.\n> >\n> > This is a #leftoverbit discussed here:\n> >  https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> >\n> > Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Cc: gitster@pobox.com\n> > Cc: Patrick Steinhardt <ps@pks.im>\n> > Cc: phillip.wood123@gmail.com\n> > Cc: Christian Couder <christian.couder@gmail.com>\n> > Cc: Eric Sunshine <sunshine@sunshineco.com>\n> > Cc: Taylor Blau <me@ttaylorr.com>\n\nThe Cc annotations shouldn't be part of the commit message. If you want\nto Cc specific folks you should rather do it e.g. on the command line or\nwhatever you use to send out the patches. Otherwise, these will all end\nup in our history.\n\n> > ---\n> >  daemon.c    | 14 +++++++++-----\n> >  imap-send.c | 13 ++++++++-----\n> >  merge-ll.c  |  6 ++----\n> >  3 files changed, 19 insertions(+), 14 deletions(-)\n> >\n> > diff --git a/daemon.c b/daemon.c\n> > index cb946e3c95f..3fdb6e83c40 100644\n> > --- a/daemon.c\n> > +++ b/daemon.c\n> > @@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n> >                         continue;\n> >                 }\n> >                 if (skip_prefix(arg, \"--timeout=\", &v)) {\n> > -                       timeout = atoi(v);\n> > +                       if (strtoul_ui(v, 10, &timeout) < 0) {\n> > +                               die(\"'%s': not a valid integer for --timeout\", v);\n> > +                       }\n> >                         continue;\n> >                 }\n\nWe don't use braces around single-line statements. It would also help to\nexplain whether this is fixing a bug and, if it does, then it would be\nnice to have a testcase that demonstrates the behaviour. The same is\ntrue for the other sites that you convert.\n\n[snip]\n> I also want to ask if this is the right way to send another patch as I\n> noticed that it is showing my previous patch which is not related to\n> this. Thank you.\n\nYou shouldn't ever include patches from another patch series. I guess\ntha problem here is that you created all of your work on the same\nbranch. I'd recommend to use separate feature branches for every series\nyou are working on. In general, these branches should start from the\ncurrent \"main\" branch.\n\nPatrick\n"},{"id":"505019","messageId":"4d178731-b530-4806-84da-abda50b2ecd4@gmail.com","threadId":"62325","inReplyTo":"63b3f6e1-d076-4522-9dee-79516200b8c3@app.fastmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-14T13:48:18Z","receivedAt":"2024-10-14T13:48:27Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Kristoffer\n\nOn 14/10/2024 11:06, Kristoffer Haugsbakk wrote:\n>>> Cc: gitster@pobox.com\n>>> Cc: Patrick Steinhardt <ps@pks.im>\n>>> Cc: phillip.wood123@gmail.com\n>>> Cc: Christian Couder <christian.couder@gmail.com>\n>>> Cc: Eric Sunshine <sunshine@sunshineco.com>\n>>> Cc: Taylor Blau <me@ttaylorr.com>\n>>\n>> We do not tend to use Cc: footers on this list. Also note that as there\n>> is a blank line between the Signed-off-by: line and this paragraph the\n>> Signed-off-by: will be ignored by git-interpret-trailers.\n> \n> I thought that gitgitgadget checked for missing sign-off.  I’ve seen\n> that message before at least.\n\nI'm not sure what the DCO check does as I can't figure out what code its \nrunning, but it looks like the commit lint just uses a regex on the \nwhole commit message[1]. I think the check could be tightened up to \nensure there is a Signed-off-by line that matches the commit author as I \nseem to recall we've sometimes seen SOB lines with another identity instead.\n\nBest Wishes\n\nPhillip\n\n[1] \nhttps://github.com/gitgitgadget/gitgitgadget/blob/7726b025bfaa18b72c889ae01f053d77d34f199d/lib/commit-lint.ts#L142\n\n"},{"id":"505020","messageId":"2a937b6f-a3fb-4f2a-997b-5508f0e20e65@gmail.com","threadId":"62325","inReplyTo":"Zwz4B4osJnYJw6pd@pks.im","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-14T13:57:13Z","receivedAt":"2024-10-14T13:57:21Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"On 14/10/2024 11:53, Patrick Steinhardt wrote:\n> On Sun, Oct 13, 2024 at 09:42:41AM +0000, Usman Akinyemi wrote:\n>> On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n>> <gitgitgadget@gmail.com> wrote:\n>>>\n>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>>>\n>>> Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n>>> and strtol_i() for signed integers across multiple files. This change\n>>> improves error handling and prevents potential integer overflow issues.\n>>>\n>>> The following files were updated:\n>>> - daemon.c: Update parsing of --timeout, --init-timeout, and\n>>>    --max-connections\n>>> - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n>>>    tags\n>>> - merge-ll.c: Enhance parsing of marker size in ll_merge and\n>>>    ll_merge_marker_size\n> \n> To me it's always an indicator that something should be split up across\n> multiple commits once you have a bulleted list of changes in your commit\n> message.\n\nAgreed, but I think in this case there is a common theme (converting \natoi() to a safer alternative) and the problem is with the commit \nmessage listing which files have changed rather than unrelated code \nchanges being grouped together. This patch could be split up and if \nthere were many more atoi() conversions it would need to be split to \nprevent it being too long but I don't think its essential to do so.\n\nBest Wishes\n\nPhillip\n\n>>> This change allows for better error detection when parsing integer\n>>> values from command-line arguments and IMAP responses, making the code\n>>> more robust and secure.\n>>>\n>>> This is a #leftoverbit discussed here:\n>>>   https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n>>>\n>>> Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>>>\n>>> Cc: gitster@pobox.com\n>>> Cc: Patrick Steinhardt <ps@pks.im>\n>>> Cc: phillip.wood123@gmail.com\n>>> Cc: Christian Couder <christian.couder@gmail.com>\n>>> Cc: Eric Sunshine <sunshine@sunshineco.com>\n>>> Cc: Taylor Blau <me@ttaylorr.com>\n> \n> The Cc annotations shouldn't be part of the commit message. If you want\n> to Cc specific folks you should rather do it e.g. on the command line or\n> whatever you use to send out the patches. Otherwise, these will all end\n> up in our history.\n> \n>>> ---\n>>>   daemon.c    | 14 +++++++++-----\n>>>   imap-send.c | 13 ++++++++-----\n>>>   merge-ll.c  |  6 ++----\n>>>   3 files changed, 19 insertions(+), 14 deletions(-)\n>>>\n>>> diff --git a/daemon.c b/daemon.c\n>>> index cb946e3c95f..3fdb6e83c40 100644\n>>> --- a/daemon.c\n>>> +++ b/daemon.c\n>>> @@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n>>>                          continue;\n>>>                  }\n>>>                  if (skip_prefix(arg, \"--timeout=\", &v)) {\n>>> -                       timeout = atoi(v);\n>>> +                       if (strtoul_ui(v, 10, &timeout) < 0) {\n>>> +                               die(\"'%s': not a valid integer for --timeout\", v);\n>>> +                       }\n>>>                          continue;\n>>>                  }\n> \n> We don't use braces around single-line statements. It would also help to\n> explain whether this is fixing a bug and, if it does, then it would be\n> nice to have a testcase that demonstrates the behaviour. The same is\n> true for the other sites that you convert.\n> \n> [snip]\n>> I also want to ask if this is the right way to send another patch as I\n>> noticed that it is showing my previous patch which is not related to\n>> this. Thank you.\n> \n> You shouldn't ever include patches from another patch series. I guess\n> tha problem here is that you created all of your work on the same\n> branch. I'd recommend to use separate feature branches for every series\n> you are working on. In general, these branches should start from the\n> current \"main\" branch.\n> \n> Patrick\n> \n\n"},{"id":"505023","messageId":"Zw0kGLZ-mcYjb6Je@pks.im","threadId":"62325","inReplyTo":"2a937b6f-a3fb-4f2a-997b-5508f0e20e65@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-14T14:00:56Z","receivedAt":"2024-10-14T14:01:06Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Mon, Oct 14, 2024 at 02:57:13PM +0100, Phillip Wood wrote:\n> On 14/10/2024 11:53, Patrick Steinhardt wrote:\n> > On Sun, Oct 13, 2024 at 09:42:41AM +0000, Usman Akinyemi wrote:\n> > > On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n> > > <gitgitgadget@gmail.com> wrote:\n> > > > \n> > > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > > > \n> > > > Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> > > > and strtol_i() for signed integers across multiple files. This change\n> > > > improves error handling and prevents potential integer overflow issues.\n> > > > \n> > > > The following files were updated:\n> > > > - daemon.c: Update parsing of --timeout, --init-timeout, and\n> > > >    --max-connections\n> > > > - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n> > > >    tags\n> > > > - merge-ll.c: Enhance parsing of marker size in ll_merge and\n> > > >    ll_merge_marker_size\n> > \n> > To me it's always an indicator that something should be split up across\n> > multiple commits once you have a bulleted list of changes in your commit\n> > message.\n> \n> Agreed, but I think in this case there is a common theme (converting atoi()\n> to a safer alternative) and the problem is with the commit message listing\n> which files have changed rather than unrelated code changes being grouped\n> together. This patch could be split up and if there were many more atoi()\n> conversions it would need to be split to prevent it being too long but I\n> don't think its essential to do so.\n\nIn theory I agree. In practice I think we should have better\nexplanations why the respective conversions are fine and whether this is\nfixing a bug or not. And if it is fixing bugs I'd also like to see tests\nadded to the tree.\n\nAnd by the time we got there it makes sense to split up commits.\n\nPatrick\n"},{"id":"505028","messageId":"2160f8ea-5f00-49d9-8e02-d71d4d827d39@gmail.com","threadId":"62325","inReplyTo":"Zw0kGLZ-mcYjb6Je@pks.im","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-14T14:55:18Z","receivedAt":"2024-10-14T14:55:26Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"On 14/10/2024 15:00, Patrick Steinhardt wrote:\n> On Mon, Oct 14, 2024 at 02:57:13PM +0100, Phillip Wood wrote:\n>> On 14/10/2024 11:53, Patrick Steinhardt wrote:\n>>> On Sun, Oct 13, 2024 at 09:42:41AM +0000, Usman Akinyemi wrote:\n>>>> On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n>>>> <gitgitgadget@gmail.com> wrote:\n>>>>>\n>>>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>>>>>\n>>>>> Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n>>>>> and strtol_i() for signed integers across multiple files. This change\n>>>>> improves error handling and prevents potential integer overflow issues.\n>>>>>\n>>>>> The following files were updated:\n>>>>> - daemon.c: Update parsing of --timeout, --init-timeout, and\n>>>>>     --max-connections\n>>>>> - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n>>>>>     tags\n>>>>> - merge-ll.c: Enhance parsing of marker size in ll_merge and\n>>>>>     ll_merge_marker_size\n>>>\n>>> To me it's always an indicator that something should be split up across\n>>> multiple commits once you have a bulleted list of changes in your commit\n>>> message.\n>>\n>> Agreed, but I think in this case there is a common theme (converting atoi()\n>> to a safer alternative) and the problem is with the commit message listing\n>> which files have changed rather than unrelated code changes being grouped\n>> together. This patch could be split up and if there were many more atoi()\n>> conversions it would need to be split to prevent it being too long but I\n>> don't think its essential to do so.\n> \n> In theory I agree. In practice I think we should have better\n> explanations why the respective conversions are fine and whether this is\n> fixing a bug or not. And if it is fixing bugs I'd also like to see tests\n> added to the tree.\n\nI'm not sure if I would describe any of the changes as fixing bugs. The \noption and config parsing code becomes stricter so I guess you could say \nit was a bug to accept any old rubbish and treat it as zero before. The \nimap code that's changed all rejected zero anyway apart from the tag \nparsing so maybe accepting the changes to the tag parsing are fixing a bug.\n\n> And by the time we got there it makes sense to split up commits.\n\nYes if we start adding tests then it is worth splitting them up, I'm not \nsure we have anyway of testing the imap changes but it would be worth \ntesting the other changes though.\n\nPhillip\n\n> Patrick\n> \n\n"},{"id":"505034","messageId":"CAPSxiM-i3EmmXM6BuPb80q51Lmud0PfnZ_WQfSJfvq1nYynnLQ@mail.gmail.com","threadId":"62325","inReplyTo":"14db295a-0049-434b-8747-09f82e511bb9@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-14T15:56:30Z","receivedAt":"2024-10-14T15:56:42Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 9:00 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> Hi Usman\n>\n> On 13/10/2024 10:42, Usman Akinyemi wrote:\n> > On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n> >\n> > I also want to ask if this is the right way to send another patch as I\n> > noticed that it is showing my previous patch which is not related to\n> > this. Thank you.\n>\n> When you start working on a new patch series you should create a new\n> branch from origin/master with\n>\n>      git switch -c my-new-branch origin/master\n>\n> that way your new work will be based on Junio's master branch rather\n> than your other patch series. You can use\n>\n>      git branch --set-upstream-to origin/master\n>      git rebase HEAD^\n>\n> to drop the first two patches and set the correct upstream for your branch.\n>\n> Best Wishes\n>\n> Phillip\n>\nThanks Philip, I actually created another branch but I was really\nconfused if to base the new branch on master or the branch which has\nthe previous commits. Thanks for clarifying this.\n"},{"id":"505035","messageId":"CAPSxiM9t63E3OJm6SrLEOf_0bcLX_Eo9uS+u6TqeovVUrb-2rA@mail.gmail.com","threadId":"62325","inReplyTo":"Zwz4B4osJnYJw6pd@pks.im","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-14T16:03:59Z","receivedAt":"2024-10-14T16:04:11Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 10:53 AM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Sun, Oct 13, 2024 at 09:42:41AM +0000, Usman Akinyemi wrote:\n> > On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n> > <gitgitgadget@gmail.com> wrote:\n> > >\n> > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > >\n> > > Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> > > and strtol_i() for signed integers across multiple files. This change\n> > > improves error handling and prevents potential integer overflow issues.\n> > >\n> > > The following files were updated:\n> > > - daemon.c: Update parsing of --timeout, --init-timeout, and\n> > >   --max-connections\n> > > - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n> > >   tags\n> > > - merge-ll.c: Enhance parsing of marker size in ll_merge and\n> > >   ll_merge_marker_size\n>\n> To me it's always an indicator that something should be split up across\n> multiple commits once you have a bulleted list of changes in your commit\n> message.\n>\n> > > This change allows for better error detection when parsing integer\n> > > values from command-line arguments and IMAP responses, making the code\n> > > more robust and secure.\n> > >\n> > > This is a #leftoverbit discussed here:\n> > >  https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> > >\n> > > Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > >\n> > > Cc: gitster@pobox.com\n> > > Cc: Patrick Steinhardt <ps@pks.im>\n> > > Cc: phillip.wood123@gmail.com\n> > > Cc: Christian Couder <christian.couder@gmail.com>\n> > > Cc: Eric Sunshine <sunshine@sunshineco.com>\n> > > Cc: Taylor Blau <me@ttaylorr.com>\n>\n> The Cc annotations shouldn't be part of the commit message. If you want\n> to Cc specific folks you should rather do it e.g. on the command line or\n> whatever you use to send out the patches. Otherwise, these will all end\n> up in our history.\nThanks for this, I thought the gitgitgadget automatically use the Cc\nfrom the commit message.\n>\n> > > ---\n> > >  daemon.c    | 14 +++++++++-----\n> > >  imap-send.c | 13 ++++++++-----\n> > >  merge-ll.c  |  6 ++----\n> > >  3 files changed, 19 insertions(+), 14 deletions(-)\n> > >\n> > > diff --git a/daemon.c b/daemon.c\n> > > index cb946e3c95f..3fdb6e83c40 100644\n> > > --- a/daemon.c\n> > > +++ b/daemon.c\n> > > @@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n> > >                         continue;\n> > >                 }\n> > >                 if (skip_prefix(arg, \"--timeout=\", &v)) {\n> > > -                       timeout = atoi(v);\n> > > +                       if (strtoul_ui(v, 10, &timeout) < 0) {\n> > > +                               die(\"'%s': not a valid integer for --timeout\", v);\n> > > +                       }\n> > >                         continue;\n> > >                 }\n>\n> We don't use braces around single-line statements. It would also help to\n> explain whether this is fixing a bug and, if it does, then it would be\n> nice to have a testcase that demonstrates the behaviour. The same is\n> true for the other sites that you convert.\n>\nI was going to add testcase, I sent this patch to ensure I am going in\nthe right direction.\n> [snip]\n> > I also want to ask if this is the right way to send another patch as I\n> > noticed that it is showing my previous patch which is not related to\n> > this. Thank you.\n>\n> You shouldn't ever include patches from another patch series. I guess\n> tha problem here is that you created all of your work on the same\n> branch. I'd recommend to use separate feature branches for every series\n> you are working on. In general, these branches should start from the\n> current \"main\" branch.\n>\n> Patrick\nThanks Patrick. I actually created a new branch for this branch, my\nmistake was not basing it on the master branch. I was a little bit\nconfused. But, now I understand better. Thanks.\n"},{"id":"505036","messageId":"CAPSxiM9ncwaZ3HF72wsRwmen7joWk3mjipsu78WxKEzLX607sw@mail.gmail.com","threadId":"62325","inReplyTo":"2160f8ea-5f00-49d9-8e02-d71d4d827d39@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-14T16:13:06Z","receivedAt":"2024-10-14T16:13:18Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> On 14/10/2024 15:00, Patrick Steinhardt wrote:\n> > On Mon, Oct 14, 2024 at 02:57:13PM +0100, Phillip Wood wrote:\n> >> On 14/10/2024 11:53, Patrick Steinhardt wrote:\n> >>> On Sun, Oct 13, 2024 at 09:42:41AM +0000, Usman Akinyemi wrote:\n> >>>> On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n> >>>> <gitgitgadget@gmail.com> wrote:\n> >>>>>\n> >>>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >>>>>\n> >>>>> Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> >>>>> and strtol_i() for signed integers across multiple files. This change\n> >>>>> improves error handling and prevents potential integer overflow issues.\n> >>>>>\n> >>>>> The following files were updated:\n> >>>>> - daemon.c: Update parsing of --timeout, --init-timeout, and\n> >>>>>     --max-connections\n> >>>>> - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n> >>>>>     tags\n> >>>>> - merge-ll.c: Enhance parsing of marker size in ll_merge and\n> >>>>>     ll_merge_marker_size\n> >>>\n> >>> To me it's always an indicator that something should be split up across\n> >>> multiple commits once you have a bulleted list of changes in your commit\n> >>> message.\n> >>\n> >> Agreed, but I think in this case there is a common theme (converting atoi()\n> >> to a safer alternative) and the problem is with the commit message listing\n> >> which files have changed rather than unrelated code changes being grouped\n> >> together. This patch could be split up and if there were many more atoi()\n> >> conversions it would need to be split to prevent it being too long but I\n> >> don't think its essential to do so.\n> >\n> > In theory I agree. In practice I think we should have better\n> > explanations why the respective conversions are fine and whether this is\n> > fixing a bug or not. And if it is fixing bugs I'd also like to see tests\n> > added to the tree.\n>\n> I'm not sure if I would describe any of the changes as fixing bugs. The\n> option and config parsing code becomes stricter so I guess you could say\n> it was a bug to accept any old rubbish and treat it as zero before. The\n> imap code that's changed all rejected zero anyway apart from the tag\n> parsing so maybe accepting the changes to the tag parsing are fixing a bug.\n>\n> > And by the time we got there it makes sense to split up commits.\n>\n> Yes if we start adding tests then it is worth splitting them up, I'm not\n> sure we have anyway of testing the imap changes but it would be worth\n> testing the other changes though.\n>\n> Phillip\n>\n> > Patrick\n> >\n>\nI got this from a leftoverbit which the main issue was reported as\nbug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n\nFor the test, I should have the test as another patch right ?\nThanks.\n"},{"id":"505038","messageId":"CAPSxiM-aptyjesMX1H-P5QJjA-6CUonA01Bo84cq2_t==TqFgw@mail.gmail.com","threadId":"62325","inReplyTo":"CAPSxiM9ncwaZ3HF72wsRwmen7joWk3mjipsu78WxKEzLX607sw@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-14T16:26:17Z","receivedAt":"2024-10-14T16:26:29Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 4:13 PM Usman Akinyemi\n<usmanakinyemi202@gmail.com> wrote:\n>\n> On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> >\n> > On 14/10/2024 15:00, Patrick Steinhardt wrote:\n> > > On Mon, Oct 14, 2024 at 02:57:13PM +0100, Phillip Wood wrote:\n> > >> On 14/10/2024 11:53, Patrick Steinhardt wrote:\n> > >>> On Sun, Oct 13, 2024 at 09:42:41AM +0000, Usman Akinyemi wrote:\n> > >>>> On Sat, Oct 12, 2024 at 11:09 PM Usman Akinyemi via GitGitGadget\n> > >>>> <gitgitgadget@gmail.com> wrote:\n> > >>>>>\n> > >>>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > >>>>>\n> > >>>>> Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> > >>>>> and strtol_i() for signed integers across multiple files. This change\n> > >>>>> improves error handling and prevents potential integer overflow issues.\n> > >>>>>\n> > >>>>> The following files were updated:\n> > >>>>> - daemon.c: Update parsing of --timeout, --init-timeout, and\n> > >>>>>     --max-connections\n> > >>>>> - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n> > >>>>>     tags\n> > >>>>> - merge-ll.c: Enhance parsing of marker size in ll_merge and\n> > >>>>>     ll_merge_marker_size\n> > >>>\n> > >>> To me it's always an indicator that something should be split up across\n> > >>> multiple commits once you have a bulleted list of changes in your commit\n> > >>> message.\n> > >>\n> > >> Agreed, but I think in this case there is a common theme (converting atoi()\n> > >> to a safer alternative) and the problem is with the commit message listing\n> > >> which files have changed rather than unrelated code changes being grouped\n> > >> together. This patch could be split up and if there were many more atoi()\n> > >> conversions it would need to be split to prevent it being too long but I\n> > >> don't think its essential to do so.\n> > >\n> > > In theory I agree. In practice I think we should have better\n> > > explanations why the respective conversions are fine and whether this is\n> > > fixing a bug or not. And if it is fixing bugs I'd also like to see tests\n> > > added to the tree.\n> >\n> > I'm not sure if I would describe any of the changes as fixing bugs. The\n> > option and config parsing code becomes stricter so I guess you could say\n> > it was a bug to accept any old rubbish and treat it as zero before. The\n> > imap code that's changed all rejected zero anyway apart from the tag\n> > parsing so maybe accepting the changes to the tag parsing are fixing a bug.\n> >\n> > > And by the time we got there it makes sense to split up commits.\n> >\n> > Yes if we start adding tests then it is worth splitting them up, I'm not\n> > sure we have anyway of testing the imap changes but it would be worth\n> > testing the other changes though.\n> >\n> > Phillip\n> >\n> > > Patrick\n> > >\n> >\n> I got this from a leftoverbit which the main issue was reported as\n> bug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n>\n> For the test, I should have the test as another patch right ?\n> Thanks.\nAlso, do I need to add the reference which mentions the leftoverbit in\nthe commit message?\n"},{"id":"505042","messageId":"CAPSxiM_+1C3upsEzqj0reMgxT5viw5K9qKQq9=eBgVSO2MK3eA@mail.gmail.com","threadId":"62325","inReplyTo":"6875cb49-becc-4562-ace8-9f07848a345c@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-14T18:20:09Z","receivedAt":"2024-10-14T18:20:22Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 9:49 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> Hi Usman\n>\n> On 13/10/2024 00:09, Usman Akinyemi via GitGitGadget wrote:\n> > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> > and strtol_i() for signed integers across multiple files. This change\n> > improves error handling and prevents potential integer overflow issues.\n>\n> This paragraph is good as it explains why you are making this change\n>\n> > The following files were updated:\n> > - daemon.c: Update parsing of --timeout, --init-timeout, and\n> >    --max-connections\n> > - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n> >    tags\n> > - merge-ll.c: Enhance parsing of marker size in ll_merge and\n> >    ll_merge_marker_size\n>\n> This information is not really needed in the commit message as it is\n> shown in the diff.\n>\n> > This change allows for better error detection when parsing integer\n> > values from command-line arguments and IMAP responses, making the code\n> > more robust and secure.\n>\n> Great\n>\n> > This is a #leftoverbit discussed here:\n> >   https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> >\n> > Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Cc: gitster@pobox.com\n> > Cc: Patrick Steinhardt <ps@pks.im>\n> > Cc: phillip.wood123@gmail.com\n> > Cc: Christian Couder <christian.couder@gmail.com>\n> > Cc: Eric Sunshine <sunshine@sunshineco.com>\n> > Cc: Taylor Blau <me@ttaylorr.com>\n>\n> We do not tend to use Cc: footers on this list. Also note that as there\n> is a blank line between the Signed-off-by: line and this paragraph the\n> Signed-off-by: will be ignored by git-interpret-trailers.\n>\n> > ---\n> >   daemon.c    | 14 +++++++++-----\n> >   imap-send.c | 13 ++++++++-----\n> >   merge-ll.c  |  6 ++----\n> >   3 files changed, 19 insertions(+), 14 deletions(-)\n> >\n> > diff --git a/daemon.c b/daemon.c\n> > index cb946e3c95f..3fdb6e83c40 100644\n> > --- a/daemon.c\n> > +++ b/daemon.c\n> > @@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--timeout=\", &v)) {\n> > -                     timeout = atoi(v);\n> > +                     if (strtoul_ui(v, 10, &timeout) < 0) {\n>\n> For functions that return 0 or -1 to indicate success or error\n> respectively we use \"if (func(args))\" to check for errors.\n>\n> > +                             die(\"'%s': not a valid integer for --timeout\", v);\n>\n> \"-1\" is a valid integer but it is not a valid timeout, maybe we could\n> say something like \"invalid timeout '%s', expecting a non-negative integer\".\n>\n> > +                     }\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> > -                     init_timeout = atoi(v);\n> > +                     if (strtoul_ui(v, 10, &init_timeout) < 0) {\n> > +                             die(\"'%s': not a valid integer for --init-timeout\", v);\n>\n> The comments for --timeout apply here as well\n>\n> > +                     }\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--max-connections=\", &v)) {\n> > -                     max_connections = atoi(v);\n> > -                     if (max_connections < 0)\n> > -                             max_connections = 0;            /* unlimited */\n> > +                     if (strtol_i(v, 10, &max_connections) != 0 || max_connections < 0) {\n>\n> This is a faithful translation but if the aim of this series is to\n> detect errors then I think we want to do something like\n>\n>         if (strtol_i(v, 10, &max_connections))\n>                 die(...)\nohh, what I understand in this part of the code is intended to set\nmax_connections to 0 if the value it is currently set to is invalid,\nsuch as containing letters or being negative. Your suggestion implies\nthat we should return an error to indicate that letters are not\naccepted.\n>         if (max_connections < 0)\n>                 max_connections = 0; /* unlimited */\n>\n> > +                             max_connections = 0;  /* unlimited */\n> > +                     }\n> >                       continue;\n> >               }\n> >               if (!strcmp(arg, \"--strict-paths\")) {\n> > diff --git a/imap-send.c b/imap-send.c\n> > index ec68a066877..33b74dfded7 100644\n> > --- a/imap-send.c\n> > +++ b/imap-send.c\n> > @@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n> >               return RESP_BAD;\n> >       }\n> >       if (!strcmp(\"UIDVALIDITY\", arg)) {\n> > -             if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n> > +             if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) != 0) {\n>\n> The original is checking for a zero return from atoi() which indicates\n> an error or that the parsed value was zero. To do that with strtol_i()\n> we need to do\n>\n>         || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity)\n>\n> The IMAP RFC[1] specifies that UIDVALIDITY should be a non-zero,\n> non-negative 32bit integer but I'm not sure we want to start change it's\n> type and using strtoul_ui here.\n>\n> [1] https://www.rfc-editor.org/rfc/rfc3501#section-2.3.1.1\n>\n> >                       fprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n> >                       return RESP_BAD;\n> >               }\n> >       } else if (!strcmp(\"UIDNEXT\", arg)) {\n> > -             if (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n> > +             if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) != 0) {\n>\n> The comments above apply here\n>\n> >                       fprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n> >                       return RESP_BAD;\n> >               }\n> > @@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n> >               for (; isspace((unsigned char)*p); p++);\n> >               fprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n> >       } else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n> > -             if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n> > -                 !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n> > +             if (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) != 0) ||\n> > +                     !(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) != 0)) {\n>\n> And here\n>\n> >                       fprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n> >                       return RESP_BAD;\n> >               }\n> > @@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n> >                       if (!tcmd)\n> >                               return DRV_OK;\n> >               } else {\n> > -                     tag = atoi(arg);\n> > +                     if (strtol_i(arg, 10, &tag) != 0) {\n>\n> To check for an error just use (strtol_i(arg, 10, &tag))\n>\n> > +                             fprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n> > +                             return RESP_BAD;\n>\n> This matches the error below so I assume it's good.\n>\n> > +                     }\n> >                       for (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n> >                               if (cmdp->tag == tag)\n> >                                       goto gottag;\n> > diff --git a/merge-ll.c b/merge-ll.c\n> > index 8e63071922b..2bfee0f2c6b 100644\n> > --- a/merge-ll.c\n> > +++ b/merge-ll.c\n> > @@ -427,8 +427,7 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n> >       git_check_attr(istate, path, check);\n> >       ll_driver_name = check->items[0].value;\n> >       if (check->items[1].value) {\n> > -             marker_size = atoi(check->items[1].value);\n> > -             if (marker_size <= 0)\n> > +             if (strtol_i(check->items[1].value, 10, &marker_size) != 0 || marker_size <= 0)\n>\n> Here I think we want to return an error if we cannot parse the marker\n> size and then set the default if the marker size is <= 0 like we do for\n> the max_connections code in daemon.c above.\n>\n> >                       marker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n> >       }\n> >       driver = find_ll_merge_driver(ll_driver_name);\n> > @@ -454,8 +453,7 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n> >               check = attr_check_initl(\"conflict-marker-size\", NULL);\n> >       git_check_attr(istate, path, check);\n> >       if (check->items[0].value) {\n> > -             marker_size = atoi(check->items[0].value);\n> > -             if (marker_size <= 0)\n> > +             if (strtol_i(check->items[0].value, 10, &marker_size) != 0 || marker_size <= 0)\n>\n> And the same here\n>\n> Thanks for working on this, it will be a useful improvement to our\n> integer parsing. I think you've got the basic idea, it just needs a bit\n> of polish\n>\n> Phillip\n>\n"},{"id":"505043","messageId":"c710c45e-5090-446b-961b-ed0820523aad@gmail.com","threadId":"62325","inReplyTo":"CAPSxiM_+1C3upsEzqj0reMgxT5viw5K9qKQq9=eBgVSO2MK3eA@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-14T18:30:40Z","receivedAt":"2024-10-14T18:30:44Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"On 14/10/2024 19:20, Usman Akinyemi wrote:\n> On Mon, Oct 14, 2024 at 9:49 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>> On 13/10/2024 00:09, Usman Akinyemi via GitGitGadget wrote:\n>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>>>                }\n>>>                if (skip_prefix(arg, \"--max-connections=\", &v)) {\n>>> -                     max_connections = atoi(v);\n>>> -                     if (max_connections < 0)\n>>> -                             max_connections = 0;            /* unlimited */\n>>> +                     if (strtol_i(v, 10, &max_connections) != 0 || max_connections < 0) {\n>>\n>> This is a faithful translation but if the aim of this series is to\n>> detect errors then I think we want to do something like\n>>\n>>          if (strtol_i(v, 10, &max_connections))\n>>                  die(...)\n> ohh, what I understand in this part of the code is intended to set\n> max_connections to 0 if the value it is currently set to is invalid,\n> such as containing letters or being negative. Your suggestion implies\n> that we should return an error to indicate that letters are not\n> accepted.\n\nYes - I don't think we should be accepting any old rubbish when we \nexpect a number\n\nBest Wishes\n\nPhillip\n\n>>          if (max_connections < 0)\n>>                  max_connections = 0; /* unlimited */\n>>\n>>> +                             max_connections = 0;  /* unlimited */\n>>> +                     }\n>>>                        continue;\n>>>                }\n>>>                if (!strcmp(arg, \"--strict-paths\")) {\n>>> diff --git a/imap-send.c b/imap-send.c\n>>> index ec68a066877..33b74dfded7 100644\n>>> --- a/imap-send.c\n>>> +++ b/imap-send.c\n>>> @@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n>>>                return RESP_BAD;\n>>>        }\n>>>        if (!strcmp(\"UIDVALIDITY\", arg)) {\n>>> -             if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n>>> +             if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) != 0) {\n>>\n>> The original is checking for a zero return from atoi() which indicates\n>> an error or that the parsed value was zero. To do that with strtol_i()\n>> we need to do\n>>\n>>          || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity)\n>>\n>> The IMAP RFC[1] specifies that UIDVALIDITY should be a non-zero,\n>> non-negative 32bit integer but I'm not sure we want to start change it's\n>> type and using strtoul_ui here.\n>>\n>> [1] https://www.rfc-editor.org/rfc/rfc3501#section-2.3.1.1\n>>\n>>>                        fprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n>>>                        return RESP_BAD;\n>>>                }\n>>>        } else if (!strcmp(\"UIDNEXT\", arg)) {\n>>> -             if (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n>>> +             if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) != 0) {\n>>\n>> The comments above apply here\n>>\n>>>                        fprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n>>>                        return RESP_BAD;\n>>>                }\n>>> @@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n>>>                for (; isspace((unsigned char)*p); p++);\n>>>                fprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n>>>        } else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n>>> -             if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n>>> -                 !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n>>> +             if (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) != 0) ||\n>>> +                     !(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) != 0)) {\n>>\n>> And here\n>>\n>>>                        fprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n>>>                        return RESP_BAD;\n>>>                }\n>>> @@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n>>>                        if (!tcmd)\n>>>                                return DRV_OK;\n>>>                } else {\n>>> -                     tag = atoi(arg);\n>>> +                     if (strtol_i(arg, 10, &tag) != 0) {\n>>\n>> To check for an error just use (strtol_i(arg, 10, &tag))\n>>\n>>> +                             fprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n>>> +                             return RESP_BAD;\n>>\n>> This matches the error below so I assume it's good.\n>>\n>>> +                     }\n>>>                        for (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n>>>                                if (cmdp->tag == tag)\n>>>                                        goto gottag;\n>>> diff --git a/merge-ll.c b/merge-ll.c\n>>> index 8e63071922b..2bfee0f2c6b 100644\n>>> --- a/merge-ll.c\n>>> +++ b/merge-ll.c\n>>> @@ -427,8 +427,7 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n>>>        git_check_attr(istate, path, check);\n>>>        ll_driver_name = check->items[0].value;\n>>>        if (check->items[1].value) {\n>>> -             marker_size = atoi(check->items[1].value);\n>>> -             if (marker_size <= 0)\n>>> +             if (strtol_i(check->items[1].value, 10, &marker_size) != 0 || marker_size <= 0)\n>>\n>> Here I think we want to return an error if we cannot parse the marker\n>> size and then set the default if the marker size is <= 0 like we do for\n>> the max_connections code in daemon.c above.\n>>\n>>>                        marker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n>>>        }\n>>>        driver = find_ll_merge_driver(ll_driver_name);\n>>> @@ -454,8 +453,7 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n>>>                check = attr_check_initl(\"conflict-marker-size\", NULL);\n>>>        git_check_attr(istate, path, check);\n>>>        if (check->items[0].value) {\n>>> -             marker_size = atoi(check->items[0].value);\n>>> -             if (marker_size <= 0)\n>>> +             if (strtol_i(check->items[0].value, 10, &marker_size) != 0 || marker_size <= 0)\n>>\n>> And the same here\n>>\n>> Thanks for working on this, it will be a useful improvement to our\n>> integer parsing. I think you've got the basic idea, it just needs a bit\n>> of polish\n>>\n>> Phillip\n>>\n\n"},{"id":"505044","messageId":"84dbe9f1-976d-45f8-a49a-d0f942906686@gmail.com","threadId":"62325","inReplyTo":"CAPSxiM-aptyjesMX1H-P5QJjA-6CUonA01Bo84cq2_t==TqFgw@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-14T18:36:46Z","receivedAt":"2024-10-14T18:36:49Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"On 14/10/2024 17:26, Usman Akinyemi wrote:\n> On Mon, Oct 14, 2024 at 4:13 PM Usman Akinyemi\n>> On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>> I got this from a leftoverbit which the main issue was reported as\n>> bug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n>> For the test, I should have the test as another patch right ?\n\nIn general you should add tests in the same commit as the code changes \nthat they test. In this instance I think you want to split this patch \ninto three, one patch for git-daemon, one for imap-send and one for the \nmerge marker config changes. Each patch should have a commit message \nexplaining the changes and whether they change the behavior of the code \n(for example rejecting non-numbers) and add some tests. Note that I \ndon't think it is possible to test the imap-send changes but the other \ntwo should be easy enough. The tests should be added to one of the \nexisting test files that are testing the code being changed.\n\n>> Thanks.\n> Also, do I need to add the reference which mentions the leftoverbit in\n> the commit message?\n\nI'm not sure that's necessary so long as you explain the reason for the \nchanges in the commit message.\n\n\nBest Wishes\n\nPhillip\n\n\n"},{"id":"505070","messageId":"Zw2NTPk+YwEqcydf@nand.local","threadId":"62325","inReplyTo":"bfff7937cd20737bb5a8791dc7492700b1d7881f.1728774574.git.gitgitgadget@gmail.com","subject":"Re: [PATCH 1/3] t3404: avoid losing exit status with focus on `git show` and `git cat-file`","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-14T21:29:48Z","receivedAt":"2024-10-14T21:29:50Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Sat, Oct 12, 2024 at 11:09:32PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>\n> The exit code of the preceding command in a pipe is disregarded. So\n> if that preceding command is a Git command that fails, the test would\n> not fail. Instead, by saving the output of that Git command to a file,\n> and removing the pipe, we make sure the test will fail if that Git\n> command fails. This particular patch focuses on all `git show` and\n> some instances of `git cat-file`.\n>\n> Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> ---\n>  t/t3404-rebase-interactive.sh | 71 +++++++++++++++++++++++------------\n>  1 file changed, 48 insertions(+), 23 deletions(-)\n>\n> diff --git a/t/t3404-rebase-interactive.sh b/t/t3404-rebase-interactive.sh\n> index f171af3061d..96a65783c47 100755\n> --- a/t/t3404-rebase-interactive.sh\n> +++ b/t/t3404-rebase-interactive.sh\n> @@ -319,7 +319,8 @@ test_expect_success 'retain authorship' '\n>  \tGIT_AUTHOR_NAME=\"Twerp Snog\" git commit -m \"different author\" &&\n>  \tgit tag twerp &&\n>  \tgit rebase -i --onto primary HEAD^ &&\n> -\tgit show HEAD | grep \"^Author: Twerp Snog\"\n> +\tgit show HEAD >actual &&\n> +\tgrep \"^Author: Twerp Snog\" actual\n>  '\n\nGood.\n\n> @@ -397,7 +400,9 @@ test_expect_success 'multi-squash only fires up editor once' '\n>  \t\t\tgit rebase -i $base\n>  \t) &&\n>  \ttest $base = $(git rev-parse HEAD^) &&\n> -\ttest 1 = $(git show | grep ONCE | wc -l)\n> +\tgit show >output &&\n> +\tcount=$(grep ONCE output | wc -l) &&\n> +\ttest 1 = $count\n>  '\n\nI think moving 'git show' out of the pipeline is a good step here, but I\ndon't think we need to store $count in a separate variable. It would be\nfine to write:\n\n    git show >output &&\n    test 1 = $(grep ONCE output | wc -l)\n\nor even to replace the subshell with 'grep -c' instead of piping 'grep'\nto 'wc -l'.\n\n>  test_expect_success 'multi-fixup does not fire up editor' '\n> @@ -410,7 +415,9 @@ test_expect_success 'multi-fixup does not fire up editor' '\n>  \t\t\tgit rebase -i $base\n>  \t) &&\n>  \ttest $base = $(git rev-parse HEAD^) &&\n> -\ttest 0 = $(git show | grep NEVER | wc -l) &&\n> +\tgit show >output &&\n> +\tcount=$(grep NEVER output | wc -l) &&\n> +\ttest 0 = $count &&\n>  \tgit checkout @{-1} &&\n>  \tgit branch -D multi-fixup\n>  '\n\nSame notes from above here and the next two tests (elided from my\nresponse) below.\n\n> @@ -470,10 +481,10 @@ test_expect_success 'squash and fixup generate correct log messages' '\n>  \t) &&\n>  \tgit cat-file commit HEAD | sed -e 1,/^\\$/d > actual-squash-fixup &&\n>  \ttest_cmp expect-squash-fixup actual-squash-fixup &&\n> -\tgit cat-file commit HEAD@{2} |\n> -\t\tgrep \"^# This is a combination of 3 commits\\.\"  &&\n> -\tgit cat-file commit HEAD@{3} |\n> -\t\tgrep \"^# This is a combination of 2 commits\\.\"  &&\n> +\tgit cat-file commit HEAD@{2} >actual &&\n> +\tgrep \"^# This is a combination of 3 commits\\.\" actual &&\n\nIs there a more descriptive name for the output here than just 'actual'?\n\nThanks,\nTaylor\n"},{"id":"505072","messageId":"Zw2OsWorAVL4hCB9@nand.local","threadId":"62325","inReplyTo":"e2cae7f3a510027864303fe91dcf447f63eb0873.1728774574.git.gitgitgadget@gmail.com","subject":"Re: [PATCH 2/3] t3404: replace test with test_line_count()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-14T21:35:45Z","receivedAt":"2024-10-14T21:35:48Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Sat, Oct 12, 2024 at 11:09:33PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>\n> Refactor t3404 to replace instances of `test` with `test_line_count()`\n> for checking line counts. This improves readability and aligns with Git's\n> current test practices.\n>\n> Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> ---\n>  t/t3404-rebase-interactive.sh | 28 ++++++++++++++--------------\n>  1 file changed, 14 insertions(+), 14 deletions(-)\n>\n> diff --git a/t/t3404-rebase-interactive.sh b/t/t3404-rebase-interactive.sh\n> index 96a65783c47..2ab660ef30f 100755\n> --- a/t/t3404-rebase-interactive.sh\n> +++ b/t/t3404-rebase-interactive.sh\n> @@ -281,8 +281,9 @@ test_expect_success 'stop on conflicting pick' '\n>  \ttest_cmp expect2 file1 &&\n>  \ttest \"$(git diff --name-status |\n>  \t\tsed -n -e \"/^U/s/^U[^a-z]*//p\")\" = file1 &&\n> -\ttest 4 = $(grep -v \"^#\" < .git/rebase-merge/done | wc -l) &&\n> -\ttest 0 = $(grep -c \"^[^#]\" < .git/rebase-merge/git-rebase-todo)\n> +\tgrep -v \"^#\" <.git/rebase-merge/done >actual &&\n> +\ttest_line_count = 4 actual &&\n> +\ttest 0 = $(grep -c \"^[^#]\" <.git/rebase-merge/git-rebase-todo)\n\nYou use 'test_line_count' in one instance here, but 'test 0 =' below.\nYou could use 'test_must_be_empty' to stick with our test_-helper\nfunctions.\n\nBut I like that you used 'grep -c' here, so it may be better to match\nthe two like so:\n\n    test 4 $(grep -c -v \"^#\" <.git/rebase-merge/done) &&\n    test 0 = $(grep -c \"^[^#]\" <.git/rebase-merge/git-rebase-todo)\n\n> @@ -416,8 +417,7 @@ test_expect_success 'multi-fixup does not fire up editor' '\n>  \t) &&\n>  \ttest $base = $(git rev-parse HEAD^) &&\n>  \tgit show >output &&\n> -\tcount=$(grep NEVER output | wc -l) &&\n> -\ttest 0 = $count &&\n> +\t! grep NEVER output &&\n>  \tgit checkout @{-1} &&\n>  \tgit branch -D multi-fixup\n>  '\n\nHmm. Wasn't this modified by the previous step as well? Is there a\nreason that these can't be combined to avoid a new intermediate state\nthat will be thrown away in the next step?\n\n> @@ -436,8 +436,8 @@ test_expect_success 'commit message used after conflict' '\n>  \t) &&\n>  \ttest $base = $(git rev-parse HEAD^) &&\n>  \tgit show >output &&\n> -\tcount=$(grep ONCE output | wc -l) &&\n> -\ttest 1 = $count &&\n> +\tgrep ONCE output >actual &&\n> +\ttest_line_count = 1 actual &&\n>  \tgit checkout @{-1} &&\n>  \tgit branch -D conflict-fixup\n\nI am not sure what the benefit of using test_line_count here is over\nbare 'test'. Can you explain why you chose to use it here?\n\nIn the body of your patch above, you appear to suggest that using\ntest_line_count is more in the style of Git's current test practices. I\nthink that's true for cases like writing:\n\n    test_line_count = 1 actual\n\nas opposed to:\n\n    test 1 = $(wc -l <actual)\n\nSince the former doesn't have the gotcha that you must remember redirect\nthe input of 'wc -l' to avoid having the filename appear in the output,\nand the former also ensures that the file exists, has better error\nmessages, etc.\n\nBut in the case where we're running 'grep -c' directly, it seems cleaner\nto use bare test, since we're not writing the matches to a file on disk.\n\nThanks,\nTaylor\n"},{"id":"505171","messageId":"CAPSxiM8-C6DAE3nYqMUCs+UgHN1R41grwVE+S-cSi6gZGvCpYw@mail.gmail.com","threadId":"62325","inReplyTo":"84dbe9f1-976d-45f8-a49a-d0f942906686@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-15T15:17:05Z","receivedAt":"2024-10-15T15:17:16Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 6:36 PM <phillip.wood123@gmail.com> wrote:\n>\n> On 14/10/2024 17:26, Usman Akinyemi wrote:\n> > On Mon, Oct 14, 2024 at 4:13 PM Usman Akinyemi\n> >> On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> >> I got this from a leftoverbit which the main issue was reported as\n> >> bug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> >> For the test, I should have the test as another patch right ?\n>\n> In general you should add tests in the same commit as the code changes\n> that they test. In this instance I think you want to split this patch\n> into three, one patch for git-daemon, one for imap-send and one for the\n> merge marker config changes. Each patch should have a commit message\n> explaining the changes and whether they change the behavior of the code\n> (for example rejecting non-numbers) and add some tests. Note that I\n> don't think it is possible to test the imap-send changes but the other\n> two should be easy enough. The tests should be added to one of the\n> existing test files that are testing the code being changed.\n>\nHello, thanks for this, I was working on this and I need help. For the\nmerge-ll.c,\nI noticed that the check->items[0].value were already checked to\nensure they do not contain letters in them.\n        if (check->items[1].value) {\n                marker_size = atoi(check->items[1].value);\n                if (strtol_i(check->items[1].value, 10, &marker_size))\n                        die(\"invalid marker-size expecting an integer\");\n                if (marker_size <= 0)\n                        marker_size = DEFAULT_CONFLICT_MARKER_SIZE\n\nerror: option `marker-size' expects a numerical value\nnot ok 38 - merge without conflict wrong marker-size\n#\n# cp new1.txt test.txt &&\n# test_must_fail git merge-file -p --marker-size=1a test.txt orig.txt\nnew2.txt 2>error &&\n# cat error &&\n#     grep \"invalid\" error\n#\nI grepped the error message and I noticed that the message is gotten\nfrom parse-options.c and it ensures that the arg is negative. How to\nproceed in such a case ?\n\nAlso, for the daemon.c I am finding\nit hard to get the exact test file to add the new test.\n\nThank you.\nUsman Akinyemi\n\n\n> >> Thanks.\n> > Also, do I need to add the reference which mentions the leftoverbit in\n> > the commit message?\n>\n> I'm not sure that's necessary so long as you explain the reason for the\n> changes in the commit message.\n>\n>\n> Best Wishes\n>\n> Phillip\n>\n>\n"},{"id":"505175","messageId":"Zw6WKuhUufWeSipU@nand.local","threadId":"62325","inReplyTo":"CAPSxiM8-C6DAE3nYqMUCs+UgHN1R41grwVE+S-cSi6gZGvCpYw@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-15T16:19:54Z","receivedAt":"2024-10-15T16:19:56Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Tue, Oct 15, 2024 at 03:17:05PM +0000, Usman Akinyemi wrote:\n> Also, for the daemon.c I am finding\n> it hard to get the exact test file to add the new test.\n\nt5570-git-daemon.sh is the test file I usually think of for adding the\nmost direct tests exercising git-daemon.\n\nIf you're ever unsure, I find it useful to grep through the filenames of\nscripts in t, like so:\n\n    $ ls t/t????-*.sh | grep daemon\n    t/t5570-git-daemon.sh\n\nThanks,\nTaylor\n"},{"id":"505184","messageId":"9952b3a7-0ebc-4555-b8b3-f50f6f383704@gmail.com","threadId":"62325","inReplyTo":"CAPSxiM8-C6DAE3nYqMUCs+UgHN1R41grwVE+S-cSi6gZGvCpYw@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-15T18:28:20Z","receivedAt":"2024-10-15T18:28:24Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Usman\n\nOn 15/10/2024 16:17, Usman Akinyemi wrote:\n> On Mon, Oct 14, 2024 at 6:36 PM <phillip.wood123@gmail.com> wrote:\n>>\n>> On 14/10/2024 17:26, Usman Akinyemi wrote:\n>>> On Mon, Oct 14, 2024 at 4:13 PM Usman Akinyemi\n>>>> On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>>>> I got this from a leftoverbit which the main issue was reported as\n>>>> bug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n>>>> For the test, I should have the test as another patch right ?\n>>\n>> In general you should add tests in the same commit as the code changes\n>> that they test. In this instance I think you want to split this patch\n>> into three, one patch for git-daemon, one for imap-send and one for the\n>> merge marker config changes. Each patch should have a commit message\n>> explaining the changes and whether they change the behavior of the code\n>> (for example rejecting non-numbers) and add some tests. Note that I\n>> don't think it is possible to test the imap-send changes but the other\n>> two should be easy enough. The tests should be added to one of the\n>> existing test files that are testing the code being changed.\n>>\n> Hello, thanks for this, I was working on this and I need help. For the\n> merge-ll.c,\n> I noticed that the check->items[0].value were already checked to\n> ensure they do not contain letters in them.\n>          if (check->items[1].value) {\n>                  marker_size = atoi(check->items[1].value);\n>                  if (strtol_i(check->items[1].value, 10, &marker_size))\n>                          die(\"invalid marker-size expecting an integer\");\n>                  if (marker_size <= 0)\n>                          marker_size = DEFAULT_CONFLICT_MARKER_SIZE\n> \n> error: option `marker-size' expects a numerical value\n> not ok 38 - merge without conflict wrong marker-size\n> #\n> # cp new1.txt test.txt &&\n> # test_must_fail git merge-file -p --marker-size=1a test.txt orig.txt\n> new2.txt 2>error &&\n> # cat error &&\n> #     grep \"invalid\" error\n\nIt would be better to check for the error message with test_cmp or at \nleast grep for a longer phrase so we're sure the error message is the \none we think we should be getting.\n\n> #\n> I grepped the error message and I noticed that the message is gotten\n> from parse-options.c and it ensures that the arg is negative. How to\n> proceed in such a case ?\n\nThe code you're changing parses the conflict-marker-size attribute so \nyou need to set up a .gitattributes file with an invalid marker size and \nthen run \"git merge\" or \"git cherry-pick\"\n\nBest Wishes\n\nPhillip\n\n> Also, for the daemon.c I am finding\n> it hard to get the exact test file to add the new test.\n> \n> Thank you.\n> Usman Akinyemi\n> \n> \n>>>> Thanks.\n>>> Also, do I need to add the reference which mentions the leftoverbit in\n>>> the commit message?\n>>\n>> I'm not sure that's necessary so long as you explain the reason for the\n>> changes in the commit message.\n>>\n>>\n>> Best Wishes\n>>\n>> Phillip\n>>\n>>\n\n"},{"id":"505260","messageId":"87090897-7ff9-4396-b81c-0fc423593602@gmail.com","threadId":"62325","inReplyTo":"9952b3a7-0ebc-4555-b8b3-f50f6f383704@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-16T09:20:11Z","receivedAt":"2024-10-16T09:20:14Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"On 15/10/2024 19:28, phillip.wood123@gmail.com wrote:\n> On 15/10/2024 16:17, Usman Akinyemi wrote:\n>> \n>> I grepped the error message and I noticed that the message is gotten\n>> from parse-options.c and it ensures that the arg is negative. How to\n>> proceed in such a case ?\n> \n> The code you're changing parses the conflict-marker-size attribute so \n> you need to set up a .gitattributes file with an invalid marker size and \n> then run \"git merge\" or \"git cherry-pick\"\n\nt/t6406-merge-attr.sh would be a good place to add this test\n\nBest Wishes\n\nPhillip\n\n"},{"id":"505275","messageId":"CAPSxiM_GJTVvm61Y-bzTms_DT_9Xg=L8zDnMtRP5up7DRq=72w@mail.gmail.com","threadId":"62325","inReplyTo":"Zw6WKuhUufWeSipU@nand.local","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-16T17:58:10Z","receivedAt":"2024-10-16T17:58:22Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Tue, Oct 15, 2024 at 4:19 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Tue, Oct 15, 2024 at 03:17:05PM +0000, Usman Akinyemi wrote:\n> > Also, for the daemon.c I am finding\n> > it hard to get the exact test file to add the new test.\n>\n> t5570-git-daemon.sh is the test file I usually think of for adding the\n> most direct tests exercising git-daemon.\n>\n> If you're ever unsure, I find it useful to grep through the filenames of\n> scripts in t, like so:\n>\n>     $ ls t/t????-*.sh | grep daemon\n>     t/t5570-git-daemon.sh\n>\n> Thanks,\n> Taylor\nThanks for this, I really appreciate it.\n"},{"id":"505276","messageId":"CAPSxiM9KnkNjhtcQvZn0sekZimyzqtzX4Q3xpH_GGhy8goCWdw@mail.gmail.com","threadId":"62325","inReplyTo":"87090897-7ff9-4396-b81c-0fc423593602@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-16T18:00:00Z","receivedAt":"2024-10-16T18:00:12Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Wed, Oct 16, 2024 at 9:20 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> On 15/10/2024 19:28, phillip.wood123@gmail.com wrote:\n> > On 15/10/2024 16:17, Usman Akinyemi wrote:\n> >>\n> >> I grepped the error message and I noticed that the message is gotten\n> >> from parse-options.c and it ensures that the arg is negative. How to\n> >> proceed in such a case ?\n> >\n> > The code you're changing parses the conflict-marker-size attribute so\n> > you need to set up a .gitattributes file with an invalid marker size and\n> > then run \"git merge\" or \"git cherry-pick\"\nThanks.\n>\n> t/t6406-merge-attr.sh would be a good place to add this test\nThank you Philip.\n>\n> Best Wishes\n>\n> Phillip\n>\n"},{"id":"505358","messageId":"CAPSxiM9j50ksZsdd+mVYt7p5=5GQDjA3eXSgryGCF7QsDNEE1w@mail.gmail.com","threadId":"62325","inReplyTo":"6875cb49-becc-4562-ace8-9f07848a345c@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-17T11:16:45Z","receivedAt":"2024-10-17T11:16:57Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 9:49 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> Hi Usman\n>\n> On 13/10/2024 00:09, Usman Akinyemi via GitGitGadget wrote:\n> > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n> > and strtol_i() for signed integers across multiple files. This change\n> > improves error handling and prevents potential integer overflow issues.\n>\n> This paragraph is good as it explains why you are making this change\n>\n> > The following files were updated:\n> > - daemon.c: Update parsing of --timeout, --init-timeout, and\n> >    --max-connections\n> > - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n> >    tags\n> > - merge-ll.c: Enhance parsing of marker size in ll_merge and\n> >    ll_merge_marker_size\n>\n> This information is not really needed in the commit message as it is\n> shown in the diff.\n>\n> > This change allows for better error detection when parsing integer\n> > values from command-line arguments and IMAP responses, making the code\n> > more robust and secure.\n>\n> Great\n>\n> > This is a #leftoverbit discussed here:\n> >   https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> >\n> > Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Cc: gitster@pobox.com\n> > Cc: Patrick Steinhardt <ps@pks.im>\n> > Cc: phillip.wood123@gmail.com\n> > Cc: Christian Couder <christian.couder@gmail.com>\n> > Cc: Eric Sunshine <sunshine@sunshineco.com>\n> > Cc: Taylor Blau <me@ttaylorr.com>\n>\n> We do not tend to use Cc: footers on this list. Also note that as there\n> is a blank line between the Signed-off-by: line and this paragraph the\n> Signed-off-by: will be ignored by git-interpret-trailers.\n>\n> > ---\n> >   daemon.c    | 14 +++++++++-----\n> >   imap-send.c | 13 ++++++++-----\n> >   merge-ll.c  |  6 ++----\n> >   3 files changed, 19 insertions(+), 14 deletions(-)\n> >\n> > diff --git a/daemon.c b/daemon.c\n> > index cb946e3c95f..3fdb6e83c40 100644\n> > --- a/daemon.c\n> > +++ b/daemon.c\n> > @@ -1308,17 +1308,21 @@ int cmd_main(int argc, const char **argv)\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--timeout=\", &v)) {\n> > -                     timeout = atoi(v);\n> > +                     if (strtoul_ui(v, 10, &timeout) < 0) {\n>\n> For functions that return 0 or -1 to indicate success or error\n> respectively we use \"if (func(args))\" to check for errors.\n>\n> > +                             die(\"'%s': not a valid integer for --timeout\", v);\n>\n> \"-1\" is a valid integer but it is not a valid timeout, maybe we could\n> say something like \"invalid timeout '%s', expecting a non-negative integer\".\n>\n> > +                     }\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> > -                     init_timeout = atoi(v);\n> > +                     if (strtoul_ui(v, 10, &init_timeout) < 0) {\n> > +                             die(\"'%s': not a valid integer for --init-timeout\", v);\n>\n> The comments for --timeout apply here as well\n>\n> > +                     }\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--max-connections=\", &v)) {\n> > -                     max_connections = atoi(v);\n> > -                     if (max_connections < 0)\n> > -                             max_connections = 0;            /* unlimited */\n> > +                     if (strtol_i(v, 10, &max_connections) != 0 || max_connections < 0) {\n>\n> This is a faithful translation but if the aim of this series is to\n> detect errors then I think we want to do something like\n>\n>         if (strtol_i(v, 10, &max_connections))\n>                 die(...)\n>         if (max_connections < 0)\n>                 max_connections = 0; /* unlimited */\n>\n> > +                             max_connections = 0;  /* unlimited */\n> > +                     }\n> >                       continue;\n> >               }\n> >               if (!strcmp(arg, \"--strict-paths\")) {\n> > diff --git a/imap-send.c b/imap-send.c\n> > index ec68a066877..33b74dfded7 100644\n> > --- a/imap-send.c\n> > +++ b/imap-send.c\n> > @@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n> >               return RESP_BAD;\n> >       }\n> >       if (!strcmp(\"UIDVALIDITY\", arg)) {\n> > -             if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n> > +             if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) != 0) {\n>\n> The original is checking for a zero return from atoi() which indicates\n> an error or that the parsed value was zero. To do that with strtol_i()\n> we need to do\n>\n>         || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity)\n>\n> The IMAP RFC[1] specifies that UIDVALIDITY should be a non-zero,\n> non-negative 32bit integer but I'm not sure we want to start change it's\n> type and using strtoul_ui here.\nHello, regarding this. I used strtol_i here as ctx->uidvalidity\nwas declared to be int so, the strtoul_ui complained as it was\nexpecting an unsigned int.\nMy suggestion will be to leave it as strol_i and use this comparison\n(strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity), what do you think ?\n>\n> [1] https://www.rfc-editor.org/rfc/rfc3501#section-2.3.1.1\n>\n> >                       fprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n> >                       return RESP_BAD;\n> >               }\n> >       } else if (!strcmp(\"UIDNEXT\", arg)) {\n> > -             if (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n> > +             if (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) != 0) {\n>\n> The comments above apply here\n>\n> >                       fprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n> >                       return RESP_BAD;\n> >               }\n> > @@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n> >               for (; isspace((unsigned char)*p); p++);\n> >               fprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n> >       } else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n> > -             if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n> > -                 !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n> > +             if (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) != 0) ||\n> > +                     !(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) != 0)) {\n>\n> And here\n>\n> >                       fprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n> >                       return RESP_BAD;\n> >               }\n> > @@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n> >                       if (!tcmd)\n> >                               return DRV_OK;\n> >               } else {\n> > -                     tag = atoi(arg);\n> > +                     if (strtol_i(arg, 10, &tag) != 0) {\n>\n> To check for an error just use (strtol_i(arg, 10, &tag))\n>\n> > +                             fprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n> > +                             return RESP_BAD;\n>\n> This matches the error below so I assume it's good.\n>\n> > +                     }\n> >                       for (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n> >                               if (cmdp->tag == tag)\n> >                                       goto gottag;\n> > diff --git a/merge-ll.c b/merge-ll.c\n> > index 8e63071922b..2bfee0f2c6b 100644\n> > --- a/merge-ll.c\n> > +++ b/merge-ll.c\n> > @@ -427,8 +427,7 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n> >       git_check_attr(istate, path, check);\n> >       ll_driver_name = check->items[0].value;\n> >       if (check->items[1].value) {\n> > -             marker_size = atoi(check->items[1].value);\n> > -             if (marker_size <= 0)\n> > +             if (strtol_i(check->items[1].value, 10, &marker_size) != 0 || marker_size <= 0)\n>\n> Here I think we want to return an error if we cannot parse the marker\n> size and then set the default if the marker size is <= 0 like we do for\n> the max_connections code in daemon.c above.\n>\n> >                       marker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n> >       }\n> >       driver = find_ll_merge_driver(ll_driver_name);\n> > @@ -454,8 +453,7 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n> >               check = attr_check_initl(\"conflict-marker-size\", NULL);\n> >       git_check_attr(istate, path, check);\n> >       if (check->items[0].value) {\n> > -             marker_size = atoi(check->items[0].value);\n> > -             if (marker_size <= 0)\n> > +             if (strtol_i(check->items[0].value, 10, &marker_size) != 0 || marker_size <= 0)\n>\n> And the same here\n>\n> Thanks for working on this, it will be a useful improvement to our\n> integer parsing. I think you've got the basic idea, it just needs a bit\n> of polish\n>\n> Phillip\n>\n"},{"id":"505360","messageId":"CAPSxiM-Yw2H65+EHoDckU2N2hr+UrXRu5Y2JjXc+TEwEUKJT0Q@mail.gmail.com","threadId":"62325","inReplyTo":"84dbe9f1-976d-45f8-a49a-d0f942906686@gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-17T11:56:33Z","receivedAt":"2024-10-17T11:56:45Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 14, 2024 at 6:36 PM <phillip.wood123@gmail.com> wrote:\n>\n> On 14/10/2024 17:26, Usman Akinyemi wrote:\n> > On Mon, Oct 14, 2024 at 4:13 PM Usman Akinyemi\n> >> On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> >> I got this from a leftoverbit which the main issue was reported as\n> >> bug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> >> For the test, I should have the test as another patch right ?\n>\n> In general you should add tests in the same commit as the code changes\n> that they test. In this instance I think you want to split this patch\n> into three, one patch for git-daemon, one for imap-send and one for the\n> merge marker config changes. Each patch should have a commit message\n> explaining the changes and whether they change the behavior of the code\n> (for example rejecting non-numbers) and add some tests. Note that I\n> don't think it is possible to test the imap-send changes but the other\n> two should be easy enough. The tests should be added to one of the\n> existing test files that are testing the code being changed.\nHello,\nI am currently facing some issues while trying to write the test for\ndaemon.c, I need some help on it.\nThe start_git_daemon function inside lib-git-daemon.sh is made to\nallow --init-timeout, --max-connections and\ntimeout as well as other arguments. The start_git_daemon function in\nlib-git-daemon.sh is used at t5570-git-daemon.sh.\nBasically this is my changes\n                if (skip_prefix(arg, \"--timeout=\", &v)) {\n-                       timeout = atoi(v);\n+                       if (strtoul_ui(v, 10, &timeout))\n+                               die(\"invalid timeout '%s', expecting a\nnon-negative integer\", v);\n                        continue;\n                }\n                if (skip_prefix(arg, \"--init-timeout=\", &v)) {\n-                       init_timeout = atoi(v);\n+                       if (strtoul_ui(v, 10, &init_timeout))\n+                               die(\"invalid init-timeout '%s',\nexpecting a non-negative integer\", v);\n                        continue;\n                }\n                if (skip_prefix(arg, \"--max-connections=\", &v)) {\n-                       max_connections = atoi(v);\n+                       if (strtol_i(v, 10, &max_connections))\n+                               die(\"invalid '--max-connections' '%s',\nexpecting an integer\", v);\n                        if (max_connections < 0)\n-                               max_connections = 0;            /* unlimited */\n+                               max_connections = 0;  /* unlimited */\n                        continue;\n                }\nWhat happened is that the start_git_daemon will already fail and will\nprevent the\nt5570-git-daemon.sh from starting if there is any wrong starting\ncondition such as the new\nchanges I added. I am finding it hard to come up with an approach to\ntest the new change.\n\n\nThank you.\n>\n> >> Thanks.\n> > Also, do I need to add the reference which mentions the leftoverbit in\n> > the commit message?\n>\n> I'm not sure that's necessary so long as you explain the reason for the\n> changes in the commit message.\n>\n>\n> Best Wishes\n>\n> Phillip\n>\n>\n"},{"id":"505362","messageId":"ZxD84l-tcU0TrX1K@pks.im","threadId":"62325","inReplyTo":"CAPSxiM-Yw2H65+EHoDckU2N2hr+UrXRu5Y2JjXc+TEwEUKJT0Q@mail.gmail.com","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-17T12:02:49Z","receivedAt":"2024-10-17T12:02:54Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Thu, Oct 17, 2024 at 11:56:33AM +0000, Usman Akinyemi wrote:\n> On Mon, Oct 14, 2024 at 6:36 PM <phillip.wood123@gmail.com> wrote:\n> >\n> > On 14/10/2024 17:26, Usman Akinyemi wrote:\n> > > On Mon, Oct 14, 2024 at 4:13 PM Usman Akinyemi\n> > >> On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> > >> I got this from a leftoverbit which the main issue was reported as\n> > >> bug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> > >> For the test, I should have the test as another patch right ?\n> >\n> > In general you should add tests in the same commit as the code changes\n> > that they test. In this instance I think you want to split this patch\n> > into three, one patch for git-daemon, one for imap-send and one for the\n> > merge marker config changes. Each patch should have a commit message\n> > explaining the changes and whether they change the behavior of the code\n> > (for example rejecting non-numbers) and add some tests. Note that I\n> > don't think it is possible to test the imap-send changes but the other\n> > two should be easy enough. The tests should be added to one of the\n> > existing test files that are testing the code being changed.\n> Hello,\n> I am currently facing some issues while trying to write the test for\n> daemon.c, I need some help on it.\n> The start_git_daemon function inside lib-git-daemon.sh is made to\n> allow --init-timeout, --max-connections and\n> timeout as well as other arguments. The start_git_daemon function in\n> lib-git-daemon.sh is used at t5570-git-daemon.sh.\n> Basically this is my changes\n>                 if (skip_prefix(arg, \"--timeout=\", &v)) {\n> -                       timeout = atoi(v);\n> +                       if (strtoul_ui(v, 10, &timeout))\n> +                               die(\"invalid timeout '%s', expecting a\n> non-negative integer\", v);\n>                         continue;\n>                 }\n>                 if (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> -                       init_timeout = atoi(v);\n> +                       if (strtoul_ui(v, 10, &init_timeout))\n> +                               die(\"invalid init-timeout '%s',\n> expecting a non-negative integer\", v);\n>                         continue;\n>                 }\n>                 if (skip_prefix(arg, \"--max-connections=\", &v)) {\n> -                       max_connections = atoi(v);\n> +                       if (strtol_i(v, 10, &max_connections))\n> +                               die(\"invalid '--max-connections' '%s',\n> expecting an integer\", v);\n>                         if (max_connections < 0)\n> -                               max_connections = 0;            /* unlimited */\n> +                               max_connections = 0;  /* unlimited */\n>                         continue;\n>                 }\n> What happened is that the start_git_daemon will already fail and will\n> prevent the\n> t5570-git-daemon.sh from starting if there is any wrong starting\n> condition such as the new\n> changes I added. I am finding it hard to come up with an approach to\n> test the new change.\n\nI'd just not use `start_git_daemon ()` in the first place. Instead, I'd\ninvoke git-daemon(1) directly with invalid options and then observe that\nit fails to start up with the expected error message.\n\nPatrick\n"},{"id":"505366","messageId":"CAPSxiM99x8vEQSnDHCfKrQKuxE0dzenj5O4jrR0+jE62KAxErw@mail.gmail.com","threadId":"62325","inReplyTo":"ZxD84l-tcU0TrX1K@pks.im","subject":"Re: [PATCH 3/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-17T12:13:28Z","receivedAt":"2024-10-17T12:13:40Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Thu, Oct 17, 2024 at 12:02 PM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Thu, Oct 17, 2024 at 11:56:33AM +0000, Usman Akinyemi wrote:\n> > On Mon, Oct 14, 2024 at 6:36 PM <phillip.wood123@gmail.com> wrote:\n> > >\n> > > On 14/10/2024 17:26, Usman Akinyemi wrote:\n> > > > On Mon, Oct 14, 2024 at 4:13 PM Usman Akinyemi\n> > > >> On Mon, Oct 14, 2024 at 2:55 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> > > >> I got this from a leftoverbit which the main issue was reported as\n> > > >> bug. https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n> > > >> For the test, I should have the test as another patch right ?\n> > >\n> > > In general you should add tests in the same commit as the code changes\n> > > that they test. In this instance I think you want to split this patch\n> > > into three, one patch for git-daemon, one for imap-send and one for the\n> > > merge marker config changes. Each patch should have a commit message\n> > > explaining the changes and whether they change the behavior of the code\n> > > (for example rejecting non-numbers) and add some tests. Note that I\n> > > don't think it is possible to test the imap-send changes but the other\n> > > two should be easy enough. The tests should be added to one of the\n> > > existing test files that are testing the code being changed.\n> > Hello,\n> > I am currently facing some issues while trying to write the test for\n> > daemon.c, I need some help on it.\n> > The start_git_daemon function inside lib-git-daemon.sh is made to\n> > allow --init-timeout, --max-connections and\n> > timeout as well as other arguments. The start_git_daemon function in\n> > lib-git-daemon.sh is used at t5570-git-daemon.sh.\n> > Basically this is my changes\n> >                 if (skip_prefix(arg, \"--timeout=\", &v)) {\n> > -                       timeout = atoi(v);\n> > +                       if (strtoul_ui(v, 10, &timeout))\n> > +                               die(\"invalid timeout '%s', expecting a\n> > non-negative integer\", v);\n> >                         continue;\n> >                 }\n> >                 if (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> > -                       init_timeout = atoi(v);\n> > +                       if (strtoul_ui(v, 10, &init_timeout))\n> > +                               die(\"invalid init-timeout '%s',\n> > expecting a non-negative integer\", v);\n> >                         continue;\n> >                 }\n> >                 if (skip_prefix(arg, \"--max-connections=\", &v)) {\n> > -                       max_connections = atoi(v);\n> > +                       if (strtol_i(v, 10, &max_connections))\n> > +                               die(\"invalid '--max-connections' '%s',\n> > expecting an integer\", v);\n> >                         if (max_connections < 0)\n> > -                               max_connections = 0;            /* unlimited */\n> > +                               max_connections = 0;  /* unlimited */\n> >                         continue;\n> >                 }\n> > What happened is that the start_git_daemon will already fail and will\n> > prevent the\n> > t5570-git-daemon.sh from starting if there is any wrong starting\n> > condition such as the new\n> > changes I added. I am finding it hard to come up with an approach to\n> > test the new change.\n>\n> I'd just not use `start_git_daemon ()` in the first place. Instead, I'd\n> invoke git-daemon(1) directly with invalid options and then observe that\n> it fails to start up with the expected error message.\n>\n> Patrick\nHello Patrick, thanks for the reply. that works, I really appreciate it.\n"},{"id":"505440","messageId":"pull.1810.v2.git.git.1729259580.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.git.git.1728774574.gitgitgadget@gmail.com","subject":"[PATCH v2 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-18T13:52:57Z","receivedAt":"2024-10-18T13:53:03Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"Changes from Version 1:\n\n * In my initial commit, I mistakenly included changes from a different\n   patch and commit. This issue has now been resolved.\n * I have split the original commit into three separate patches for better\n   clarity and organization.\n * I added corresponding tests for each of the changes to ensure proper\n   functionality.\n * In the first version, I used the following logic: if (strtoul_ui(v, 10,\n   &timeout) == 0) Based on feedback from my mentor, I improved it to:\n   (strtoul_ui(v, 10, &timeout)) and similar cases.\n\nUsman Akinyemi (3):\n  daemon: replace atoi() with strtoul_ui() and strtol_i()\n  merge: replace atoi() with strtol_i() for marker size validation\n  imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n    parsing\n\n daemon.c              | 11 +++++++----\n imap-send.c           | 13 ++++++++-----\n merge-ll.c            |  6 ++++--\n t/t5570-git-daemon.sh | 27 ++++++++++++++++++++++++++-\n t/t6406-merge-attr.sh |  7 +++++++\n 5 files changed, 52 insertions(+), 12 deletions(-)\n\n\nbase-commit: 90fe3800b92a49173530828c0a17951abd30f0e1\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1810%2FUnique-Usman%2Fr_atoi-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1810/Unique-Usman/r_atoi-v2\nPull-Request: https://github.com/git/git/pull/1810\n\nRange-diff vs v1:\n\n 1:  bfff7937cd2 < -:  ----------- t3404: avoid losing exit status with focus on `git show` and `git cat-file`\n 2:  e2cae7f3a51 < -:  ----------- t3404: replace test with test_line_count()\n -:  ----------- > 1:  a333d8a4013 daemon: replace atoi() with strtoul_ui() and strtol_i()\n -:  ----------- > 2:  5d58c150efb merge: replace atoi() with strtol_i() for marker size validation\n 3:  c93bc2d81ff ! 3:  c09c7b3df0d parse: replace atoi() with strtoul_ui() and strtol_i()\n     @@ Metadata\n      Author: Usman Akinyemi <usmanakinyemi202@gmail.com>\n      \n       ## Commit message ##\n     -    parse: replace atoi() with strtoul_ui() and strtol_i()\n     +    imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing\n      \n     -    Replace unsafe uses of atoi() with strtoul_ui() for unsigned integers\n     -    and strtol_i() for signed integers across multiple files. This change\n     -    improves error handling and prevents potential integer overflow issues.\n     -\n     -    The following files were updated:\n     -    - daemon.c: Update parsing of --timeout, --init-timeout, and\n     -      --max-connections\n     -    - imap-send.c: Improve parsing of UIDVALIDITY, UIDNEXT, APPENDUID, and\n     -      tags\n     -    - merge-ll.c: Enhance parsing of marker size in ll_merge and\n     -      ll_merge_marker_size\n     -\n     -    This change allows for better error detection when parsing integer\n     -    values from command-line arguments and IMAP responses, making the code\n     -    more robust and secure.\n     -\n     -    This is a #leftoverbit discussed here:\n     -     https://public-inbox.org/git/CAC4O8c-nuOTS=a0sVp1603KaM2bZjs+yNZzdAaa5CGTNGFE7hQ@mail.gmail.com/\n     +    Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n     +    when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n     +    Invalid values, such as those with letters,\n     +    now trigger error messages and prevent malformed status responses.\n      \n          Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n      \n     -    Cc: gitster@pobox.com\n     -    Cc: Patrick Steinhardt <ps@pks.im>\n     -    Cc: phillip.wood123@gmail.com\n     -    Cc: Christian Couder <christian.couder@gmail.com>\n     -    Cc: Eric Sunshine <sunshine@sunshineco.com>\n     -    Cc: Taylor Blau <me@ttaylorr.com>\n     -\n     - ## daemon.c ##\n     -@@ daemon.c: int cmd_main(int argc, const char **argv)\n     - \t\t\tcontinue;\n     - \t\t}\n     - \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n     --\t\t\ttimeout = atoi(v);\n     -+\t\t\tif (strtoul_ui(v, 10, &timeout) < 0) {\n     -+\t\t\t\tdie(\"'%s': not a valid integer for --timeout\", v);\n     -+\t\t\t}\n     - \t\t\tcontinue;\n     - \t\t}\n     - \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n     --\t\t\tinit_timeout = atoi(v);\n     -+\t\t\tif (strtoul_ui(v, 10, &init_timeout) < 0) {\n     -+\t\t\t\tdie(\"'%s': not a valid integer for --init-timeout\", v);\n     -+\t\t\t}\n     - \t\t\tcontinue;\n     - \t\t}\n     - \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n     --\t\t\tmax_connections = atoi(v);\n     --\t\t\tif (max_connections < 0)\n     --\t\t\t\tmax_connections = 0;\t        /* unlimited */\n     -+\t\t\tif (strtol_i(v, 10, &max_connections) != 0 || max_connections < 0) {\n     -+\t\t\t\tmax_connections = 0;  /* unlimited */\n     -+\t\t\t}\n     - \t\t\tcontinue;\n     - \t\t}\n     - \t\tif (!strcmp(arg, \"--strict-paths\")) {\n     -\n       ## imap-send.c ##\n      @@ imap-send.c: static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n       \t\treturn RESP_BAD;\n       \t}\n       \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n      -\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n     -+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) != 0) {\n     ++\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) {\n       \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n       \t\t\treturn RESP_BAD;\n       \t\t}\n       \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n      -\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n     -+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) != 0) {\n     ++\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) || !imap->uidnext) {\n       \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n       \t\t\treturn RESP_BAD;\n       \t\t}\n     @@ imap-send.c: static int parse_response_code(struct imap_store *ctx, struct imap_\n       \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n      -\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n      -\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n     -+\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) != 0) ||\n     -+\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) != 0)) {\n     ++\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) ||\n     ++\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx)) {\n       \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n       \t\t\treturn RESP_BAD;\n       \t\t}\n     @@ imap-send.c: static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *\n       \t\t\t\treturn DRV_OK;\n       \t\t} else {\n      -\t\t\ttag = atoi(arg);\n     -+\t\t\tif (strtol_i(arg, 10, &tag) != 0) {\n     ++\t\t\tif (strtol_i(arg, 10, &tag)) {\n      +\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n      +\t\t\t\treturn RESP_BAD;\n      +\t\t\t}\n       \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n       \t\t\t\tif (cmdp->tag == tag)\n       \t\t\t\t\tgoto gottag;\n     -\n     - ## merge-ll.c ##\n     -@@ merge-ll.c: enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n     - \tgit_check_attr(istate, path, check);\n     - \tll_driver_name = check->items[0].value;\n     - \tif (check->items[1].value) {\n     --\t\tmarker_size = atoi(check->items[1].value);\n     --\t\tif (marker_size <= 0)\n     -+\t\tif (strtol_i(check->items[1].value, 10, &marker_size) != 0 || marker_size <= 0)\n     - \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n     - \t}\n     - \tdriver = find_ll_merge_driver(ll_driver_name);\n     -@@ merge-ll.c: int ll_merge_marker_size(struct index_state *istate, const char *path)\n     - \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n     - \tgit_check_attr(istate, path, check);\n     - \tif (check->items[0].value) {\n     --\t\tmarker_size = atoi(check->items[0].value);\n     --\t\tif (marker_size <= 0)\n     -+\t\tif (strtol_i(check->items[0].value, 10, &marker_size) != 0 || marker_size <= 0)\n     - \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n     - \t}\n     - \treturn marker_size;\n\n-- \ngitgitgadget\n"},{"id":"505441","messageId":"a333d8a40134f4a06812fdbf85c2b011e9d3e472.1729259580.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v2.git.git.1729259580.gitgitgadget@gmail.com","subject":"[PATCH v2 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-18T13:52:58Z","receivedAt":"2024-10-18T13:53:04Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplaced atoi() with strtoul_ui() for --timeout and --init-timeout\n(non-negative integers) and with strtol_i() for --max-connections\n(signed integers). This improves error handling and input validation\nby detecting invalid values and providing clear error messages.\nUpdated tests to ensure these arguments are properly validated.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n daemon.c              | 11 +++++++----\n t/t5570-git-daemon.sh | 27 ++++++++++++++++++++++++++-\n 2 files changed, 33 insertions(+), 5 deletions(-)\n\ndiff --git a/daemon.c b/daemon.c\nindex cb946e3c95f..09a31d2344d 100644\n--- a/daemon.c\n+++ b/daemon.c\n@@ -1308,17 +1308,20 @@ int cmd_main(int argc, const char **argv)\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n-\t\t\ttimeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &timeout))\n+\t\t\t\tdie(\"invalid timeout '%s', expecting a non-negative integer\", v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n-\t\t\tinit_timeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &init_timeout))\n+\t\t\t\tdie(\"invalid init-timeout '%s', expecting a non-negative integer\", v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n-\t\t\tmax_connections = atoi(v);\n+\t\t\tif (strtol_i(v, 10, &max_connections))\n+\t\t\t\tdie(\"invalid max-connections '%s', expecting an integer\", v);\n \t\t\tif (max_connections < 0)\n-\t\t\t\tmax_connections = 0;\t        /* unlimited */\n+\t\t\t\tmax_connections = 0;  /* unlimited */\n \t\t\tcontinue;\n \t\t}\n \t\tif (!strcmp(arg, \"--strict-paths\")) {\ndiff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\nindex c5f08b67996..c73c2196981 100755\n--- a/t/t5570-git-daemon.sh\n+++ b/t/t5570-git-daemon.sh\n@@ -1,6 +1,6 @@\n #!/bin/sh\n \n-test_description='test fetching over git protocol'\n+test_description='test fetching over git protocol and daemon rejects invalid options'\n GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=main\n export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME\n \n@@ -8,6 +8,31 @@ TEST_PASSES_SANITIZE_LEAK=true\n . ./test-lib.sh\n \n . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n+\n+test_expect_success 'daemon rejects invalid --init-timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid init-timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --max-connections values' '\n+\ttest_must_fail git daemon --max-connections=3a 2>actual_error &&\n+\ttest_write_lines \"fatal: invalid max-connections '\\''3a'\\'', expecting an integer\" >expected &&\n+\ttest_cmp actual_error expected\n+'\n+\n start_git_daemon\n \n check_verbose_connect () {\n-- \ngitgitgadget\n\n"},{"id":"505442","messageId":"5d58c150efbed1a10e90dba10e18f8641d11a70f.1729259580.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v2.git.git.1729259580.gitgitgadget@gmail.com","subject":"[PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-18T13:52:59Z","receivedAt":"2024-10-18T13:53:04Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplaced atoi() with strtol_i() for parsing conflict-marker-size to\nimprove error handling. Invalid values, such as those containing letters\nnow trigger a clear error message.\nUpdated the test to verify invalid input handling.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n merge-ll.c            | 6 ++++--\n t/t6406-merge-attr.sh | 7 +++++++\n 2 files changed, 11 insertions(+), 2 deletions(-)\n\ndiff --git a/merge-ll.c b/merge-ll.c\nindex 8e63071922b..52870226816 100644\n--- a/merge-ll.c\n+++ b/merge-ll.c\n@@ -427,7 +427,8 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n \tgit_check_attr(istate, path, check);\n \tll_driver_name = check->items[0].value;\n \tif (check->items[1].value) {\n-\t\tmarker_size = atoi(check->items[1].value);\n+\t\tif (strtol_i(check->items[1].value, 10, &marker_size))\n+\t\t\tdie(\"invalid marker-size '%s', expecting an integer\", check->items[1].value);\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\n@@ -454,7 +455,8 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n \tgit_check_attr(istate, path, check);\n \tif (check->items[0].value) {\n-\t\tmarker_size = atoi(check->items[0].value);\n+\t\tif (strtol_i(check->items[0].value, 10, &marker_size))\n+\t\t\tdie(\"invalid marker-size '%s', expecting an integer\", check->items[0].value);\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\ndiff --git a/t/t6406-merge-attr.sh b/t/t6406-merge-attr.sh\nindex 9bf95249347..1299b30aeb1 100755\n--- a/t/t6406-merge-attr.sh\n+++ b/t/t6406-merge-attr.sh\n@@ -118,6 +118,13 @@ test_expect_success 'retry the merge with longer context' '\n \tgrep \"<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\" actual\n '\n \n+test_expect_success 'invalid conflict-marker-size 3a' '\n+    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n+    test_must_fail git checkout -m text 2>actual_error &&\n+    test_write_lines \"fatal: invalid marker-size '\\''3a'\\'', expecting an integer\" >expected &&\n+    test_cmp actual_error expected\n+'\n+\n test_expect_success 'custom merge backend' '\n \n \techo \"* merge=union\" >.gitattributes &&\n-- \ngitgitgadget\n\n"},{"id":"505443","messageId":"c09c7b3df0d7eac3069cee45cddc49a76da2503e.1729259580.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v2.git.git.1729259580.gitgitgadget@gmail.com","subject":"[PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-18T13:53:00Z","receivedAt":"2024-10-18T13:53:05Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplaced unsafe uses of atoi() with strtol_i() to improve error handling\nwhen parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\nInvalid values, such as those with letters,\nnow trigger error messages and prevent malformed status responses.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n imap-send.c | 13 ++++++++-----\n 1 file changed, 8 insertions(+), 5 deletions(-)\n\ndiff --git a/imap-send.c b/imap-send.c\nindex ec68a066877..8214df128e5 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\treturn RESP_BAD;\n \t}\n \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) || !imap->uidnext) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\tfor (; isspace((unsigned char)*p); p++);\n \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n-\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) ||\n+\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx)) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n \t\t\tif (!tcmd)\n \t\t\t\treturn DRV_OK;\n \t\t} else {\n-\t\t\ttag = atoi(arg);\n+\t\t\tif (strtol_i(arg, 10, &tag)) {\n+\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n+\t\t\t\treturn RESP_BAD;\n+\t\t\t}\n \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n \t\t\t\tif (cmdp->tag == tag)\n \t\t\t\t\tgoto gottag;\n-- \ngitgitgadget\n"},{"id":"505468","messageId":"ZxLRdu4cPDgPLpCz@nand.local","threadId":"62325","inReplyTo":"pull.1810.v2.git.git.1729259580.gitgitgadget@gmail.com","subject":"Re: [PATCH v2 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-18T21:21:58Z","receivedAt":"2024-10-18T21:22:01Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Fri, Oct 18, 2024 at 01:52:57PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> Changes from Version 1:\n>\n>  * In my initial commit, I mistakenly included changes from a different\n>    patch and commit. This issue has now been resolved.\n\nShould we treat this as a new series, then? Or is this a true reroll of\nthe previous round and should be kept together?\n\n>  * I have split the original commit into three separate patches for better\n>    clarity and organization.\n>  * I added corresponding tests for each of the changes to ensure proper\n>    functionality.\n>  * In the first version, I used the following logic: if (strtoul_ui(v, 10,\n>    &timeout) == 0) Based on feedback from my mentor, I improved it to:\n>    (strtoul_ui(v, 10, &timeout)) and similar cases.\n>\n> Usman Akinyemi (3):\n>   daemon: replace atoi() with strtoul_ui() and strtol_i()\n>   merge: replace atoi() with strtol_i() for marker size validation\n>   imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n>     parsing\n\nThanks,\nTaylor\n"},{"id":"505470","messageId":"CAPSxiM_dcpmpAsbo9wmXSDqGWXxU==QLfdVpowK5Xv-LW9iLCQ@mail.gmail.com","threadId":"62325","inReplyTo":"ZxLRdu4cPDgPLpCz@nand.local","subject":"Re: [PATCH v2 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-18T21:29:44Z","receivedAt":"2024-10-18T21:29:57Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Fri, Oct 18, 2024 at 9:22 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Fri, Oct 18, 2024 at 01:52:57PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > Changes from Version 1:\n> >\n> >  * In my initial commit, I mistakenly included changes from a different\n> >    patch and commit. This issue has now been resolved.\n>\n> Should we treat this as a new series, then? Or is this a true reroll of\n> the previous round and should be kept together?\nHello Taylor,\nYeah, this should be treated as a new series different from the two below.\n - t3404: replace test with test_line_count()\n - t3404: avoid losing exit status with focus on `git show` and `git cat-file`\nThank you.\n>\n> >  * I have split the original commit into three separate patches for better\n> >    clarity and organization.\n> >  * I added corresponding tests for each of the changes to ensure proper\n> >    functionality.\n> >  * In the first version, I used the following logic: if (strtoul_ui(v, 10,\n> >    &timeout) == 0) Based on feedback from my mentor, I improved it to:\n> >    (strtoul_ui(v, 10, &timeout)) and similar cases.\n> >\n> > Usman Akinyemi (3):\n> >   daemon: replace atoi() with strtoul_ui() and strtol_i()\n> >   merge: replace atoi() with strtol_i() for marker size validation\n> >   imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n> >     parsing\n>\n> Thanks,\n> Taylor\n"},{"id":"505472","messageId":"ZxLUvlN9f7QP+kdY@nand.local","threadId":"62325","inReplyTo":"CAPSxiM_dcpmpAsbo9wmXSDqGWXxU==QLfdVpowK5Xv-LW9iLCQ@mail.gmail.com","subject":"Re: [PATCH v2 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-18T21:35:58Z","receivedAt":"2024-10-18T21:36:02Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Fri, Oct 18, 2024 at 09:29:44PM +0000, Usman Akinyemi wrote:\n> On Fri, Oct 18, 2024 at 9:22 PM Taylor Blau <me@ttaylorr.com> wrote:\n> >\n> > On Fri, Oct 18, 2024 at 01:52:57PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > Changes from Version 1:\n> > >\n> > >  * In my initial commit, I mistakenly included changes from a different\n> > >    patch and commit. This issue has now been resolved.\n> >\n> > Should we treat this as a new series, then? Or is this a true reroll of\n> > the previous round and should be kept together?\n> Hello Taylor,\n> Yeah, this should be treated as a new series different from the two below.\n>  - t3404: replace test with test_line_count()\n>  - t3404: avoid losing exit status with focus on `git show` and `git cat-file`\n\nGotcha. So in the original ua/t3404-cleanup series from my tree, I\nshould drop the third and final patch:\n\n  parse: replace atoi() with strtoul_ui() and strtol_i()\n\n?\n\nThanks,\nTaylor\n"},{"id":"505476","messageId":"CAPSxiM_K_=My1KnUjdBpb8k8LGQRBU_8kB6wy8mLcNdawVVTiw@mail.gmail.com","threadId":"62325","inReplyTo":"ZxLUvlN9f7QP+kdY@nand.local","subject":"Re: [PATCH v2 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-18T21:43:39Z","receivedAt":"2024-10-18T21:43:51Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Fri, Oct 18, 2024 at 9:36 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Fri, Oct 18, 2024 at 09:29:44PM +0000, Usman Akinyemi wrote:\n> > On Fri, Oct 18, 2024 at 9:22 PM Taylor Blau <me@ttaylorr.com> wrote:\n> > >\n> > > On Fri, Oct 18, 2024 at 01:52:57PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > Changes from Version 1:\n> > > >\n> > > >  * In my initial commit, I mistakenly included changes from a different\n> > > >    patch and commit. This issue has now been resolved.\n> > >\n> > > Should we treat this as a new series, then? Or is this a true reroll of\n> > > the previous round and should be kept together?\n> > Hello Taylor,\n> > Yeah, this should be treated as a new series different from the two below.\n> >  - t3404: replace test with test_line_count()\n> >  - t3404: avoid losing exit status with focus on `git show` and `git cat-file`\n>\n> Gotcha. So in the original ua/t3404-cleanup series from my tree, I\n> should drop the third and final patch:\n>\n>   parse: replace atoi() with strtoul_ui() and strtol_i()\n>\n> ?\nHello Taylor,\nYeah, exactly. Thank you.\nUsman Akinyemi.\n>\n> Thanks,\n> Taylor\n"},{"id":"505666","messageId":"ZxZHFY4cXQ1lA4QU@pks.im","threadId":"62325","inReplyTo":"a333d8a40134f4a06812fdbf85c2b011e9d3e472.1729259580.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v2 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-21T12:20:43Z","receivedAt":"2024-10-21T12:20:51Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Fri, Oct 18, 2024 at 01:52:58PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> diff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\n> index c5f08b67996..c73c2196981 100755\n> --- a/t/t5570-git-daemon.sh\n> +++ b/t/t5570-git-daemon.sh\n> @@ -1,6 +1,6 @@\n>  #!/bin/sh\n>  \n> -test_description='test fetching over git protocol'\n> +test_description='test fetching over git protocol and daemon rejects invalid options'\n>  GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=main\n>  export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME\n>  \n\nHum. I think the test description can stay as-is, as we don't typically\nmention all the exact details of what we test in a test suite. But I\nalso don't mind this too much.\n\n> @@ -8,6 +8,31 @@ TEST_PASSES_SANITIZE_LEAK=true\n>  . ./test-lib.sh\n>  \n>  . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n> +\n> +test_expect_success 'daemon rejects invalid --init-timeout values' '\n> +\tfor arg in \"3a\" \"-3\"\n> +\tdo\n> +\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n> +\t\ttest_write_lines \"fatal: invalid init-timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n\nYou can use ${SQ} instead of '\\'', also for the other two tests.\n\nPatrick\n"},{"id":"505667","messageId":"ZxZHH-oHE7g09xIR@pks.im","threadId":"62325","inReplyTo":"5d58c150efbed1a10e90dba10e18f8641d11a70f.1729259580.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-21T12:20:47Z","receivedAt":"2024-10-21T12:20:52Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> \n> Replaced atoi() with strtol_i() for parsing conflict-marker-size to\n> improve error handling. Invalid values, such as those containing letters\n> now trigger a clear error message.\n> Updated the test to verify invalid input handling.\n\nWhen starting a new paragraph we typically have an empty line between\nthe paragraphs. We also tend to write commit messages as if instructing\nthe code to change. So instead of \"Replaced atoi() with...\" you'd say\n\"Replace atoi() with\", and instead of \"Updated the test...\", you'd say\n\"Update the test ...\".\n\nThe same applies to your other commits, as well.\n\n> \n> diff --git a/merge-ll.c b/merge-ll.c\n> index 8e63071922b..52870226816 100644\n> --- a/merge-ll.c\n> +++ b/merge-ll.c\n> @@ -427,7 +427,8 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n>  \tgit_check_attr(istate, path, check);\n>  \tll_driver_name = check->items[0].value;\n>  \tif (check->items[1].value) {\n> -\t\tmarker_size = atoi(check->items[1].value);\n> +\t\tif (strtol_i(check->items[1].value, 10, &marker_size))\n> +\t\t\tdie(\"invalid marker-size '%s', expecting an integer\", check->items[1].value);\n>  \t\tif (marker_size <= 0)\n>  \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n>  \t}\n> @@ -454,7 +455,8 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n>  \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n>  \tgit_check_attr(istate, path, check);\n>  \tif (check->items[0].value) {\n> -\t\tmarker_size = atoi(check->items[0].value);\n> +\t\tif (strtol_i(check->items[0].value, 10, &marker_size))\n> +\t\t\tdie(\"invalid marker-size '%s', expecting an integer\", check->items[0].value);\n>  \t\tif (marker_size <= 0)\n>  \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n>  \t}\n\nThese are a bit curious. As your test demonstrates, we retrieve the\nvalues from the \"gitattributes\" file. And given that the file tends to be\nchecked into the repository, you can now basically break somebody elses\ncommands by having an invalid value in there.\n\nThat makes me think that we likely shouldn't die here. We may print a\nwarning, but other than that we should likely continue and use the\nDEFAULT_CONFLICT_MARKER_SIZE.\n\nPatrick\n"},{"id":"505668","messageId":"ZxZHIk-gH0Onpt15@pks.im","threadId":"62325","inReplyTo":"c09c7b3df0d7eac3069cee45cddc49a76da2503e.1729259580.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-21T12:20:50Z","receivedAt":"2024-10-21T12:20:54Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Fri, Oct 18, 2024 at 01:53:00PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> \n> Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n> when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n> Invalid values, such as those with letters,\n> now trigger error messages and prevent malformed status responses.\n\nThe line break after \"letters,\" is a bit funny.\n\nIt would also be nice to point out why this commit doesn't add any new\ntests. I guess the answer is that we don't have any tests for\ngit-imap-send(1) at all, which is too bad, but a fair excuse and not a\nproblem of your patch. So introducing such tests would be too much to\nask.\n\nPatrick\n"},{"id":"505670","messageId":"CAPSxiM-wLZfA1+1zvfjW-PN=Zpjrgy3KR9c_jrb=we7vhvoUYg@mail.gmail.com","threadId":"62325","inReplyTo":"ZxZHIk-gH0Onpt15@pks.im","subject":"Re: [PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T12:27:05Z","receivedAt":"2024-10-21T12:27:18Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 12:20 PM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Fri, Oct 18, 2024 at 01:53:00PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n> > when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n> > Invalid values, such as those with letters,\n> > now trigger error messages and prevent malformed status responses.\n>\n> The line break after \"letters,\" is a bit funny.\nI just noticed that I will change it.\n>\n> It would also be nice to point out why this commit doesn't add any new\n> tests. I guess the answer is that we don't have any tests for\n> git-imap-send(1) at all, which is too bad, but a fair excuse and not a\n> problem of your patch. So introducing such tests would be too much to\n> ask.\nI can try, but, why was it not introduced before, is there a reason ?\n>\n> Patrick\n"},{"id":"505671","messageId":"ZxZKQrc0Ch_YA1IV@pks.im","threadId":"62325","inReplyTo":"CAPSxiM-wLZfA1+1zvfjW-PN=Zpjrgy3KR9c_jrb=we7vhvoUYg@mail.gmail.com","subject":"Re: [PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-21T12:34:10Z","receivedAt":"2024-10-21T12:34:21Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Mon, Oct 21, 2024 at 12:27:05PM +0000, Usman Akinyemi wrote:\n> On Mon, Oct 21, 2024 at 12:20 PM Patrick Steinhardt <ps@pks.im> wrote:\n> >\n> > On Fri, Oct 18, 2024 at 01:53:00PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > >\n> > > Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n> > > when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n> > > Invalid values, such as those with letters,\n> > > now trigger error messages and prevent malformed status responses.\n> >\n> > The line break after \"letters,\" is a bit funny.\n> I just noticed that I will change it.\n> >\n> > It would also be nice to point out why this commit doesn't add any new\n> > tests. I guess the answer is that we don't have any tests for\n> > git-imap-send(1) at all, which is too bad, but a fair excuse and not a\n> > problem of your patch. So introducing such tests would be too much to\n> > ask.\n> I can try, but, why was it not introduced before, is there a reason ?\n\nI think it's mostly that we'd have to have an IMAP server available to\ntest sending emails properly, so the test setup would be comparatively\ninvolved. Nobody felt like doing that, and thus we don't have any tests\n:)\n\nPatrick\n"},{"id":"505687","messageId":"CAPSxiM_+4ZaaiyvWDVwXf3tnt08otsx=1dcJJtQsL7h59dO8kQ@mail.gmail.com","threadId":"62325","inReplyTo":"ZxZHFY4cXQ1lA4QU@pks.im","subject":"Re: [PATCH v2 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T13:43:53Z","receivedAt":"2024-10-21T13:44:04Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 1:36 PM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Fri, Oct 18, 2024 at 01:52:58PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > diff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\n> > index c5f08b67996..c73c2196981 100755\n> > --- a/t/t5570-git-daemon.sh\n> > +++ b/t/t5570-git-daemon.sh\n> > @@ -1,6 +1,6 @@\n> >  #!/bin/sh\n> >\n> > -test_description='test fetching over git protocol'\n> > +test_description='test fetching over git protocol and daemon rejects invalid options'\n> >  GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=main\n> >  export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME\n> >\n>\n> Hum. I think the test description can stay as-is, as we don't typically\n> mention all the exact details of what we test in a test suite. But I\n> also don't mind this too much.\nOhh, noted. I just thought the test description does not have anything\nabout merge.\n>\n> > @@ -8,6 +8,31 @@ TEST_PASSES_SANITIZE_LEAK=true\n> >  . ./test-lib.sh\n> >\n> >  . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n> > +\n> > +test_expect_success 'daemon rejects invalid --init-timeout values' '\n> > +     for arg in \"3a\" \"-3\"\n> > +     do\n> > +             test_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n> > +             test_write_lines \"fatal: invalid init-timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n>\n> You can use ${SQ} instead of '\\'', also for the other two tests.\nWill make a change now.\n>\n> Patrick\n"},{"id":"505697","messageId":"CAPSxiM_BCz2n-uOOSRk3AsVp-Y7R+1XNfVRt6dH6=fWVBZ6cBw@mail.gmail.com","threadId":"62325","inReplyTo":"ZxZHH-oHE7g09xIR@pks.im","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T14:24:38Z","receivedAt":"2024-10-21T14:24:50Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 2:01 PM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Replaced atoi() with strtol_i() for parsing conflict-marker-size to\n> > improve error handling. Invalid values, such as those containing letters\n> > now trigger a clear error message.\n> > Updated the test to verify invalid input handling.\n>\n> When starting a new paragraph we typically have an empty line between\n> the paragraphs. We also tend to write commit messages as if instructing\n> the code to change. So instead of \"Replaced atoi() with...\" you'd say\n> \"Replace atoi() with\", and instead of \"Updated the test...\", you'd say\n> \"Update the test ...\".\n>\n> The same applies to your other commits, as well.\n>\n> >\n> > diff --git a/merge-ll.c b/merge-ll.c\n> > index 8e63071922b..52870226816 100644\n> > --- a/merge-ll.c\n> > +++ b/merge-ll.c\n> > @@ -427,7 +427,8 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n> >       git_check_attr(istate, path, check);\n> >       ll_driver_name = check->items[0].value;\n> >       if (check->items[1].value) {\n> > -             marker_size = atoi(check->items[1].value);\n> > +             if (strtol_i(check->items[1].value, 10, &marker_size))\n> > +                     die(\"invalid marker-size '%s', expecting an integer\", check->items[1].value);\n> >               if (marker_size <= 0)\n> >                       marker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n> >       }\n> > @@ -454,7 +455,8 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n> >               check = attr_check_initl(\"conflict-marker-size\", NULL);\n> >       git_check_attr(istate, path, check);\n> >       if (check->items[0].value) {\n> > -             marker_size = atoi(check->items[0].value);\n> > +             if (strtol_i(check->items[0].value, 10, &marker_size))\n> > +                     die(\"invalid marker-size '%s', expecting an integer\", check->items[0].value);\n> >               if (marker_size <= 0)\n> >                       marker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n> >       }\n>\n> These are a bit curious. As your test demonstrates, we retrieve the\n> values from the \"gitattributes\" file. And given that the file tends to be\n> checked into the repository, you can now basically break somebody elses\n> commands by having an invalid value in there.\n>\n> That makes me think that we likely shouldn't die here. We may print a\n> warning, but other than that we should likely continue and use the\n> DEFAULT_CONFLICT_MARKER_SIZE.\n>\nOhh, I understand. Philip suggested this. For the warning, will I just\nuse printf statement or what function to print the statement ?\nAlso, how do I test the print warning statement ?\n\nThank you.\nUsman Akinyemi.\n> Patrick\n"},{"id":"505699","messageId":"CAPSxiM9BuOCXSstZCm5B9dR6D0rg5vB23T0xNT3xAOJihQy0BA@mail.gmail.com","threadId":"62325","inReplyTo":"ZxZKQrc0Ch_YA1IV@pks.im","subject":"Re: [PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T14:38:40Z","receivedAt":"2024-10-21T14:38:52Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 2:01 PM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Mon, Oct 21, 2024 at 12:27:05PM +0000, Usman Akinyemi wrote:\n> > On Mon, Oct 21, 2024 at 12:20 PM Patrick Steinhardt <ps@pks.im> wrote:\n> > >\n> > > On Fri, Oct 18, 2024 at 01:53:00PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > > >\n> > > > Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n> > > > when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n> > > > Invalid values, such as those with letters,\n> > > > now trigger error messages and prevent malformed status responses.\n> > >\n> > > The line break after \"letters,\" is a bit funny.\n> > I just noticed that I will change it.\n> > >\n> > > It would also be nice to point out why this commit doesn't add any new\n> > > tests. I guess the answer is that we don't have any tests for\n> > > git-imap-send(1) at all, which is too bad, but a fair excuse and not a\n> > > problem of your patch. So introducing such tests would be too much to\n> > > ask.\n> > I can try, but, why was it not introduced before, is there a reason ?\n>\n> I think it's mostly that we'd have to have an IMAP server available to\n> test sending emails properly, so the test setup would be comparatively\n> involved. Nobody felt like doing that, and thus we don't have any tests\n> :)\nOhh, I see. I have not set up an IMAP server before though. I can take\nit up but might require some level of guidance.\n\nUsman Akinyemi.\n>\n> Patrick\n"},{"id":"505705","messageId":"ZxaAVgJa1VCj/9Ge@nand.local","threadId":"62325","inReplyTo":"CAPSxiM_+4ZaaiyvWDVwXf3tnt08otsx=1dcJJtQsL7h59dO8kQ@mail.gmail.com","subject":"Re: [PATCH v2 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-21T16:24:54Z","receivedAt":"2024-10-21T16:24:56Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Mon, Oct 21, 2024 at 01:43:53PM +0000, Usman Akinyemi wrote:\n> > Hum. I think the test description can stay as-is, as we don't typically\n> > mention all the exact details of what we test in a test suite. But I\n> > also don't mind this too much.\n>\n> Ohh, noted. I just thought the test description does not have anything\n> about merge.\n\nLet's leave it as-is, unless you can come up with a new description that\nis a little shorter. Absent of that, I think the current description is\nfine as-is.\n\n> > > @@ -8,6 +8,31 @@ TEST_PASSES_SANITIZE_LEAK=true\n> > >  . ./test-lib.sh\n> > >\n> > >  . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n> > > +\n> > > +test_expect_success 'daemon rejects invalid --init-timeout values' '\n> > > +     for arg in \"3a\" \"-3\"\n> > > +     do\n> > > +             test_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n> > > +             test_write_lines \"fatal: invalid init-timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n> >\n> > You can use ${SQ} instead of '\\'', also for the other two tests.\n>\n> Will make a change now.\n\nThanks. ${SQ} is much preferred here, and makes the resulting test much\neasier to read.\n\nThanks,\nTaylor\n"},{"id":"505706","messageId":"CAPSxiM_3msts1md99umicv+D7wAmKqW541-7oxW44fF65NKpTA@mail.gmail.com","threadId":"62325","inReplyTo":"ZxaAVgJa1VCj/9Ge@nand.local","subject":"Re: [PATCH v2 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T16:34:18Z","receivedAt":"2024-10-21T16:34:30Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 4:24 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Mon, Oct 21, 2024 at 01:43:53PM +0000, Usman Akinyemi wrote:\n> > > Hum. I think the test description can stay as-is, as we don't typically\n> > > mention all the exact details of what we test in a test suite. But I\n> > > also don't mind this too much.\n> >\n> > Ohh, noted. I just thought the test description does not have anything\n> > about merge.\n>\n> Let's leave it as-is, unless you can come up with a new description that\n> is a little shorter. Absent of that, I think the current description is\n> fine as-is.\nNoted andThanks.\n>\n> > > > @@ -8,6 +8,31 @@ TEST_PASSES_SANITIZE_LEAK=true\n> > > >  . ./test-lib.sh\n> > > >\n> > > >  . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n> > > > +\n> > > > +test_expect_success 'daemon rejects invalid --init-timeout values' '\n> > > > +     for arg in \"3a\" \"-3\"\n> > > > +     do\n> > > > +             test_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n> > > > +             test_write_lines \"fatal: invalid init-timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n> > >\n> > > You can use ${SQ} instead of '\\'', also for the other two tests.\n> >\n> > Will make a change now.\n>\n> Thanks. ${SQ} is much preferred here, and makes the resulting test much\n> easier to read.\nNoted and thanks.\n>\n> Thanks,\n> Taylor\n"},{"id":"505707","messageId":"ZxaClmjrLAJiVxNJ@nand.local","threadId":"62325","inReplyTo":"CAPSxiM_BCz2n-uOOSRk3AsVp-Y7R+1XNfVRt6dH6=fWVBZ6cBw@mail.gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-21T16:34:30Z","receivedAt":"2024-10-21T16:34:33Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Mon, Oct 21, 2024 at 02:24:38PM +0000, Usman Akinyemi wrote:\n> On Mon, Oct 21, 2024 at 2:01 PM Patrick Steinhardt <ps@pks.im> wrote:\n> >\n> > On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > >\n> > > Replaced atoi() with strtol_i() for parsing conflict-marker-size to\n> > > improve error handling. Invalid values, such as those containing letters\n> > > now trigger a clear error message.\n> > > Updated the test to verify invalid input handling.\n> >\n> > When starting a new paragraph we typically have an empty line between\n> > the paragraphs. We also tend to write commit messages as if instructing\n> > the code to change. So instead of \"Replaced atoi() with...\" you'd say\n> > \"Replace atoi() with\", and instead of \"Updated the test...\", you'd say\n> > \"Update the test ...\".\n> >\n> > The same applies to your other commits, as well.\n\nThanks for noting, Patrick.\n\n> > These are a bit curious. As your test demonstrates, we retrieve the\n> > values from the \"gitattributes\" file. And given that the file tends to be\n> > checked into the repository, you can now basically break somebody elses\n> > commands by having an invalid value in there.\n> >\n> > That makes me think that we likely shouldn't die here. We may print a\n> > warning, but other than that we should likely continue and use the\n> > DEFAULT_CONFLICT_MARKER_SIZE.\n> >\n>\n> Ohh, I understand. Philip suggested this. For the warning, will I just\n> use printf statement or what function to print the statement ?\n> Also, how do I test the print warning statement ?\n\nYou can use warning() instead of die(), which will also print the\nmessage to stderr. You can redirect stderr to a separate file in your\ntest, and then grep or test_grep that to ensure that you see the warning\nmessage.\n\nThese messages should also be marked for translation (with `_()`), so\nthe result will look something like:\n\n    if (strtol_i(check->items[0].value, 10, &marker_size))\n            warning(_(\"invalid marker-size '%s', expecting an integer\"),\n                    check->items[0].value);\n\nThanks,\nTaylor\n"},{"id":"505708","messageId":"ZxaC3o05fZNOWsf/@nand.local","threadId":"62325","inReplyTo":"CAPSxiM9BuOCXSstZCm5B9dR6D0rg5vB23T0xNT3xAOJihQy0BA@mail.gmail.com","subject":"Re: [PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-21T16:35:42Z","receivedAt":"2024-10-21T16:35:46Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Mon, Oct 21, 2024 at 02:38:40PM +0000, Usman Akinyemi wrote:\n> On Mon, Oct 21, 2024 at 2:01 PM Patrick Steinhardt <ps@pks.im> wrote:\n> >\n> > On Mon, Oct 21, 2024 at 12:27:05PM +0000, Usman Akinyemi wrote:\n> > > On Mon, Oct 21, 2024 at 12:20 PM Patrick Steinhardt <ps@pks.im> wrote:\n> > > >\n> > > > On Fri, Oct 18, 2024 at 01:53:00PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > > > >\n> > > > > Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n> > > > > when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n> > > > > Invalid values, such as those with letters,\n> > > > > now trigger error messages and prevent malformed status responses.\n> > > >\n> > > > The line break after \"letters,\" is a bit funny.\n> > > I just noticed that I will change it.\n> > > >\n> > > > It would also be nice to point out why this commit doesn't add any new\n> > > > tests. I guess the answer is that we don't have any tests for\n> > > > git-imap-send(1) at all, which is too bad, but a fair excuse and not a\n> > > > problem of your patch. So introducing such tests would be too much to\n> > > > ask.\n> > > I can try, but, why was it not introduced before, is there a reason ?\n> >\n> > I think it's mostly that we'd have to have an IMAP server available to\n> > test sending emails properly, so the test setup would be comparatively\n> > involved. Nobody felt like doing that, and thus we don't have any tests\n> > :)\n> Ohh, I see. I have not set up an IMAP server before though. I can take\n> it up but might require some level of guidance.\n\nI think what Patrick is saying is that it's probably not worth the\neffort to do so for an automated test, especially if the code change is\ntrivial by comparison.\n\nThanks,\nTaylor\n"},{"id":"505709","messageId":"CAPSxiM8VeXZFdTP3QBwLHbJvXZ2W3vBxn8P=kcDcfFQzaHSHUA@mail.gmail.com","threadId":"62325","inReplyTo":"ZxaC3o05fZNOWsf/@nand.local","subject":"Re: [PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T16:36:49Z","receivedAt":"2024-10-21T16:37:02Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 4:35 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Mon, Oct 21, 2024 at 02:38:40PM +0000, Usman Akinyemi wrote:\n> > On Mon, Oct 21, 2024 at 2:01 PM Patrick Steinhardt <ps@pks.im> wrote:\n> > >\n> > > On Mon, Oct 21, 2024 at 12:27:05PM +0000, Usman Akinyemi wrote:\n> > > > On Mon, Oct 21, 2024 at 12:20 PM Patrick Steinhardt <ps@pks.im> wrote:\n> > > > >\n> > > > > On Fri, Oct 18, 2024 at 01:53:00PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > > > > >\n> > > > > > Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n> > > > > > when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n> > > > > > Invalid values, such as those with letters,\n> > > > > > now trigger error messages and prevent malformed status responses.\n> > > > >\n> > > > > The line break after \"letters,\" is a bit funny.\n> > > > I just noticed that I will change it.\n> > > > >\n> > > > > It would also be nice to point out why this commit doesn't add any new\n> > > > > tests. I guess the answer is that we don't have any tests for\n> > > > > git-imap-send(1) at all, which is too bad, but a fair excuse and not a\n> > > > > problem of your patch. So introducing such tests would be too much to\n> > > > > ask.\n> > > > I can try, but, why was it not introduced before, is there a reason ?\n> > >\n> > > I think it's mostly that we'd have to have an IMAP server available to\n> > > test sending emails properly, so the test setup would be comparatively\n> > > involved. Nobody felt like doing that, and thus we don't have any tests\n> > > :)\n> > Ohh, I see. I have not set up an IMAP server before though. I can take\n> > it up but might require some level of guidance.\n>\n> I think what Patrick is saying is that it's probably not worth the\n> effort to do so for an automated test, especially if the code change is\n> trivial by comparison.\n>\n> Thanks,\n> Taylor\nThanks Taylor. Noted.\n"},{"id":"505710","messageId":"CAPSxiM9_110YrQiNnYH8rmYd0r13CVX4_97mw_-Wy8k9HJ8cUQ@mail.gmail.com","threadId":"62325","inReplyTo":"ZxaClmjrLAJiVxNJ@nand.local","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T16:39:40Z","receivedAt":"2024-10-21T16:39:52Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 4:34 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Mon, Oct 21, 2024 at 02:24:38PM +0000, Usman Akinyemi wrote:\n> > On Mon, Oct 21, 2024 at 2:01 PM Patrick Steinhardt <ps@pks.im> wrote:\n> > >\n> > > On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > > >\n> > > > Replaced atoi() with strtol_i() for parsing conflict-marker-size to\n> > > > improve error handling. Invalid values, such as those containing letters\n> > > > now trigger a clear error message.\n> > > > Updated the test to verify invalid input handling.\n> > >\n> > > When starting a new paragraph we typically have an empty line between\n> > > the paragraphs. We also tend to write commit messages as if instructing\n> > > the code to change. So instead of \"Replaced atoi() with...\" you'd say\n> > > \"Replace atoi() with\", and instead of \"Updated the test...\", you'd say\n> > > \"Update the test ...\".\n> > >\n> > > The same applies to your other commits, as well.\n>\n> Thanks for noting, Patrick.\n>\n> > > These are a bit curious. As your test demonstrates, we retrieve the\n> > > values from the \"gitattributes\" file. And given that the file tends to be\n> > > checked into the repository, you can now basically break somebody elses\n> > > commands by having an invalid value in there.\n> > >\n> > > That makes me think that we likely shouldn't die here. We may print a\n> > > warning, but other than that we should likely continue and use the\n> > > DEFAULT_CONFLICT_MARKER_SIZE.\n> > >\n> >\n> > Ohh, I understand. Philip suggested this. For the warning, will I just\n> > use printf statement or what function to print the statement ?\n> > Also, how do I test the print warning statement ?\n>\n> You can use warning() instead of die(), which will also print the\n> message to stderr. You can redirect stderr to a separate file in your\n> test, and then grep or test_grep that to ensure that you see the warning\n> message.\n>\n> These messages should also be marked for translation (with `_()`), so\n> the result will look something like:\n>\n>     if (strtol_i(check->items[0].value, 10, &marker_size))\n>             warning(_(\"invalid marker-size '%s', expecting an integer\"),\n>                     check->items[0].value);\n>\n> Thanks,\n> Taylor\nThank you, I will make the changes.\n"},{"id":"505718","messageId":"CAPSxiM9W+YcJqxnkFmOpBcHuHab6V_vn+ibwgq-vCNWZUXPw=w@mail.gmail.com","threadId":"62325","inReplyTo":"ZxaClmjrLAJiVxNJ@nand.local","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-21T18:00:55Z","receivedAt":"2024-10-21T18:01:07Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Mon, Oct 21, 2024 at 4:34 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Mon, Oct 21, 2024 at 02:24:38PM +0000, Usman Akinyemi wrote:\n> > On Mon, Oct 21, 2024 at 2:01 PM Patrick Steinhardt <ps@pks.im> wrote:\n> > >\n> > > On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > > >\n> > > > Replaced atoi() with strtol_i() for parsing conflict-marker-size to\n> > > > improve error handling. Invalid values, such as those containing letters\n> > > > now trigger a clear error message.\n> > > > Updated the test to verify invalid input handling.\n> > >\n> > > When starting a new paragraph we typically have an empty line between\n> > > the paragraphs. We also tend to write commit messages as if instructing\n> > > the code to change. So instead of \"Replaced atoi() with...\" you'd say\n> > > \"Replace atoi() with\", and instead of \"Updated the test...\", you'd say\n> > > \"Update the test ...\".\n> > >\n> > > The same applies to your other commits, as well.\n>\n> Thanks for noting, Patrick.\n>\n> > > These are a bit curious. As your test demonstrates, we retrieve the\n> > > values from the \"gitattributes\" file. And given that the file tends to be\n> > > checked into the repository, you can now basically break somebody elses\n> > > commands by having an invalid value in there.\n> > >\n> > > That makes me think that we likely shouldn't die here. We may print a\n> > > warning, but other than that we should likely continue and use the\n> > > DEFAULT_CONFLICT_MARKER_SIZE.\n> > >\n> >\n> > Ohh, I understand. Philip suggested this. For the warning, will I just\n> > use printf statement or what function to print the statement ?\n> > Also, how do I test the print warning statement ?\n>\n> You can use warning() instead of die(), which will also print the\n> message to stderr. You can redirect stderr to a separate file in your\n> test, and then grep or test_grep that to ensure that you see the warning\n> message.\n>\n> These messages should also be marked for translation (with `_()`), so\n> the result will look something like:\n>\n>     if (strtol_i(check->items[0].value, 10, &marker_size))\n>             warning(_(\"invalid marker-size '%s', expecting an integer\"),\n>                     check->items[0].value);\nHi Taylor, when I try to use this warning(_, I was getting some error\nIn the editor\nwarning(_(\"invalid marker-size '%s', expecting an integer\"),\ncheck->items[1].value); Incompatible integer to pointer conversion\npassing 'int' to parameter of type 'const char *'\nwhile I tried run make\n\nerge-ll.c: In function ‘ll_merge’:\nmerge-ll.c:432:33: error: implicit declaration of function ‘_’\n[-Wimplicit-function-declaration]\n  432 |                         warning(_(\"invalid marker-size '%s',\nexpecting an integer\"), check->items[1].value);\n      |                                 ^\nmerge-ll.c:432:33: error: passing argument 1 of ‘warning’ makes\npointer from integer without a cast [-Wint-conversion]\n  432 |                         warning(_(\"invalid marker-size '%s',\nexpecting an integer\"), check->items[1].value);\n      |\n^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n      |                                 |\n      |                                 int\nIn file included from merge-ll.c:9:\ngit-compat-util.h:691:26: note: expected ‘const char *’ but argument\nis of type ‘int’\n  691 | void warning(const char *err, ...) __attribute__((format\n(printf, 1, 2)));\n      |              ~~~~~~~~~~~~^~~\n\n\n>\n> Thanks,\n> Taylor\n"},{"id":"505737","messageId":"ZxayARcJ1nBKt2mh@nand.local","threadId":"62325","inReplyTo":"CAPSxiM9W+YcJqxnkFmOpBcHuHab6V_vn+ibwgq-vCNWZUXPw=w@mail.gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-21T19:56:49Z","receivedAt":"2024-10-21T19:56:51Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Mon, Oct 21, 2024 at 06:00:55PM +0000, Usman Akinyemi wrote:\n> Hi Taylor, when I try to use this warning(_, I was getting some error\n> In the editor\n\nLet's see...\n\n> erge-ll.c: In function ‘ll_merge’:\n> merge-ll.c:432:33: error: implicit declaration of function ‘_’\n> [-Wimplicit-function-declaration]\n>   432 |                         warning(_(\"invalid marker-size '%s',\n> expecting an integer\"), check->items[1].value);\n>       |                                 ^\n\nYour compiler is correctly indicating that the error is that the\nfunction '_' is undefined, likely because this file does not include\n\"gettext.h\", which is what defines that function.\n\nThanks,\nTaylor\n"},{"id":"505804","messageId":"pull.1810.v3.git.git.1729574624.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v2.git.git.1729259580.gitgitgadget@gmail.com","subject":"[PATCH v3 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T05:23:40Z","receivedAt":"2024-10-22T05:23:47Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"Changes from Version 2:\n\n * Use ${SQ} for single quote.\n * Change the commit message from Updated to Update, Replaced to Replace.\n * Format the commit message well.\n * Used warning for when marker size contains letters instead of die to\n   avoid breaking somebody elses command as the test involve adding\n   conflict_marker_size into .gitiattribute which is commited into the\n   repository.\n\nUsman Akinyemi (3):\n  daemon: replace atoi() with strtoul_ui() and strtol_i()\n  merge: replace atoi() with strtol_i() for marker size validation\n  imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n    parsing\n\n daemon.c              | 11 +++++++----\n imap-send.c           | 13 ++++++++-----\n merge-ll.c            | 11 +++++++++--\n t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n t/t6406-merge-attr.sh |  6 ++++++\n 5 files changed, 56 insertions(+), 11 deletions(-)\n\n\nbase-commit: 90fe3800b92a49173530828c0a17951abd30f0e1\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1810%2FUnique-Usman%2Fr_atoi-v3\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1810/Unique-Usman/r_atoi-v3\nPull-Request: https://github.com/git/git/pull/1810\n\nRange-diff vs v2:\n\n 1:  a333d8a4013 ! 1:  e292b82d6a1 daemon: replace atoi() with strtoul_ui() and strtol_i()\n     @@ Metadata\n       ## Commit message ##\n          daemon: replace atoi() with strtoul_ui() and strtol_i()\n      \n     -    Replaced atoi() with strtoul_ui() for --timeout and --init-timeout\n     +    Replace atoi() with strtoul_ui() for --timeout and --init-timeout\n          (non-negative integers) and with strtol_i() for --max-connections\n          (signed integers). This improves error handling and input validation\n          by detecting invalid values and providing clear error messages.\n     -    Updated tests to ensure these arguments are properly validated.\n     +    Update tests to ensure these arguments are properly validated.\n      \n          Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n      \n     @@ daemon.c: int cmd_main(int argc, const char **argv)\n       \t\tif (!strcmp(arg, \"--strict-paths\")) {\n      \n       ## t/t5570-git-daemon.sh ##\n     -@@\n     - #!/bin/sh\n     - \n     --test_description='test fetching over git protocol'\n     -+test_description='test fetching over git protocol and daemon rejects invalid options'\n     - GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=main\n     - export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME\n     - \n      @@ t/t5570-git-daemon.sh: TEST_PASSES_SANITIZE_LEAK=true\n       . ./test-lib.sh\n       \n     @@ t/t5570-git-daemon.sh: TEST_PASSES_SANITIZE_LEAK=true\n      +\tfor arg in \"3a\" \"-3\"\n      +\tdo\n      +\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n     -+\t\ttest_write_lines \"fatal: invalid init-timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n     ++\t\ttest_write_lines \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n      +\t\ttest_cmp actual_error expected || return 1\n      +\tdone\n      +'\n     @@ t/t5570-git-daemon.sh: TEST_PASSES_SANITIZE_LEAK=true\n      +\tfor arg in \"3a\" \"-3\"\n      +\tdo\n      +\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n     -+\t\ttest_write_lines \"fatal: invalid timeout '\\''$arg'\\'', expecting a non-negative integer\" >expected &&\n     ++\t\ttest_write_lines \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n      +\t\ttest_cmp actual_error expected || return 1\n      +\tdone\n      +'\n      +\n      +test_expect_success 'daemon rejects invalid --max-connections values' '\n     ++\targ='3a' &&\n      +\ttest_must_fail git daemon --max-connections=3a 2>actual_error &&\n     -+\ttest_write_lines \"fatal: invalid max-connections '\\''3a'\\'', expecting an integer\" >expected &&\n     ++\ttest_write_lines \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" >expected &&\n      +\ttest_cmp actual_error expected\n      +'\n      +\n 2:  5d58c150efb ! 2:  2ad3b0faa05 merge: replace atoi() with strtol_i() for marker size validation\n     @@ Metadata\n       ## Commit message ##\n          merge: replace atoi() with strtol_i() for marker size validation\n      \n     -    Replaced atoi() with strtol_i() for parsing conflict-marker-size to\n     +    Replace atoi() with strtol_i() for parsing conflict-marker-size to\n          improve error handling. Invalid values, such as those containing letters\n          now trigger a clear error message.\n     -    Updated the test to verify invalid input handling.\n     +    Update the test to verify invalid input handling.\n      \n          Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n      \n       ## merge-ll.c ##\n     +@@\n     + #include \"merge-ll.h\"\n     + #include \"quote.h\"\n     + #include \"strbuf.h\"\n     ++#include \"gettext.h\"\n     + \n     + struct ll_merge_driver;\n     + \n      @@ merge-ll.c: enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n       \tgit_check_attr(istate, path, check);\n       \tll_driver_name = check->items[0].value;\n       \tif (check->items[1].value) {\n      -\t\tmarker_size = atoi(check->items[1].value);\n     -+\t\tif (strtol_i(check->items[1].value, 10, &marker_size))\n     -+\t\t\tdie(\"invalid marker-size '%s', expecting an integer\", check->items[1].value);\n     ++\t\tif (strtol_i(check->items[1].value, 10, &marker_size)) {\n     ++\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n     ++\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[1].value);\n     ++\t\t}\n       \t\tif (marker_size <= 0)\n       \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n       \t}\n     @@ merge-ll.c: int ll_merge_marker_size(struct index_state *istate, const char *pat\n       \tgit_check_attr(istate, path, check);\n       \tif (check->items[0].value) {\n      -\t\tmarker_size = atoi(check->items[0].value);\n     -+\t\tif (strtol_i(check->items[0].value, 10, &marker_size))\n     -+\t\t\tdie(\"invalid marker-size '%s', expecting an integer\", check->items[0].value);\n     ++\t\tif (strtol_i(check->items[0].value, 10, &marker_size)) {\n     ++\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n     ++\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[0].value);\n     ++\t\t}\n       \t\tif (marker_size <= 0)\n       \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n       \t}\n     @@ t/t6406-merge-attr.sh: test_expect_success 'retry the merge with longer context'\n       \n      +test_expect_success 'invalid conflict-marker-size 3a' '\n      +    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n     -+    test_must_fail git checkout -m text 2>actual_error &&\n     -+    test_write_lines \"fatal: invalid marker-size '\\''3a'\\'', expecting an integer\" >expected &&\n     -+    test_cmp actual_error expected\n     ++    git checkout -m text 2>error &&\n     ++    test_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" error\n      +'\n      +\n       test_expect_success 'custom merge backend' '\n 3:  c09c7b3df0d ! 3:  d0aa756d2d0 imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing\n     @@ Metadata\n       ## Commit message ##\n          imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing\n      \n     -    Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n     +    Replace unsafe uses of atoi() with strtol_i() to improve error handling\n          when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n     -    Invalid values, such as those with letters,\n     -    now trigger error messages and prevent malformed status responses.\n     +    Invalid values, such as those with letters, now trigger error messages and\n     +    prevent malformed status responses.\n     +    I did not add any test for this commit as we do not have any test\n     +    for git-imap-send(1) at this point.\n      \n          Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n      \n\n-- \ngitgitgadget\n"},{"id":"505805","messageId":"e292b82d6a1d46990477a043901fa9c56bc00023.1729574624.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v3.git.git.1729574624.gitgitgadget@gmail.com","subject":"[PATCH v3 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T05:23:41Z","receivedAt":"2024-10-22T05:23:48Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtoul_ui() for --timeout and --init-timeout\n(non-negative integers) and with strtol_i() for --max-connections\n(signed integers). This improves error handling and input validation\nby detecting invalid values and providing clear error messages.\nUpdate tests to ensure these arguments are properly validated.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n daemon.c              | 11 +++++++----\n t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n 2 files changed, 33 insertions(+), 4 deletions(-)\n\ndiff --git a/daemon.c b/daemon.c\nindex cb946e3c95f..09a31d2344d 100644\n--- a/daemon.c\n+++ b/daemon.c\n@@ -1308,17 +1308,20 @@ int cmd_main(int argc, const char **argv)\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n-\t\t\ttimeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &timeout))\n+\t\t\t\tdie(\"invalid timeout '%s', expecting a non-negative integer\", v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n-\t\t\tinit_timeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &init_timeout))\n+\t\t\t\tdie(\"invalid init-timeout '%s', expecting a non-negative integer\", v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n-\t\t\tmax_connections = atoi(v);\n+\t\t\tif (strtol_i(v, 10, &max_connections))\n+\t\t\t\tdie(\"invalid max-connections '%s', expecting an integer\", v);\n \t\t\tif (max_connections < 0)\n-\t\t\t\tmax_connections = 0;\t        /* unlimited */\n+\t\t\t\tmax_connections = 0;  /* unlimited */\n \t\t\tcontinue;\n \t\t}\n \t\tif (!strcmp(arg, \"--strict-paths\")) {\ndiff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\nindex c5f08b67996..722ddb8b7fa 100755\n--- a/t/t5570-git-daemon.sh\n+++ b/t/t5570-git-daemon.sh\n@@ -8,6 +8,32 @@ TEST_PASSES_SANITIZE_LEAK=true\n . ./test-lib.sh\n \n . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n+\n+test_expect_success 'daemon rejects invalid --init-timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --max-connections values' '\n+\targ='3a' &&\n+\ttest_must_fail git daemon --max-connections=3a 2>actual_error &&\n+\ttest_write_lines \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" >expected &&\n+\ttest_cmp actual_error expected\n+'\n+\n start_git_daemon\n \n check_verbose_connect () {\n-- \ngitgitgadget\n\n"},{"id":"505806","messageId":"2ad3b0faa058afeee5c6b86b4bce334e77993dac.1729574624.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v3.git.git.1729574624.gitgitgadget@gmail.com","subject":"[PATCH v3 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T05:23:42Z","receivedAt":"2024-10-22T05:23:48Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtol_i() for parsing conflict-marker-size to\nimprove error handling. Invalid values, such as those containing letters\nnow trigger a clear error message.\nUpdate the test to verify invalid input handling.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n merge-ll.c            | 11 +++++++++--\n t/t6406-merge-attr.sh |  6 ++++++\n 2 files changed, 15 insertions(+), 2 deletions(-)\n\ndiff --git a/merge-ll.c b/merge-ll.c\nindex 8e63071922b..62fc625552d 100644\n--- a/merge-ll.c\n+++ b/merge-ll.c\n@@ -15,6 +15,7 @@\n #include \"merge-ll.h\"\n #include \"quote.h\"\n #include \"strbuf.h\"\n+#include \"gettext.h\"\n \n struct ll_merge_driver;\n \n@@ -427,7 +428,10 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n \tgit_check_attr(istate, path, check);\n \tll_driver_name = check->items[0].value;\n \tif (check->items[1].value) {\n-\t\tmarker_size = atoi(check->items[1].value);\n+\t\tif (strtol_i(check->items[1].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[1].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\n@@ -454,7 +458,10 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n \tgit_check_attr(istate, path, check);\n \tif (check->items[0].value) {\n-\t\tmarker_size = atoi(check->items[0].value);\n+\t\tif (strtol_i(check->items[0].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[0].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\ndiff --git a/t/t6406-merge-attr.sh b/t/t6406-merge-attr.sh\nindex 9bf95249347..c2a9cf03808 100755\n--- a/t/t6406-merge-attr.sh\n+++ b/t/t6406-merge-attr.sh\n@@ -118,6 +118,12 @@ test_expect_success 'retry the merge with longer context' '\n \tgrep \"<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\" actual\n '\n \n+test_expect_success 'invalid conflict-marker-size 3a' '\n+    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n+    git checkout -m text 2>error &&\n+    test_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" error\n+'\n+\n test_expect_success 'custom merge backend' '\n \n \techo \"* merge=union\" >.gitattributes &&\n-- \ngitgitgadget\n\n"},{"id":"505807","messageId":"d0aa756d2d07f6fdb7450b9b6baddd2ea2c99a7b.1729574624.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v3.git.git.1729574624.gitgitgadget@gmail.com","subject":"[PATCH v3 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T05:23:43Z","receivedAt":"2024-10-22T05:23:50Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace unsafe uses of atoi() with strtol_i() to improve error handling\nwhen parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\nInvalid values, such as those with letters, now trigger error messages and\nprevent malformed status responses.\nI did not add any test for this commit as we do not have any test\nfor git-imap-send(1) at this point.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n imap-send.c | 13 ++++++++-----\n 1 file changed, 8 insertions(+), 5 deletions(-)\n\ndiff --git a/imap-send.c b/imap-send.c\nindex ec68a066877..8214df128e5 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\treturn RESP_BAD;\n \t}\n \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) || !imap->uidnext) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\tfor (; isspace((unsigned char)*p); p++);\n \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n-\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) ||\n+\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx)) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n \t\t\tif (!tcmd)\n \t\t\t\treturn DRV_OK;\n \t\t} else {\n-\t\t\ttag = atoi(arg);\n+\t\t\tif (strtol_i(arg, 10, &tag)) {\n+\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n+\t\t\t\treturn RESP_BAD;\n+\t\t\t}\n \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n \t\t\t\tif (cmdp->tag == tag)\n \t\t\t\t\tgoto gottag;\n-- \ngitgitgadget\n"},{"id":"505828","messageId":"CAPSxiM9Ae4zK7R61=pByoaaaeA=4x77SufTmrsa-Huwsj7EQ-A@mail.gmail.com","threadId":"62325","inReplyTo":"ZxZKQrc0Ch_YA1IV@pks.im","subject":"Re: [PATCH v2 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-22T13:43:08Z","receivedAt":"2024-10-22T13:43:19Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Tue, Oct 22, 2024 at 7:21 AM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Mon, Oct 21, 2024 at 12:27:05PM +0000, Usman Akinyemi wrote:\n> > On Mon, Oct 21, 2024 at 12:20 PM Patrick Steinhardt <ps@pks.im> wrote:\n> > >\n> > > On Fri, Oct 18, 2024 at 01:53:00PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > > >\n> > > > Replaced unsafe uses of atoi() with strtol_i() to improve error handling\n> > > > when parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\n> > > > Invalid values, such as those with letters,\n> > > > now trigger error messages and prevent malformed status responses.\n> > >\n> > > The line break after \"letters,\" is a bit funny.\n> > I just noticed that I will change it.\n> > >\n> > > It would also be nice to point out why this commit doesn't add any new\n> > > tests. I guess the answer is that we don't have any tests for\n> > > git-imap-send(1) at all, which is too bad, but a fair excuse and not a\n> > > problem of your patch. So introducing such tests would be too much to\n> > > ask.\n> > I can try, but, why was it not introduced before, is there a reason ?\n>\n> I think it's mostly that we'd have to have an IMAP server available to\n> test sending emails properly, so the test setup would be comparatively\n> involved. Nobody felt like doing that, and thus we don't have any tests\n> :)\n>\n> Patrick\n>\nI made all these changes in version 3 of the patch. Thank you.\n"},{"id":"505839","messageId":"ZxfRIIcd2H4S3i3+@nand.local","threadId":"62325","inReplyTo":"e292b82d6a1d46990477a043901fa9c56bc00023.1729574624.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v3 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-22T16:21:52Z","receivedAt":"2024-10-22T16:21:54Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Tue, Oct 22, 2024 at 05:23:41AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> diff --git a/daemon.c b/daemon.c\n> index cb946e3c95f..09a31d2344d 100644\n> --- a/daemon.c\n> +++ b/daemon.c\n> @@ -1308,17 +1308,20 @@ int cmd_main(int argc, const char **argv)\n>  \t\t\tcontinue;\n>  \t\t}\n>  \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n> -\t\t\ttimeout = atoi(v);\n> +\t\t\tif (strtoul_ui(v, 10, &timeout))\n> +\t\t\t\tdie(\"invalid timeout '%s', expecting a non-negative integer\", v);\n\nThe conversion you made to both (a) use warning() and (b) mark the\nstring for translation in the second patch were good, but I would have\nexpected to see them here as well.\n\nPerhaps leaving this one as a die() makes sense, because we are taking\ndirect input from the user, so invoking 'git daemon' with bogus options\nshould result in us dying. But these strings should be marked as\ntranslate-able regardless.\n\nThanks,\nTaylor\n"},{"id":"505872","messageId":"CAPSxiM_YbO_AamPb7kmMEK8icSQ2YqqupFoSLHeCMNXsjGtoEQ@mail.gmail.com","threadId":"62325","inReplyTo":"ZxfRIIcd2H4S3i3+@nand.local","subject":"Re: [PATCH v3 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-22T22:06:54Z","receivedAt":"2024-10-22T22:07:06Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Tue, Oct 22, 2024 at 4:21 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Tue, Oct 22, 2024 at 05:23:41AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > diff --git a/daemon.c b/daemon.c\n> > index cb946e3c95f..09a31d2344d 100644\n> > --- a/daemon.c\n> > +++ b/daemon.c\n> > @@ -1308,17 +1308,20 @@ int cmd_main(int argc, const char **argv)\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--timeout=\", &v)) {\n> > -                     timeout = atoi(v);\n> > +                     if (strtoul_ui(v, 10, &timeout))\n> > +                             die(\"invalid timeout '%s', expecting a non-negative integer\", v);\n>\n> The conversion you made to both (a) use warning() and (b) mark the\n> string for translation in the second patch were good, but I would have\n> expected to see them here as well.\n>\n> Perhaps leaving this one as a die() makes sense, because we are taking\n> direct input from the user, so invoking 'git daemon' with bogus options\n> should result in us dying. But these strings should be marked as\n> translate-able regardless.\nAs you said, since the git daemon takes direct input from the user,\ncompared to the other which takes input from .gitattributes leaving as\ndie is okay here. I have marked it as translate-able in my fourth\npatch. Thank you very much for the review.\nUsman Akinyemi.\n>\n> Thanks,\n> Taylor\n"},{"id":"505873","messageId":"pull.1810.v4.git.git.1729634937.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v3.git.git.1729574624.gitgitgadget@gmail.com","subject":"[PATCH v4 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T22:08:54Z","receivedAt":"2024-10-22T22:09:01Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"Changes from Version 3:\n\n * Mark the error message strings as translate-able.\n\nUsman Akinyemi (3):\n  daemon: replace atoi() with strtoul_ui() and strtol_i()\n  merge: replace atoi() with strtol_i() for marker size validation\n  imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n    parsing\n\n daemon.c              | 12 ++++++++----\n imap-send.c           | 13 ++++++++-----\n merge-ll.c            | 11 +++++++++--\n t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n t/t6406-merge-attr.sh |  6 ++++++\n 5 files changed, 57 insertions(+), 11 deletions(-)\n\n\nbase-commit: 90fe3800b92a49173530828c0a17951abd30f0e1\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1810%2FUnique-Usman%2Fr_atoi-v4\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1810/Unique-Usman/r_atoi-v4\nPull-Request: https://github.com/git/git/pull/1810\n\nRange-diff vs v3:\n\n 1:  e292b82d6a1 ! 1:  d9c997d7a9c daemon: replace atoi() with strtoul_ui() and strtol_i()\n     @@ Commit message\n          Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n      \n       ## daemon.c ##\n     +@@\n     + #include \"abspath.h\"\n     + #include \"config.h\"\n     + #include \"environment.h\"\n     ++#include \"gettext.h\"\n     + #include \"path.h\"\n     + #include \"pkt-line.h\"\n     + #include \"protocol.h\"\n      @@ daemon.c: int cmd_main(int argc, const char **argv)\n       \t\t\tcontinue;\n       \t\t}\n       \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n      -\t\t\ttimeout = atoi(v);\n      +\t\t\tif (strtoul_ui(v, 10, &timeout))\n     -+\t\t\t\tdie(\"invalid timeout '%s', expecting a non-negative integer\", v);\n     ++\t\t\t\tdie(_(\"invalid timeout '%s', expecting a non-negative integer\"), v);\n       \t\t\tcontinue;\n       \t\t}\n       \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n      -\t\t\tinit_timeout = atoi(v);\n      +\t\t\tif (strtoul_ui(v, 10, &init_timeout))\n     -+\t\t\t\tdie(\"invalid init-timeout '%s', expecting a non-negative integer\", v);\n     ++\t\t\t\tdie(_(\"invalid init-timeout '%s', expecting a non-negative integer\"), v);\n       \t\t\tcontinue;\n       \t\t}\n       \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n      -\t\t\tmax_connections = atoi(v);\n      +\t\t\tif (strtol_i(v, 10, &max_connections))\n     -+\t\t\t\tdie(\"invalid max-connections '%s', expecting an integer\", v);\n     ++\t\t\t\tdie(_(\"invalid max-connections '%s', expecting an integer\"), v);\n       \t\t\tif (max_connections < 0)\n      -\t\t\t\tmax_connections = 0;\t        /* unlimited */\n      +\t\t\t\tmax_connections = 0;  /* unlimited */\n 2:  2ad3b0faa05 = 2:  da9ea10e4e1 merge: replace atoi() with strtol_i() for marker size validation\n 3:  d0aa756d2d0 = 3:  8982dca646d imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing\n\n-- \ngitgitgadget\n"},{"id":"505874","messageId":"d9c997d7a9c8975ce845aa0cb4deaba22cbf3b94.1729634938.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v4.git.git.1729634937.gitgitgadget@gmail.com","subject":"[PATCH v4 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T22:08:55Z","receivedAt":"2024-10-22T22:09:02Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtoul_ui() for --timeout and --init-timeout\n(non-negative integers) and with strtol_i() for --max-connections\n(signed integers). This improves error handling and input validation\nby detecting invalid values and providing clear error messages.\nUpdate tests to ensure these arguments are properly validated.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n daemon.c              | 12 ++++++++----\n t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n 2 files changed, 34 insertions(+), 4 deletions(-)\n\ndiff --git a/daemon.c b/daemon.c\nindex cb946e3c95f..a40e435c637 100644\n--- a/daemon.c\n+++ b/daemon.c\n@@ -4,6 +4,7 @@\n #include \"abspath.h\"\n #include \"config.h\"\n #include \"environment.h\"\n+#include \"gettext.h\"\n #include \"path.h\"\n #include \"pkt-line.h\"\n #include \"protocol.h\"\n@@ -1308,17 +1309,20 @@ int cmd_main(int argc, const char **argv)\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n-\t\t\ttimeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &timeout))\n+\t\t\t\tdie(_(\"invalid timeout '%s', expecting a non-negative integer\"), v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n-\t\t\tinit_timeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &init_timeout))\n+\t\t\t\tdie(_(\"invalid init-timeout '%s', expecting a non-negative integer\"), v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n-\t\t\tmax_connections = atoi(v);\n+\t\t\tif (strtol_i(v, 10, &max_connections))\n+\t\t\t\tdie(_(\"invalid max-connections '%s', expecting an integer\"), v);\n \t\t\tif (max_connections < 0)\n-\t\t\t\tmax_connections = 0;\t        /* unlimited */\n+\t\t\t\tmax_connections = 0;  /* unlimited */\n \t\t\tcontinue;\n \t\t}\n \t\tif (!strcmp(arg, \"--strict-paths\")) {\ndiff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\nindex c5f08b67996..722ddb8b7fa 100755\n--- a/t/t5570-git-daemon.sh\n+++ b/t/t5570-git-daemon.sh\n@@ -8,6 +8,32 @@ TEST_PASSES_SANITIZE_LEAK=true\n . ./test-lib.sh\n \n . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n+\n+test_expect_success 'daemon rejects invalid --init-timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --max-connections values' '\n+\targ='3a' &&\n+\ttest_must_fail git daemon --max-connections=3a 2>actual_error &&\n+\ttest_write_lines \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" >expected &&\n+\ttest_cmp actual_error expected\n+'\n+\n start_git_daemon\n \n check_verbose_connect () {\n-- \ngitgitgadget\n\n"},{"id":"505875","messageId":"da9ea10e4e115777c16b32f1cde96a3df8c5cbb1.1729634938.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v4.git.git.1729634937.gitgitgadget@gmail.com","subject":"[PATCH v4 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T22:08:56Z","receivedAt":"2024-10-22T22:09:02Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtol_i() for parsing conflict-marker-size to\nimprove error handling. Invalid values, such as those containing letters\nnow trigger a clear error message.\nUpdate the test to verify invalid input handling.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n merge-ll.c            | 11 +++++++++--\n t/t6406-merge-attr.sh |  6 ++++++\n 2 files changed, 15 insertions(+), 2 deletions(-)\n\ndiff --git a/merge-ll.c b/merge-ll.c\nindex 8e63071922b..62fc625552d 100644\n--- a/merge-ll.c\n+++ b/merge-ll.c\n@@ -15,6 +15,7 @@\n #include \"merge-ll.h\"\n #include \"quote.h\"\n #include \"strbuf.h\"\n+#include \"gettext.h\"\n \n struct ll_merge_driver;\n \n@@ -427,7 +428,10 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n \tgit_check_attr(istate, path, check);\n \tll_driver_name = check->items[0].value;\n \tif (check->items[1].value) {\n-\t\tmarker_size = atoi(check->items[1].value);\n+\t\tif (strtol_i(check->items[1].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[1].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\n@@ -454,7 +458,10 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n \tgit_check_attr(istate, path, check);\n \tif (check->items[0].value) {\n-\t\tmarker_size = atoi(check->items[0].value);\n+\t\tif (strtol_i(check->items[0].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[0].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\ndiff --git a/t/t6406-merge-attr.sh b/t/t6406-merge-attr.sh\nindex 9bf95249347..c2a9cf03808 100755\n--- a/t/t6406-merge-attr.sh\n+++ b/t/t6406-merge-attr.sh\n@@ -118,6 +118,12 @@ test_expect_success 'retry the merge with longer context' '\n \tgrep \"<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\" actual\n '\n \n+test_expect_success 'invalid conflict-marker-size 3a' '\n+    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n+    git checkout -m text 2>error &&\n+    test_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" error\n+'\n+\n test_expect_success 'custom merge backend' '\n \n \techo \"* merge=union\" >.gitattributes &&\n-- \ngitgitgadget\n\n"},{"id":"505876","messageId":"8982dca646db72f903bd4c20416d6118da1c210c.1729634938.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v4.git.git.1729634937.gitgitgadget@gmail.com","subject":"[PATCH v4 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-22T22:08:57Z","receivedAt":"2024-10-22T22:09:03Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace unsafe uses of atoi() with strtol_i() to improve error handling\nwhen parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\nInvalid values, such as those with letters, now trigger error messages and\nprevent malformed status responses.\nI did not add any test for this commit as we do not have any test\nfor git-imap-send(1) at this point.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n imap-send.c | 13 ++++++++-----\n 1 file changed, 8 insertions(+), 5 deletions(-)\n\ndiff --git a/imap-send.c b/imap-send.c\nindex ec68a066877..8214df128e5 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\treturn RESP_BAD;\n \t}\n \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) || !imap->uidnext) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\tfor (; isspace((unsigned char)*p); p++);\n \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n-\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) ||\n+\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx)) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n \t\t\tif (!tcmd)\n \t\t\t\treturn DRV_OK;\n \t\t} else {\n-\t\t\ttag = atoi(arg);\n+\t\t\tif (strtol_i(arg, 10, &tag)) {\n+\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n+\t\t\t\treturn RESP_BAD;\n+\t\t\t}\n \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n \t\t\t\tif (cmdp->tag == tag)\n \t\t\t\t\tgoto gottag;\n-- \ngitgitgadget\n"},{"id":"505894","messageId":"ZxiSIem-Gptk6Omi@pks.im","threadId":"62325","inReplyTo":"8982dca646db72f903bd4c20416d6118da1c210c.1729634938.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v4 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-23T06:05:28Z","receivedAt":"2024-10-23T06:05:34Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Tue, Oct 22, 2024 at 10:08:57PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> @@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n>  \t\tfor (; isspace((unsigned char)*p); p++);\n>  \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n>  \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n> -\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n> -\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n> +\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) ||\n> +\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx)) {\n>  \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n>  \t\t\treturn RESP_BAD;\n>  \t\t}\n\nTwo last nits from my side, sorry that I didn't spot these earlier:\n\n  - The second line is indented incorrectly. When you have a multi-line\n    condition, subsequent lines should align with the opening brace like\n    this:\n\n\tif (something_something ||\n\t    something_else)\n\t\tfrobnicate();\n\n  - The braces around `(strtol_i() || !ctx->uidvalidity)` are a bit\n    confusing and unnecessary.\n\nOther than that I'm happy with this series, thanks!\n\nPatrick\n"},{"id":"505899","messageId":"pull.1810.v5.git.git.1729669220.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v4.git.git.1729634937.gitgitgadget@gmail.com","subject":"[PATCH v5 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-23T07:40:17Z","receivedAt":"2024-10-23T07:40:24Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"Changes from Version 4:\n\n * Fix incorrect indentation and remove unnecessary braces to avoid\n   confusion.\n\nUsman Akinyemi (3):\n  daemon: replace atoi() with strtoul_ui() and strtol_i()\n  merge: replace atoi() with strtol_i() for marker size validation\n  imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n    parsing\n\n daemon.c              | 12 ++++++++----\n imap-send.c           | 13 ++++++++-----\n merge-ll.c            | 11 +++++++++--\n t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n t/t6406-merge-attr.sh |  6 ++++++\n 5 files changed, 57 insertions(+), 11 deletions(-)\n\n\nbase-commit: 90fe3800b92a49173530828c0a17951abd30f0e1\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1810%2FUnique-Usman%2Fr_atoi-v5\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1810/Unique-Usman/r_atoi-v5\nPull-Request: https://github.com/git/git/pull/1810\n\nRange-diff vs v4:\n\n 1:  d9c997d7a9c = 1:  d9c997d7a9c daemon: replace atoi() with strtoul_ui() and strtol_i()\n 2:  da9ea10e4e1 = 2:  da9ea10e4e1 merge: replace atoi() with strtol_i() for marker size validation\n 3:  8982dca646d ! 3:  9b2b2dc8fc8 imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing\n     @@ imap-send.c: static int parse_response_code(struct imap_store *ctx, struct imap_\n       \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n      -\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n      -\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n     -+\t\tif (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) ||\n     -+\t\t\t!(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx)) {\n     ++\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity ||\n     ++\t\t    !(arg = next_arg(&s)) || strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx) {\n       \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n       \t\t\treturn RESP_BAD;\n       \t\t}\n\n-- \ngitgitgadget\n"},{"id":"505900","messageId":"d9c997d7a9c8975ce845aa0cb4deaba22cbf3b94.1729669221.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v5.git.git.1729669220.gitgitgadget@gmail.com","subject":"[PATCH v5 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-23T07:40:18Z","receivedAt":"2024-10-23T07:40:25Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtoul_ui() for --timeout and --init-timeout\n(non-negative integers) and with strtol_i() for --max-connections\n(signed integers). This improves error handling and input validation\nby detecting invalid values and providing clear error messages.\nUpdate tests to ensure these arguments are properly validated.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n daemon.c              | 12 ++++++++----\n t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n 2 files changed, 34 insertions(+), 4 deletions(-)\n\ndiff --git a/daemon.c b/daemon.c\nindex cb946e3c95f..a40e435c637 100644\n--- a/daemon.c\n+++ b/daemon.c\n@@ -4,6 +4,7 @@\n #include \"abspath.h\"\n #include \"config.h\"\n #include \"environment.h\"\n+#include \"gettext.h\"\n #include \"path.h\"\n #include \"pkt-line.h\"\n #include \"protocol.h\"\n@@ -1308,17 +1309,20 @@ int cmd_main(int argc, const char **argv)\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n-\t\t\ttimeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &timeout))\n+\t\t\t\tdie(_(\"invalid timeout '%s', expecting a non-negative integer\"), v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n-\t\t\tinit_timeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &init_timeout))\n+\t\t\t\tdie(_(\"invalid init-timeout '%s', expecting a non-negative integer\"), v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n-\t\t\tmax_connections = atoi(v);\n+\t\t\tif (strtol_i(v, 10, &max_connections))\n+\t\t\t\tdie(_(\"invalid max-connections '%s', expecting an integer\"), v);\n \t\t\tif (max_connections < 0)\n-\t\t\t\tmax_connections = 0;\t        /* unlimited */\n+\t\t\t\tmax_connections = 0;  /* unlimited */\n \t\t\tcontinue;\n \t\t}\n \t\tif (!strcmp(arg, \"--strict-paths\")) {\ndiff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\nindex c5f08b67996..722ddb8b7fa 100755\n--- a/t/t5570-git-daemon.sh\n+++ b/t/t5570-git-daemon.sh\n@@ -8,6 +8,32 @@ TEST_PASSES_SANITIZE_LEAK=true\n . ./test-lib.sh\n \n . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n+\n+test_expect_success 'daemon rejects invalid --init-timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n+\t\ttest_write_lines \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n+\t\ttest_cmp actual_error expected || return 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --max-connections values' '\n+\targ='3a' &&\n+\ttest_must_fail git daemon --max-connections=3a 2>actual_error &&\n+\ttest_write_lines \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" >expected &&\n+\ttest_cmp actual_error expected\n+'\n+\n start_git_daemon\n \n check_verbose_connect () {\n-- \ngitgitgadget\n\n"},{"id":"505901","messageId":"da9ea10e4e115777c16b32f1cde96a3df8c5cbb1.1729669221.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v5.git.git.1729669220.gitgitgadget@gmail.com","subject":"[PATCH v5 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-23T07:40:19Z","receivedAt":"2024-10-23T07:40:26Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtol_i() for parsing conflict-marker-size to\nimprove error handling. Invalid values, such as those containing letters\nnow trigger a clear error message.\nUpdate the test to verify invalid input handling.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n merge-ll.c            | 11 +++++++++--\n t/t6406-merge-attr.sh |  6 ++++++\n 2 files changed, 15 insertions(+), 2 deletions(-)\n\ndiff --git a/merge-ll.c b/merge-ll.c\nindex 8e63071922b..62fc625552d 100644\n--- a/merge-ll.c\n+++ b/merge-ll.c\n@@ -15,6 +15,7 @@\n #include \"merge-ll.h\"\n #include \"quote.h\"\n #include \"strbuf.h\"\n+#include \"gettext.h\"\n \n struct ll_merge_driver;\n \n@@ -427,7 +428,10 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n \tgit_check_attr(istate, path, check);\n \tll_driver_name = check->items[0].value;\n \tif (check->items[1].value) {\n-\t\tmarker_size = atoi(check->items[1].value);\n+\t\tif (strtol_i(check->items[1].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[1].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\n@@ -454,7 +458,10 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n \tgit_check_attr(istate, path, check);\n \tif (check->items[0].value) {\n-\t\tmarker_size = atoi(check->items[0].value);\n+\t\tif (strtol_i(check->items[0].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[0].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\ndiff --git a/t/t6406-merge-attr.sh b/t/t6406-merge-attr.sh\nindex 9bf95249347..c2a9cf03808 100755\n--- a/t/t6406-merge-attr.sh\n+++ b/t/t6406-merge-attr.sh\n@@ -118,6 +118,12 @@ test_expect_success 'retry the merge with longer context' '\n \tgrep \"<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\" actual\n '\n \n+test_expect_success 'invalid conflict-marker-size 3a' '\n+    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n+    git checkout -m text 2>error &&\n+    test_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" error\n+'\n+\n test_expect_success 'custom merge backend' '\n \n \techo \"* merge=union\" >.gitattributes &&\n-- \ngitgitgadget\n\n"},{"id":"505902","messageId":"9b2b2dc8fc890ff55586f890e41e54a5041bce62.1729669221.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v5.git.git.1729669220.gitgitgadget@gmail.com","subject":"[PATCH v5 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-23T07:40:20Z","receivedAt":"2024-10-23T07:40:28Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace unsafe uses of atoi() with strtol_i() to improve error handling\nwhen parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\nInvalid values, such as those with letters, now trigger error messages and\nprevent malformed status responses.\nI did not add any test for this commit as we do not have any test\nfor git-imap-send(1) at this point.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n imap-send.c | 13 ++++++++-----\n 1 file changed, 8 insertions(+), 5 deletions(-)\n\ndiff --git a/imap-send.c b/imap-send.c\nindex ec68a066877..488c06e6139 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\treturn RESP_BAD;\n \t}\n \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) || !imap->uidnext) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\tfor (; isspace((unsigned char)*p); p++);\n \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n-\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity ||\n+\t\t    !(arg = next_arg(&s)) || strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n \t\t\tif (!tcmd)\n \t\t\t\treturn DRV_OK;\n \t\t} else {\n-\t\t\ttag = atoi(arg);\n+\t\t\tif (strtol_i(arg, 10, &tag)) {\n+\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n+\t\t\t\treturn RESP_BAD;\n+\t\t\t}\n \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n \t\t\t\tif (cmdp->tag == tag)\n \t\t\t\t\tgoto gottag;\n-- \ngitgitgadget\n"},{"id":"505903","messageId":"CAPSxiM8vTABv-ZPe=qCNu1yFKStqZ-eKyrwdxy1+7YMetQfECw@mail.gmail.com","threadId":"62325","inReplyTo":"ZxiSIem-Gptk6Omi@pks.im","subject":"Re: [PATCH v4 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-23T07:40:46Z","receivedAt":"2024-10-23T07:40:59Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Wed, Oct 23, 2024 at 6:05 AM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Tue, Oct 22, 2024 at 10:08:57PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > @@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n> >               for (; isspace((unsigned char)*p); p++);\n> >               fprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n> >       } else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n> > -             if (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n> > -                 !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n> > +             if (!(arg = next_arg(&s)) || (strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) ||\n> > +                     !(arg = next_arg(&s)) || (strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx)) {\n> >                       fprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n> >                       return RESP_BAD;\n> >               }\n>\n> Two last nits from my side, sorry that I didn't spot these earlier:\n>\n>   - The second line is indented incorrectly. When you have a multi-line\n>     condition, subsequent lines should align with the opening brace like\n>     this:\n>\n>         if (something_something ||\n>             something_else)\n>                 frobnicate();\n>\n>   - The braces around `(strtol_i() || !ctx->uidvalidity)` are a bit\n>     confusing and unnecessary.\nThank you Patrick for bringing my attention to this.\nI fixed it now.\nUsman\n>\n> Other than that I'm happy with this series, thanks!\n>\n> Patrick\n"},{"id":"505906","messageId":"Zxi5TeHM9qD3lrbx@pks.im","threadId":"62325","inReplyTo":"pull.1810.v5.git.git.1729669220.gitgitgadget@gmail.com","subject":"Re: [PATCH v5 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-23T08:52:36Z","receivedAt":"2024-10-23T08:52:42Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Wed, Oct 23, 2024 at 07:40:17AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> Changes from Version 4:\n> \n>  * Fix incorrect indentation and remove unnecessary braces to avoid\n>    confusion.\n\nThanks, this version looks good to me!\n\nPatrick\n"},{"id":"505977","messageId":"ZxldBxx2R+fqVQZK@nand.local","threadId":"62325","inReplyTo":"d9c997d7a9c8975ce845aa0cb4deaba22cbf3b94.1729669221.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v5 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-23T20:31:03Z","receivedAt":"2024-10-23T20:31:05Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Wed, Oct 23, 2024 at 07:40:18AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>\n> Replace atoi() with strtoul_ui() for --timeout and --init-timeout\n> (non-negative integers) and with strtol_i() for --max-connections\n> (signed integers). This improves error handling and input validation\n> by detecting invalid values and providing clear error messages.\n> Update tests to ensure these arguments are properly validated.\n>\n> Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> ---\n>  daemon.c              | 12 ++++++++----\n>  t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n>  2 files changed, 34 insertions(+), 4 deletions(-)\n>\n> diff --git a/daemon.c b/daemon.c\n> index cb946e3c95f..a40e435c637 100644\n> --- a/daemon.c\n> +++ b/daemon.c\n> @@ -4,6 +4,7 @@\n>  #include \"abspath.h\"\n>  #include \"config.h\"\n>  #include \"environment.h\"\n> +#include \"gettext.h\"\n>  #include \"path.h\"\n>  #include \"pkt-line.h\"\n>  #include \"protocol.h\"\n> @@ -1308,17 +1309,20 @@ int cmd_main(int argc, const char **argv)\n>  \t\t\tcontinue;\n>  \t\t}\n>  \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n> -\t\t\ttimeout = atoi(v);\n> +\t\t\tif (strtoul_ui(v, 10, &timeout))\n> +\t\t\t\tdie(_(\"invalid timeout '%s', expecting a non-negative integer\"), v);\n>  \t\t\tcontinue;\n>  \t\t}\n>  \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> -\t\t\tinit_timeout = atoi(v);\n> +\t\t\tif (strtoul_ui(v, 10, &init_timeout))\n> +\t\t\t\tdie(_(\"invalid init-timeout '%s', expecting a non-negative integer\"), v);\n>  \t\t\tcontinue;\n>  \t\t}\n>  \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n> -\t\t\tmax_connections = atoi(v);\n> +\t\t\tif (strtol_i(v, 10, &max_connections))\n> +\t\t\t\tdie(_(\"invalid max-connections '%s', expecting an integer\"), v);\n>  \t\t\tif (max_connections < 0)\n> -\t\t\t\tmax_connections = 0;\t        /* unlimited */\n> +\t\t\t\tmax_connections = 0;  /* unlimited */\n>  \t\t\tcontinue;\n>  \t\t}\n>  \t\tif (!strcmp(arg, \"--strict-paths\")) {\n> diff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\n> index c5f08b67996..722ddb8b7fa 100755\n> --- a/t/t5570-git-daemon.sh\n> +++ b/t/t5570-git-daemon.sh\n> @@ -8,6 +8,32 @@ TEST_PASSES_SANITIZE_LEAK=true\n>  . ./test-lib.sh\n>\n>  . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n> +\n> +test_expect_success 'daemon rejects invalid --init-timeout values' '\n> +\tfor arg in \"3a\" \"-3\"\n> +\tdo\n> +\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n> +\t\ttest_write_lines \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n\nHmmph. test_write_lines is typically called like\n\n    test_write_lines 1 2 3\n\nto write a file which contains three lines where each of the arguments\nappears on its own line.\n\nBut here you pass a single argument, which causes us to write out a\nsingle line. Is there a reason for this? If not, I would expect us to\nwrite:\n\n    echo \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expect\n\nOr, perhaps even cleaner would be to do:\n\n    test_must_fail git daemon --init-timeout=\"$arg\" 2>err &&\n    test_grep \"invalid init-timeout ${SQ}$arg${SQ}\" err\n\nsince I don't think asserting on the actual error contents matching\nverbatim what we expect is adding all that much.\n\n(Also throughout you write 2>actual_err, but redirecting 2>err is more\nconcise and in convention with the rest of the test suite's style).\n\n> +\t\ttest_cmp actual_error expected || return 1\n> +\tdone\n> +'\n> +\n> +test_expect_success 'daemon rejects invalid --timeout values' '\n> +\tfor arg in \"3a\" \"-3\"\n> +\tdo\n> +\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n> +\t\ttest_write_lines \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n> +\t\ttest_cmp actual_error expected || return 1\n> +\tdone\n> +'\n> +\n> +test_expect_success 'daemon rejects invalid --max-connections values' '\n> +\targ='3a' &&\n> +\ttest_must_fail git daemon --max-connections=3a 2>actual_error &&\n> +\ttest_write_lines \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" >expected &&\n> +\ttest_cmp actual_error expected\n> +'\n> +\n\nSame notes from above in these two as well.\n\nThanks,\nTaylor\n"},{"id":"505978","messageId":"ZxldXMfsCuiyeIE8@nand.local","threadId":"62325","inReplyTo":"da9ea10e4e115777c16b32f1cde96a3df8c5cbb1.1729669221.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v5 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-23T20:32:28Z","receivedAt":"2024-10-23T20:32:30Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Wed, Oct 23, 2024 at 07:40:19AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> diff --git a/t/t6406-merge-attr.sh b/t/t6406-merge-attr.sh\n> index 9bf95249347..c2a9cf03808 100755\n> --- a/t/t6406-merge-attr.sh\n> +++ b/t/t6406-merge-attr.sh\n> @@ -118,6 +118,12 @@ test_expect_success 'retry the merge with longer context' '\n>  \tgrep \"<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\" actual\n>  '\n>\n> +test_expect_success 'invalid conflict-marker-size 3a' '\n> +    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n> +    git checkout -m text 2>error &&\n> +    test_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" error\n> +'\n> +\n\nDo subsequent tests further down in this script depend on .gitattributes\nnot having invalid lines? If so, you may want to instead write:\n\n    cp .gitattributes .gitattributes.bak &&\n    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n    test_when_finished \"mv .gitattributes.bak .gitattributes\" &&\n\ninstead.\n\nThanks,\nTaylor\n"},{"id":"505980","messageId":"ZxldiQVBxAWbXoT4@nand.local","threadId":"62325","inReplyTo":"Zxi5TeHM9qD3lrbx@pks.im","subject":"Re: [PATCH v5 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-23T20:33:13Z","receivedAt":"2024-10-23T20:33:15Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Wed, Oct 23, 2024 at 10:52:36AM +0200, Patrick Steinhardt wrote:\n> On Wed, Oct 23, 2024 at 07:40:17AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > Changes from Version 4:\n> >\n> >  * Fix incorrect indentation and remove unnecessary braces to avoid\n> >    confusion.\n>\n> Thanks, this version looks good to me!\n\nThanks for reviewing. This one is looking pretty close, and I've moved\nit to 'jch' in my tree, but I think there are still a few lingering\ncomments that I'd like to see addressed in a subsequent round before we\nstart merging this one down.\n\nThanks,\nTaylor\n"},{"id":"505989","messageId":"CAPSxiM9r3pLrLbyDXw6bYZKy6rZ+TtPeOCwB6c=rGh_ejXqKag@mail.gmail.com","threadId":"62325","inReplyTo":"ZxldBxx2R+fqVQZK@nand.local","subject":"Re: [PATCH v5 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-24T00:23:10Z","receivedAt":"2024-10-24T00:23:24Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Wed, Oct 23, 2024 at 8:31 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Wed, Oct 23, 2024 at 07:40:18AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >\n> > Replace atoi() with strtoul_ui() for --timeout and --init-timeout\n> > (non-negative integers) and with strtol_i() for --max-connections\n> > (signed integers). This improves error handling and input validation\n> > by detecting invalid values and providing clear error messages.\n> > Update tests to ensure these arguments are properly validated.\n> >\n> > Signed-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > ---\n> >  daemon.c              | 12 ++++++++----\n> >  t/t5570-git-daemon.sh | 26 ++++++++++++++++++++++++++\n> >  2 files changed, 34 insertions(+), 4 deletions(-)\n> >\n> > diff --git a/daemon.c b/daemon.c\n> > index cb946e3c95f..a40e435c637 100644\n> > --- a/daemon.c\n> > +++ b/daemon.c\n> > @@ -4,6 +4,7 @@\n> >  #include \"abspath.h\"\n> >  #include \"config.h\"\n> >  #include \"environment.h\"\n> > +#include \"gettext.h\"\n> >  #include \"path.h\"\n> >  #include \"pkt-line.h\"\n> >  #include \"protocol.h\"\n> > @@ -1308,17 +1309,20 @@ int cmd_main(int argc, const char **argv)\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--timeout=\", &v)) {\n> > -                     timeout = atoi(v);\n> > +                     if (strtoul_ui(v, 10, &timeout))\n> > +                             die(_(\"invalid timeout '%s', expecting a non-negative integer\"), v);\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--init-timeout=\", &v)) {\n> > -                     init_timeout = atoi(v);\n> > +                     if (strtoul_ui(v, 10, &init_timeout))\n> > +                             die(_(\"invalid init-timeout '%s', expecting a non-negative integer\"), v);\n> >                       continue;\n> >               }\n> >               if (skip_prefix(arg, \"--max-connections=\", &v)) {\n> > -                     max_connections = atoi(v);\n> > +                     if (strtol_i(v, 10, &max_connections))\n> > +                             die(_(\"invalid max-connections '%s', expecting an integer\"), v);\n> >                       if (max_connections < 0)\n> > -                             max_connections = 0;            /* unlimited */\n> > +                             max_connections = 0;  /* unlimited */\n> >                       continue;\n> >               }\n> >               if (!strcmp(arg, \"--strict-paths\")) {\n> > diff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\n> > index c5f08b67996..722ddb8b7fa 100755\n> > --- a/t/t5570-git-daemon.sh\n> > +++ b/t/t5570-git-daemon.sh\n> > @@ -8,6 +8,32 @@ TEST_PASSES_SANITIZE_LEAK=true\n> >  . ./test-lib.sh\n> >\n> >  . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n> > +\n> > +test_expect_success 'daemon rejects invalid --init-timeout values' '\n> > +     for arg in \"3a\" \"-3\"\n> > +     do\n> > +             test_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n> > +             test_write_lines \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n>\n> Hmmph. test_write_lines is typically called like\n>\n>     test_write_lines 1 2 3\n>\n> to write a file which contains three lines where each of the arguments\n> appears on its own line.\n>\n> But here you pass a single argument, which causes us to write out a\n> single line. Is there a reason for this? If not, I would expect us to\n> write:\n>\n>     echo \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expect\n>\n> Or, perhaps even cleaner would be to do:\n>\n>     test_must_fail git daemon --init-timeout=\"$arg\" 2>err &&\n>     test_grep \"invalid init-timeout ${SQ}$arg${SQ}\" err\n>\nThanks and noted, I will use this approach.\nI will send a new patch to fix this.\nUsman\n> since I don't think asserting on the actual error contents matching\n> verbatim what we expect is adding all that much.\n>\n> (Also throughout you write 2>actual_err, but redirecting 2>err is more\n> concise and in convention with the rest of the test suite's style).\n>\n> > +             test_cmp actual_error expected || return 1\n> > +     done\n> > +'\n> > +\n> > +test_expect_success 'daemon rejects invalid --timeout values' '\n> > +     for arg in \"3a\" \"-3\"\n> > +     do\n> > +             test_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n> > +             test_write_lines \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n> > +             test_cmp actual_error expected || return 1\n> > +     done\n> > +'\n> > +\n> > +test_expect_success 'daemon rejects invalid --max-connections values' '\n> > +     arg='3a' &&\n> > +     test_must_fail git daemon --max-connections=3a 2>actual_error &&\n> > +     test_write_lines \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" >expected &&\n> > +     test_cmp actual_error expected\n> > +'\n> > +\n>\n> Same notes from above in these two as well.\n>\n> Thanks,\n> Taylor\n"},{"id":"505990","messageId":"CAPSxiM_itN9gHJzP4Zg6MKfLJKjgLW_o1jp0OqcAEcvn7ZcR+A@mail.gmail.com","threadId":"62325","inReplyTo":"ZxldXMfsCuiyeIE8@nand.local","subject":"Re: [PATCH v5 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-24T00:23:46Z","receivedAt":"2024-10-24T00:23:58Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Wed, Oct 23, 2024 at 8:32 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Wed, Oct 23, 2024 at 07:40:19AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > diff --git a/t/t6406-merge-attr.sh b/t/t6406-merge-attr.sh\n> > index 9bf95249347..c2a9cf03808 100755\n> > --- a/t/t6406-merge-attr.sh\n> > +++ b/t/t6406-merge-attr.sh\n> > @@ -118,6 +118,12 @@ test_expect_success 'retry the merge with longer context' '\n> >       grep \"<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\" actual\n> >  '\n> >\n> > +test_expect_success 'invalid conflict-marker-size 3a' '\n> > +    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n> > +    git checkout -m text 2>error &&\n> > +    test_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" error\n> > +'\n> > +\n>\n> Do subsequent tests further down in this script depend on .gitattributes\n> not having invalid lines? If so, you may want to instead write:\n>\n>     cp .gitattributes .gitattributes.bak &&\n>     echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n>     test_when_finished \"mv .gitattributes.bak .gitattributes\" &&\n>\n> instead.\nThanks for the review.\nUsman\n>\n> Thanks,\n> Taylor\n"},{"id":"505991","messageId":"pull.1810.v6.git.git.1729729499.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v5.git.git.1729669220.gitgitgadget@gmail.com","subject":"[PATCH v6 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-24T00:24:55Z","receivedAt":"2024-10-24T00:25:02Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"Changes from Version 5:\n\n * Save the content of .gitattributes in .gitattributes.bak before adding\n   conflict-marker-size=3a, as subsequent tests do not depend on having\n   invalid lines. Restore .gitattributes to its original state after\n   testing.\n * Use test_grep for testing failure output, as it provides a cleaner\n   approach.\n * Use err instead of actual_error for conciseness and to maintain\n   consistency with the style of the rest of the test suite.\n\nUsman Akinyemi (3):\n  daemon: replace atoi() with strtoul_ui() and strtol_i()\n  merge: replace atoi() with strtol_i() for marker size validation\n  imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n    parsing\n\n daemon.c              | 12 ++++++++----\n imap-send.c           | 13 ++++++++-----\n merge-ll.c            | 11 +++++++++--\n t/t5570-git-daemon.sh | 25 +++++++++++++++++++++++++\n t/t6406-merge-attr.sh |  8 ++++++++\n 5 files changed, 58 insertions(+), 11 deletions(-)\n\n\nbase-commit: 90fe3800b92a49173530828c0a17951abd30f0e1\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1810%2FUnique-Usman%2Fr_atoi-v6\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1810/Unique-Usman/r_atoi-v6\nPull-Request: https://github.com/git/git/pull/1810\n\nRange-diff vs v5:\n\n 1:  d9c997d7a9c ! 1:  3daedaeb260 daemon: replace atoi() with strtoul_ui() and strtol_i()\n     @@ t/t5570-git-daemon.sh: TEST_PASSES_SANITIZE_LEAK=true\n      +test_expect_success 'daemon rejects invalid --init-timeout values' '\n      +\tfor arg in \"3a\" \"-3\"\n      +\tdo\n     -+\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>actual_error &&\n     -+\t\ttest_write_lines \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n     -+\t\ttest_cmp actual_error expected || return 1\n     ++\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>err &&\n     ++\t\ttest_grep \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" err ||\n     ++\t\treturn 1\n      +\tdone\n      +'\n      +\n      +test_expect_success 'daemon rejects invalid --timeout values' '\n      +\tfor arg in \"3a\" \"-3\"\n      +\tdo\n     -+\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>actual_error &&\n     -+\t\ttest_write_lines \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" >expected &&\n     -+\t\ttest_cmp actual_error expected || return 1\n     ++\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>err &&\n     ++\t\ttest_grep \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" err ||\n     ++\t\treturn 1\n      +\tdone\n      +'\n      +\n      +test_expect_success 'daemon rejects invalid --max-connections values' '\n      +\targ='3a' &&\n     -+\ttest_must_fail git daemon --max-connections=3a 2>actual_error &&\n     -+\ttest_write_lines \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" >expected &&\n     -+\ttest_cmp actual_error expected\n     ++\ttest_must_fail git daemon --max-connections=3a 2>err &&\n     ++\ttest_grep \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" err\n      +'\n      +\n       start_git_daemon\n 2:  da9ea10e4e1 ! 2:  0ea3b349560 merge: replace atoi() with strtol_i() for marker size validation\n     @@ t/t6406-merge-attr.sh: test_expect_success 'retry the merge with longer context'\n       '\n       \n      +test_expect_success 'invalid conflict-marker-size 3a' '\n     -+    echo \"text conflict-marker-size=3a\" >>.gitattributes &&\n     -+    git checkout -m text 2>error &&\n     -+    test_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" error\n     ++\tcp .gitattributes .gitattributes.bak &&\n     ++\techo \"text conflict-marker-size=3a\" >>.gitattributes &&\n     ++\ttest_when_finished \"mv .gitattributes.bak .gitattributes\" &&\n     ++\tgit checkout -m text 2>err &&\n     ++\ttest_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" err\n      +'\n      +\n       test_expect_success 'custom merge backend' '\n 3:  9b2b2dc8fc8 = 3:  17484df5200 imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing\n\n-- \ngitgitgadget\n"},{"id":"505992","messageId":"3daedaeb260eee873c525fbfad5838c933e1e8e5.1729729499.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v6.git.git.1729729499.gitgitgadget@gmail.com","subject":"[PATCH v6 1/3] daemon: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-24T00:24:56Z","receivedAt":"2024-10-24T00:25:03Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtoul_ui() for --timeout and --init-timeout\n(non-negative integers) and with strtol_i() for --max-connections\n(signed integers). This improves error handling and input validation\nby detecting invalid values and providing clear error messages.\nUpdate tests to ensure these arguments are properly validated.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n daemon.c              | 12 ++++++++----\n t/t5570-git-daemon.sh | 25 +++++++++++++++++++++++++\n 2 files changed, 33 insertions(+), 4 deletions(-)\n\ndiff --git a/daemon.c b/daemon.c\nindex cb946e3c95f..a40e435c637 100644\n--- a/daemon.c\n+++ b/daemon.c\n@@ -4,6 +4,7 @@\n #include \"abspath.h\"\n #include \"config.h\"\n #include \"environment.h\"\n+#include \"gettext.h\"\n #include \"path.h\"\n #include \"pkt-line.h\"\n #include \"protocol.h\"\n@@ -1308,17 +1309,20 @@ int cmd_main(int argc, const char **argv)\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--timeout=\", &v)) {\n-\t\t\ttimeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &timeout))\n+\t\t\t\tdie(_(\"invalid timeout '%s', expecting a non-negative integer\"), v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--init-timeout=\", &v)) {\n-\t\t\tinit_timeout = atoi(v);\n+\t\t\tif (strtoul_ui(v, 10, &init_timeout))\n+\t\t\t\tdie(_(\"invalid init-timeout '%s', expecting a non-negative integer\"), v);\n \t\t\tcontinue;\n \t\t}\n \t\tif (skip_prefix(arg, \"--max-connections=\", &v)) {\n-\t\t\tmax_connections = atoi(v);\n+\t\t\tif (strtol_i(v, 10, &max_connections))\n+\t\t\t\tdie(_(\"invalid max-connections '%s', expecting an integer\"), v);\n \t\t\tif (max_connections < 0)\n-\t\t\t\tmax_connections = 0;\t        /* unlimited */\n+\t\t\t\tmax_connections = 0;  /* unlimited */\n \t\t\tcontinue;\n \t\t}\n \t\tif (!strcmp(arg, \"--strict-paths\")) {\ndiff --git a/t/t5570-git-daemon.sh b/t/t5570-git-daemon.sh\nindex c5f08b67996..e3df7d86410 100755\n--- a/t/t5570-git-daemon.sh\n+++ b/t/t5570-git-daemon.sh\n@@ -8,6 +8,31 @@ TEST_PASSES_SANITIZE_LEAK=true\n . ./test-lib.sh\n \n . \"$TEST_DIRECTORY\"/lib-git-daemon.sh\n+\n+test_expect_success 'daemon rejects invalid --init-timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --init-timeout=\"$arg\" 2>err &&\n+\t\ttest_grep \"fatal: invalid init-timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" err ||\n+\t\treturn 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --timeout values' '\n+\tfor arg in \"3a\" \"-3\"\n+\tdo\n+\t\ttest_must_fail git daemon --timeout=\"$arg\" 2>err &&\n+\t\ttest_grep \"fatal: invalid timeout ${SQ}$arg${SQ}, expecting a non-negative integer\" err ||\n+\t\treturn 1\n+\tdone\n+'\n+\n+test_expect_success 'daemon rejects invalid --max-connections values' '\n+\targ='3a' &&\n+\ttest_must_fail git daemon --max-connections=3a 2>err &&\n+\ttest_grep \"fatal: invalid max-connections ${SQ}$arg${SQ}, expecting an integer\" err\n+'\n+\n start_git_daemon\n \n check_verbose_connect () {\n-- \ngitgitgadget\n\n"},{"id":"505993","messageId":"0ea3b3495609deef8942899b960756d9cab6e25d.1729729499.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v6.git.git.1729729499.gitgitgadget@gmail.com","subject":"[PATCH v6 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-24T00:24:57Z","receivedAt":"2024-10-24T00:25:04Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace atoi() with strtol_i() for parsing conflict-marker-size to\nimprove error handling. Invalid values, such as those containing letters\nnow trigger a clear error message.\nUpdate the test to verify invalid input handling.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n merge-ll.c            | 11 +++++++++--\n t/t6406-merge-attr.sh |  8 ++++++++\n 2 files changed, 17 insertions(+), 2 deletions(-)\n\ndiff --git a/merge-ll.c b/merge-ll.c\nindex 8e63071922b..62fc625552d 100644\n--- a/merge-ll.c\n+++ b/merge-ll.c\n@@ -15,6 +15,7 @@\n #include \"merge-ll.h\"\n #include \"quote.h\"\n #include \"strbuf.h\"\n+#include \"gettext.h\"\n \n struct ll_merge_driver;\n \n@@ -427,7 +428,10 @@ enum ll_merge_result ll_merge(mmbuffer_t *result_buf,\n \tgit_check_attr(istate, path, check);\n \tll_driver_name = check->items[0].value;\n \tif (check->items[1].value) {\n-\t\tmarker_size = atoi(check->items[1].value);\n+\t\tif (strtol_i(check->items[1].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[1].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\n@@ -454,7 +458,10 @@ int ll_merge_marker_size(struct index_state *istate, const char *path)\n \t\tcheck = attr_check_initl(\"conflict-marker-size\", NULL);\n \tgit_check_attr(istate, path, check);\n \tif (check->items[0].value) {\n-\t\tmarker_size = atoi(check->items[0].value);\n+\t\tif (strtol_i(check->items[0].value, 10, &marker_size)) {\n+\t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n+\t\t\twarning(_(\"invalid marker-size '%s', expecting an integer\"), check->items[0].value);\n+\t\t}\n \t\tif (marker_size <= 0)\n \t\t\tmarker_size = DEFAULT_CONFLICT_MARKER_SIZE;\n \t}\ndiff --git a/t/t6406-merge-attr.sh b/t/t6406-merge-attr.sh\nindex 9bf95249347..2dfc9a873d4 100755\n--- a/t/t6406-merge-attr.sh\n+++ b/t/t6406-merge-attr.sh\n@@ -118,6 +118,14 @@ test_expect_success 'retry the merge with longer context' '\n \tgrep \"<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<\" actual\n '\n \n+test_expect_success 'invalid conflict-marker-size 3a' '\n+\tcp .gitattributes .gitattributes.bak &&\n+\techo \"text conflict-marker-size=3a\" >>.gitattributes &&\n+\ttest_when_finished \"mv .gitattributes.bak .gitattributes\" &&\n+\tgit checkout -m text 2>err &&\n+\ttest_grep \"warning: invalid marker-size ${SQ}3a${SQ}, expecting an integer\" err\n+'\n+\n test_expect_success 'custom merge backend' '\n \n \techo \"* merge=union\" >.gitattributes &&\n-- \ngitgitgadget\n\n"},{"id":"505994","messageId":"17484df5200356c9cc17cde293e501a5a88a744a.1729729499.git.gitgitgadget@gmail.com","threadId":"62325","inReplyTo":"pull.1810.v6.git.git.1729729499.gitgitgadget@gmail.com","subject":"[PATCH v6 3/3] imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT parsing","fromName":"Usman Akinyemi via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2024-10-24T00:24:58Z","receivedAt":"2024-10-24T00:25:04Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n\nReplace unsafe uses of atoi() with strtol_i() to improve error handling\nwhen parsing UIDVALIDITY, UIDNEXT, and APPENDUID in IMAP commands.\nInvalid values, such as those with letters, now trigger error messages and\nprevent malformed status responses.\nI did not add any test for this commit as we do not have any test\nfor git-imap-send(1) at this point.\n\nSigned-off-by: Usman Akinyemi <usmanakinyemi202@gmail.com>\n---\n imap-send.c | 13 ++++++++-----\n 1 file changed, 8 insertions(+), 5 deletions(-)\n\ndiff --git a/imap-send.c b/imap-send.c\nindex ec68a066877..488c06e6139 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -668,12 +668,12 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\treturn RESP_BAD;\n \t}\n \tif (!strcmp(\"UIDVALIDITY\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed UIDVALIDITY status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n \t} else if (!strcmp(\"UIDNEXT\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(imap->uidnext = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &imap->uidnext) || !imap->uidnext) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed NEXTUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -686,8 +686,8 @@ static int parse_response_code(struct imap_store *ctx, struct imap_cmd_cb *cb,\n \t\tfor (; isspace((unsigned char)*p); p++);\n \t\tfprintf(stderr, \"*** IMAP ALERT *** %s\\n\", p);\n \t} else if (cb && cb->ctx && !strcmp(\"APPENDUID\", arg)) {\n-\t\tif (!(arg = next_arg(&s)) || !(ctx->uidvalidity = atoi(arg)) ||\n-\t\t    !(arg = next_arg(&s)) || !(*(int *)cb->ctx = atoi(arg))) {\n+\t\tif (!(arg = next_arg(&s)) || strtol_i(arg, 10, &ctx->uidvalidity) || !ctx->uidvalidity ||\n+\t\t    !(arg = next_arg(&s)) || strtol_i(arg, 10, (int *)cb->ctx) || !cb->ctx) {\n \t\t\tfprintf(stderr, \"IMAP error: malformed APPENDUID status\\n\");\n \t\t\treturn RESP_BAD;\n \t\t}\n@@ -773,7 +773,10 @@ static int get_cmd_result(struct imap_store *ctx, struct imap_cmd *tcmd)\n \t\t\tif (!tcmd)\n \t\t\t\treturn DRV_OK;\n \t\t} else {\n-\t\t\ttag = atoi(arg);\n+\t\t\tif (strtol_i(arg, 10, &tag)) {\n+\t\t\t\tfprintf(stderr, \"IMAP error: malformed tag %s\\n\", arg);\n+\t\t\t\treturn RESP_BAD;\n+\t\t\t}\n \t\t\tfor (pcmdp = &imap->in_progress; (cmdp = *pcmdp); pcmdp = &cmdp->next)\n \t\t\t\tif (cmdp->tag == tag)\n \t\t\t\t\tgoto gottag;\n-- \ngitgitgadget\n"},{"id":"505995","messageId":"CAPSxiM8KbpzQuOgTG1V9rsQJ33wZy-+mGn2pGq0kS7JNMv-Wog@mail.gmail.com","threadId":"62325","inReplyTo":"ZxldiQVBxAWbXoT4@nand.local","subject":"Re: [PATCH v5 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-24T00:25:10Z","receivedAt":"2024-10-24T00:25:22Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Wed, Oct 23, 2024 at 8:33 PM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> On Wed, Oct 23, 2024 at 10:52:36AM +0200, Patrick Steinhardt wrote:\n> > On Wed, Oct 23, 2024 at 07:40:17AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > Changes from Version 4:\n> > >\n> > >  * Fix incorrect indentation and remove unnecessary braces to avoid\n> > >    confusion.\n> >\n> > Thanks, this version looks good to me!\n>\n> Thanks for reviewing. This one is looking pretty close, and I've moved\n> it to 'jch' in my tree, but I think there are still a few lingering\n> comments that I'd like to see addressed in a subsequent round before we\n> start merging this one down.\n>\nThanks to all the mentors, I really appreciate your time. I have sent\nanother round.\nUsman.\n> Thanks,\n> Taylor\n"},{"id":"506055","messageId":"ZxqL4MId4ah+OmTW@nand.local","threadId":"62325","inReplyTo":"pull.1810.v6.git.git.1729729499.gitgitgadget@gmail.com","subject":"Re: [PATCH v6 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-24T18:03:12Z","receivedAt":"2024-10-24T18:03:15Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Thu, Oct 24, 2024 at 12:24:55AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> Usman Akinyemi (3):\n>   daemon: replace atoi() with strtoul_ui() and strtol_i()\n>   merge: replace atoi() with strtol_i() for marker size validation\n>   imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n>     parsing\n\nThanks, this new round looks quite good to me. Do others have thoughts\non this, or are we ready to start merging it down?\n\nThanks,\nTaylor\n"},{"id":"506077","messageId":"Zxsncryo3cdbgxu7@pks.im","threadId":"62325","inReplyTo":"ZxqL4MId4ah+OmTW@nand.local","subject":"Re: [PATCH v6 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2024-10-25T05:06:58Z","receivedAt":"2024-10-25T05:07:07Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Thu, Oct 24, 2024 at 02:03:12PM -0400, Taylor Blau wrote:\n> On Thu, Oct 24, 2024 at 12:24:55AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > Usman Akinyemi (3):\n> >   daemon: replace atoi() with strtoul_ui() and strtol_i()\n> >   merge: replace atoi() with strtol_i() for marker size validation\n> >   imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n> >     parsing\n> \n> Thanks, this new round looks quite good to me. Do others have thoughts\n> on this, or are we ready to start merging it down?\n\nI'm happy with this version.\n\nPatrick\n"},{"id":"506080","messageId":"CAPSxiM-jFOjiX2QpJjLM-LD9ci0JMV_vvD0Y0QiPNkwS1GPfLg@mail.gmail.com","threadId":"62325","inReplyTo":"Zxsncryo3cdbgxu7@pks.im","subject":"Re: [PATCH v6 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-25T06:11:05Z","receivedAt":"2024-10-25T06:11:18Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Fri, Oct 25, 2024 at 5:07 AM Patrick Steinhardt <ps@pks.im> wrote:\n>\n> On Thu, Oct 24, 2024 at 02:03:12PM -0400, Taylor Blau wrote:\n> > On Thu, Oct 24, 2024 at 12:24:55AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > Usman Akinyemi (3):\n> > >   daemon: replace atoi() with strtoul_ui() and strtol_i()\n> > >   merge: replace atoi() with strtol_i() for marker size validation\n> > >   imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n> > >     parsing\n> >\n> > Thanks, this new round looks quite good to me. Do others have thoughts\n> > on this, or are we ready to start merging it down?\n>\n> I'm happy with this version.\n>\n> Patrick\nThanks to Patrick and Taylor, I really appreciate your time and mentorship.\n"},{"id":"506104","messageId":"Zxuu4U+5eBsrtv7A@nand.local","threadId":"62325","inReplyTo":"CAPSxiM-jFOjiX2QpJjLM-LD9ci0JMV_vvD0Y0QiPNkwS1GPfLg@mail.gmail.com","subject":"Re: [PATCH v6 0/3] parse: replace atoi() with strtoul_ui() and strtol_i()","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2024-10-25T14:44:58Z","receivedAt":"2024-10-25T14:45:03Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Fri, Oct 25, 2024 at 06:11:05AM +0000, Usman Akinyemi wrote:\n> On Fri, Oct 25, 2024 at 5:07 AM Patrick Steinhardt <ps@pks.im> wrote:\n> >\n> > On Thu, Oct 24, 2024 at 02:03:12PM -0400, Taylor Blau wrote:\n> > > On Thu, Oct 24, 2024 at 12:24:55AM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > > > Usman Akinyemi (3):\n> > > >   daemon: replace atoi() with strtoul_ui() and strtol_i()\n> > > >   merge: replace atoi() with strtol_i() for marker size validation\n> > > >   imap: replace atoi() with strtol_i() for UIDVALIDITY and UIDNEXT\n> > > >     parsing\n> > >\n> > > Thanks, this new round looks quite good to me. Do others have thoughts\n> > > on this, or are we ready to start merging it down?\n> >\n> > I'm happy with this version.\n> >\n> > Patrick\n>\n> Thanks to Patrick and Taylor, I really appreciate your time and mentorship.\n\nThanks, both, for working on and reviewing this topic.\n\nThanks,\nTaylor\n"},{"id":"506329","messageId":"e4a70501-af2d-450a-a232-4c7952196a74@gmail.com","threadId":"62325","inReplyTo":"ZxZHH-oHE7g09xIR@pks.im","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-30T15:20:06Z","receivedAt":"2024-10-30T15:20:10Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Patrick and Usman\n\nOn 21/10/2024 13:20, Patrick Steinhardt wrote:\n> On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> These are a bit curious. As your test demonstrates, we retrieve the\n> values from the \"gitattributes\" file. And given that the file tends to be\n> checked into the repository, you can now basically break somebody elses\n> commands by having an invalid value in there.\n> \n> That makes me think that we likely shouldn't die here. We may print a\n> warning, but other than that we should likely continue and use the\n> DEFAULT_CONFLICT_MARKER_SIZE.\n\nI think using a warning here is a good idea, we should probably fix the \nwhitespace attributes to do the same. If you have\n\n     * whitespace=indent-with-non-tab,tab-in-indent\n\nin .gitattributes then \"git diff\" dies with\n\n     fatal: cannot enforce both tab-in-indent and indent-with-non-tab\n\nAnyway that's not really related to this series but I thought I'd add it \nas #leftoverbits for future reference.\n\nThanks for working on this Usman, what is queued in next looks good to me.\n\nBest Wishes\n\nPhillip\n\n\n> Patrick\n> \n\n"},{"id":"506330","messageId":"CAPSxiM-X3gk4tsVSJ_dFP2EGWX_dvFnqRp0rTYvhPxqYsUeijg@mail.gmail.com","threadId":"62325","inReplyTo":"e4a70501-af2d-450a-a232-4c7952196a74@gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-30T16:19:20Z","receivedAt":"2024-10-30T16:19:32Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Wed, Oct 30, 2024 at 3:20 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> Hi Patrick and Usman\n>\n> On 21/10/2024 13:20, Patrick Steinhardt wrote:\n> > On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> >> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > These are a bit curious. As your test demonstrates, we retrieve the\n> > values from the \"gitattributes\" file. And given that the file tends to be\n> > checked into the repository, you can now basically break somebody elses\n> > commands by having an invalid value in there.\n> >\n> > That makes me think that we likely shouldn't die here. We may print a\n> > warning, but other than that we should likely continue and use the\n> > DEFAULT_CONFLICT_MARKER_SIZE.\n>\n> I think using a warning here is a good idea, we should probably fix the\n> whitespace attributes to do the same. If you have\n>\n>      * whitespace=indent-with-non-tab,tab-in-indent\n>\n> in .gitattributes then \"git diff\" dies with\n>\n>      fatal: cannot enforce both tab-in-indent and indent-with-non-tab\n>\n> Anyway that's not really related to this series but I thought I'd add it\n> as #leftoverbits for future reference.\n>\n> Thanks for working on this Usman, what is queued in next looks good to me.\nHi Philip,\n\nI just checked it. I will be glad to work on it.\n\nI also noticed that the test used for testing used a different\napproach(test_must_fail) compared to the one I wrote which used\ntest_grep. Should I change the test also ?\n\nAlso, when should someone redirect a warning/failure into a file then\nuse test_grep or just used test_must_fail ?\n\nThank you\nUsman Akinyemi\n>\n> Best Wishes\n>\n> Phillip\n>\n>\n> > Patrick\n> >\n>\n"},{"id":"506378","messageId":"3c081d3c-3f6f-45ff-b254-09f1cd6b7de5@gmail.com","threadId":"62325","inReplyTo":"CAPSxiM-X3gk4tsVSJ_dFP2EGWX_dvFnqRp0rTYvhPxqYsUeijg@mail.gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-10-31T09:58:35Z","receivedAt":"2024-10-31T09:58:38Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Usman\n\nOn 30/10/2024 16:19, Usman Akinyemi wrote:\n> On Wed, Oct 30, 2024 at 3:20 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>> On 21/10/2024 13:20, Patrick Steinhardt wrote:\n>>> On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n>>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n>>> These are a bit curious. As your test demonstrates, we retrieve the\n>>> values from the \"gitattributes\" file. And given that the file tends to be\n>>> checked into the repository, you can now basically break somebody elses\n>>> commands by having an invalid value in there.\n>>>\n>>> That makes me think that we likely shouldn't die here. We may print a\n>>> warning, but other than that we should likely continue and use the\n>>> DEFAULT_CONFLICT_MARKER_SIZE.\n>>\n>> I think using a warning here is a good idea, we should probably fix the\n>> whitespace attributes to do the same. If you have\n>>\n>>       * whitespace=indent-with-non-tab,tab-in-indent\n>>\n>> in .gitattributes then \"git diff\" dies with\n>>\n>>       fatal: cannot enforce both tab-in-indent and indent-with-non-tab\n>>\n>> Anyway that's not really related to this series but I thought I'd add it\n>> as #leftoverbits for future reference.\n>>\n>> Thanks for working on this Usman, what is queued in next looks good to me.\n> \n> I just checked it. I will be glad to work on it.\n\nIf you want to work on this that's great, but please don't feel any \nobligation to do so.\n\n> I also noticed that the test used for testing used a different\n> approach(test_must_fail) compared to the one I wrote which used\n> test_grep. Should I change the test also ?\n\nI'm not sure which test you are looking at but I assume it is using \ntest_must_fail because the command being tested is expected to die. If \nwe change the code to print a warning instead then we'd need to capture \nstderr and use test_grep or test_cmp. Note that we only want to print a \nwarning when parsing .gitattributes, the other callers of \nparse_whitespace_rule() still want to die. Also we should decide what \nvalue to use when the user provides both - neither indent-with-non-tab \nor tab-in-indent are on by default so it's not clear exactly what we \nshould do.\n\n> Also, when should someone redirect a warning/failure into a file then\n> use test_grep or just used test_must_fail ?\n\nYou must use test_must_fail if you expect a git command to fail, if you \nexpect the command to print a warning but exit successfully you should \nnot use test_must_fail. So if you expect a command to fail and print an \nerror or warning then you'd do\n\n     test_must_fail git my failing command 2>err &&\n     test_grep \"error message\" err\n\ntest_must_fail checks that the command fails, but reports an error if \nthe command is killed by a signal such as SIGSEV.\n\nBest Wishes\n\nPhillip\n\n> Thank you\n> Usman Akinyemi\n>>\n>> Best Wishes\n>>\n>> Phillip\n>>\n>>\n>>> Patrick\n>>>\n>>\n> \n\n"},{"id":"506386","messageId":"CAPSxiM8u8CdeipatHRJ8Fq_8hKHDqyTm8OCh7sR49_Bh6Ps8uQ@mail.gmail.com","threadId":"62325","inReplyTo":"3c081d3c-3f6f-45ff-b254-09f1cd6b7de5@gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-10-31T12:21:15Z","receivedAt":"2024-10-31T12:21:28Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Thu, Oct 31, 2024 at 9:58 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> Hi Usman\n>\n> On 30/10/2024 16:19, Usman Akinyemi wrote:\n> > On Wed, Oct 30, 2024 at 3:20 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> >> On 21/10/2024 13:20, Patrick Steinhardt wrote:\n> >>> On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> >>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> >>> These are a bit curious. As your test demonstrates, we retrieve the\n> >>> values from the \"gitattributes\" file. And given that the file tends to be\n> >>> checked into the repository, you can now basically break somebody elses\n> >>> commands by having an invalid value in there.\n> >>>\n> >>> That makes me think that we likely shouldn't die here. We may print a\n> >>> warning, but other than that we should likely continue and use the\n> >>> DEFAULT_CONFLICT_MARKER_SIZE.\n> >>\n> >> I think using a warning here is a good idea, we should probably fix the\n> >> whitespace attributes to do the same. If you have\n> >>\n> >>       * whitespace=indent-with-non-tab,tab-in-indent\n> >>\n> >> in .gitattributes then \"git diff\" dies with\n> >>\n> >>       fatal: cannot enforce both tab-in-indent and indent-with-non-tab\n> >>\n> >> Anyway that's not really related to this series but I thought I'd add it\n> >> as #leftoverbits for future reference.\n> >>\n> >> Thanks for working on this Usman, what is queued in next looks good to me.\n> >\n> > I just checked it. I will be glad to work on it.\n>\n> If you want to work on this that's great, but please don't feel any\n> obligation to do so.\n>\n> > I also noticed that the test used for testing used a different\n> > approach(test_must_fail) compared to the one I wrote which used\n> > test_grep. Should I change the test also ?\n>\n> I'm not sure which test you are looking at but I assume it is using\n> test_must_fail because the command being tested is expected to die. If\n> we change the code to print a warning instead then we'd need to capture\n> stderr and use test_grep or test_cmp. Note that we only want to print a\n> warning when parsing .gitattributes, the other callers of\n> parse_whitespace_rule() still want to die. Also we should decide what\n> value to use when the user provides both - neither indent-with-non-tab\n> or tab-in-indent are on by default so it's not clear exactly what we\n> should do.\nHi Philip,\n\nI understand, we will have to pick one if we are to use a warning in this case,\nindent-with-non-tab seems to be a good candidate as it is not excluded\nby default.\n\nWe can have something like this\n\n    if (rule & WS_TAB_IN_INDENT && rule & WS_INDENT_WITH_NON_TAB) {\n        warning(_(\"cannot enforce both tab-in-indent and\nindent-with-non-tab, removing tab-in-indent\"));\n        rule &= ~WS_TAB_IN_INDENT;\n    }\nand this for default\n#define WS_DEFAULT_RULE (WS_TRAILING_SPACE | WS_SPACE_BEFORE_TAB |\nWS_INDENT_WITH_NON_TAB | 8)\n\nor just leave the WS_DEFAULT_RULE as it is and remove WS_TAB_IN_INDENT\nin case both are set.\n\nwhat do you think ?\n\nThank you.\nUsman\n\n\n>\n> > Also, when should someone redirect a warning/failure into a file then\n> > use test_grep or just used test_must_fail ?\n>\n> You must use test_must_fail if you expect a git command to fail, if you\n> expect the command to print a warning but exit successfully you should\n> not use test_must_fail. So if you expect a command to fail and print an\n> error or warning then you'd do\n>\n>      test_must_fail git my failing command 2>err &&\n>      test_grep \"error message\" err\n>\n> test_must_fail checks that the command fails, but reports an error if\n> the command is killed by a signal such as SIGSEV.\nThanks for the explanation. I understand it well now.\n>\n> Best Wishes\n>\n> Phillip\n>\n> > Thank you\n> > Usman Akinyemi\n> >>\n> >> Best Wishes\n> >>\n> >> Phillip\n> >>\n> >>\n> >>> Patrick\n> >>>\n> >>\n> >\n>\n"},{"id":"506700","messageId":"CAPSxiM8q0pA-ZZ5LdUsKoz6kqWQgvEikX_fKK+icFdH1kREs6w@mail.gmail.com","threadId":"62325","inReplyTo":"CAPSxiM8u8CdeipatHRJ8Fq_8hKHDqyTm8OCh7sR49_Bh6Ps8uQ@mail.gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"Usman Akinyemi","fromEmail":"usmanakinyemi202@gmail.com","sentAt":"2024-11-06T06:05:23Z","receivedAt":"2024-11-06T06:05:36Z","isPatch":true,"sender":{"key":"usmanakinyemi202@gmail.com","avatar":"https://avatars.githubusercontent.com/u/86585626?v=4"},"body":"On Thu, Oct 31, 2024 at 12:21 PM Usman Akinyemi\n<usmanakinyemi202@gmail.com> wrote:\n>\n> On Thu, Oct 31, 2024 at 9:58 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> >\n> > Hi Usman\n> >\n> > On 30/10/2024 16:19, Usman Akinyemi wrote:\n> > > On Wed, Oct 30, 2024 at 3:20 PM Phillip Wood <phillip.wood123@gmail.com> wrote:\n> > >> On 21/10/2024 13:20, Patrick Steinhardt wrote:\n> > >>> On Fri, Oct 18, 2024 at 01:52:59PM +0000, Usman Akinyemi via GitGitGadget wrote:\n> > >>>> From: Usman Akinyemi <usmanakinyemi202@gmail.com>\n> > >>> These are a bit curious. As your test demonstrates, we retrieve the\n> > >>> values from the \"gitattributes\" file. And given that the file tends to be\n> > >>> checked into the repository, you can now basically break somebody elses\n> > >>> commands by having an invalid value in there.\n> > >>>\n> > >>> That makes me think that we likely shouldn't die here. We may print a\n> > >>> warning, but other than that we should likely continue and use the\n> > >>> DEFAULT_CONFLICT_MARKER_SIZE.\n> > >>\n> > >> I think using a warning here is a good idea, we should probably fix the\n> > >> whitespace attributes to do the same. If you have\n> > >>\n> > >>       * whitespace=indent-with-non-tab,tab-in-indent\n> > >>\n> > >> in .gitattributes then \"git diff\" dies with\n> > >>\n> > >>       fatal: cannot enforce both tab-in-indent and indent-with-non-tab\n> > >>\n> > >> Anyway that's not really related to this series but I thought I'd add it\n> > >> as #leftoverbits for future reference.\n> > >>\n> > >> Thanks for working on this Usman, what is queued in next looks good to me.\n> > >\n> > > I just checked it. I will be glad to work on it.\n> >\n> > If you want to work on this that's great, but please don't feel any\n> > obligation to do so.\n> >\n> > > I also noticed that the test used for testing used a different\n> > > approach(test_must_fail) compared to the one I wrote which used\n> > > test_grep. Should I change the test also ?\n> >\n> > I'm not sure which test you are looking at but I assume it is using\n> > test_must_fail because the command being tested is expected to die. If\n> > we change the code to print a warning instead then we'd need to capture\n> > stderr and use test_grep or test_cmp. Note that we only want to print a\n> > warning when parsing .gitattributes, the other callers of\n> > parse_whitespace_rule() still want to die. Also we should decide what\n> > value to use when the user provides both - neither indent-with-non-tab\n> > or tab-in-indent are on by default so it's not clear exactly what we\n> > should do.\n> Hi Philip,\n>\n> I understand, we will have to pick one if we are to use a warning in this case,\n> indent-with-non-tab seems to be a good candidate as it is not excluded\n> by default.\n>\n> We can have something like this\n>\n>     if (rule & WS_TAB_IN_INDENT && rule & WS_INDENT_WITH_NON_TAB) {\n>         warning(_(\"cannot enforce both tab-in-indent and\n> indent-with-non-tab, removing tab-in-indent\"));\n>         rule &= ~WS_TAB_IN_INDENT;\n>     }\n> and this for default\n> #define WS_DEFAULT_RULE (WS_TRAILING_SPACE | WS_SPACE_BEFORE_TAB |\n> WS_INDENT_WITH_NON_TAB | 8)\n>\n> or just leave the WS_DEFAULT_RULE as it is and remove WS_TAB_IN_INDENT\n> in case both are set.\n>\n> what do you think ?\n>\n> Thank you.\n> Usman\nHello,\n\nBringing attention to this.\n>\n>\n> >\n> > > Also, when should someone redirect a warning/failure into a file then\n> > > use test_grep or just used test_must_fail ?\n> >\n> > You must use test_must_fail if you expect a git command to fail, if you\n> > expect the command to print a warning but exit successfully you should\n> > not use test_must_fail. So if you expect a command to fail and print an\n> > error or warning then you'd do\n> >\n> >      test_must_fail git my failing command 2>err &&\n> >      test_grep \"error message\" err\n> >\n> > test_must_fail checks that the command fails, but reports an error if\n> > the command is killed by a signal such as SIGSEV.\n> Thanks for the explanation. I understand it well now.\n> >\n> > Best Wishes\n> >\n> > Phillip\n> >\n> > > Thank you\n> > > Usman Akinyemi\n> > >>\n> > >> Best Wishes\n> > >>\n> > >> Phillip\n> > >>\n> > >>\n> > >>> Patrick\n> > >>>\n> > >>\n> > >\n> >\n"},{"id":"506747","messageId":"e996ced2-7c0b-4d58-8318-28db07ac5a29@gmail.com","threadId":"62325","inReplyTo":"CAPSxiM8u8CdeipatHRJ8Fq_8hKHDqyTm8OCh7sR49_Bh6Ps8uQ@mail.gmail.com","subject":"Re: [PATCH v2 2/3] merge: replace atoi() with strtol_i() for marker size validation","fromName":"","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-11-06T16:03:25Z","receivedAt":"2024-11-06T16:03:28Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Usman\n\nSorry for the slow response\n\nOn 31/10/2024 12:21, Usman Akinyemi wrote:\n> On Thu, Oct 31, 2024 at 9:58 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>> On 30/10/2024 16:19, Usman Akinyemi wrote:\n>>\n>> If you want to work on this that's great, but please don't feel any\n>> obligation to do so.\n>>\n>>> I also noticed that the test used for testing used a different\n>>> approach(test_must_fail) compared to the one I wrote which used\n>>> test_grep. Should I change the test also ?\n>>\n>> I'm not sure which test you are looking at but I assume it is using\n>> test_must_fail because the command being tested is expected to die. If\n>> we change the code to print a warning instead then we'd need to capture\n>> stderr and use test_grep or test_cmp. Note that we only want to print a\n>> warning when parsing .gitattributes, the other callers of\n>> parse_whitespace_rule() still want to die. Also we should decide what\n>> value to use when the user provides both - neither indent-with-non-tab\n>> or tab-in-indent are on by default so it's not clear exactly what we\n>> should do.\n> Hi Philip,\n> \n> I understand, we will have to pick one if we are to use a warning in this case,\n> indent-with-non-tab seems to be a good candidate as it is not excluded\n> by default.\n\nI'm not sure I understand I what you mean by \"not excluded by default\".\n\n > We can have something like this>\n>      if (rule & WS_TAB_IN_INDENT && rule & WS_INDENT_WITH_NON_TAB) {\n>          warning(_(\"cannot enforce both tab-in-indent and\n> indent-with-non-tab, removing tab-in-indent\"));\n>          rule &= ~WS_TAB_IN_INDENT;\n>      }\n\nThat sounds reasonable for the cases where we want to warn rather than die.\n\n> and this for default\n> #define WS_DEFAULT_RULE (WS_TRAILING_SPACE | WS_SPACE_BEFORE_TAB |\n> WS_INDENT_WITH_NON_TAB | 8)\n> \n> or just leave the WS_DEFAULT_RULE as it is and remove WS_TAB_IN_INDENT\n> in case both are set.\n\nI don't think we want to change the default rule as it could cause \nproblems for users who rely on it.\n\nBest Wishes\n\nPhillip\n\n"}]}