{"thread":{"id":"66160","subject":"[PATCH] serve: reject valueless promisor-remote capability","startedAt":"2026-08-12T06:39:46Z","lastAt":"2026-08-13T15:28:00Z","messageCount":3,"participants":["Elijah Newren via GitGitGadget","Elijah Newren","Christian Couder"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"550347","messageId":"pull.2199.git.1786516783909.gitgitgadget@gmail.com","threadId":"66160","inReplyTo":null,"subject":"[PATCH] serve: reject valueless promisor-remote capability","fromName":"Elijah Newren via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-08-12T06:39:43Z","receivedAt":"2026-08-12T06:39:46Z","isPatch":true,"body":"From: Elijah Newren <newren@gmail.com>\n\nd460267613da (Add 'promisor-remote' capability to protocol v2,\n2025-02-18) added a receive callback which passes the capability value\ndirectly to mark_promisor_remotes_as_accepted(). However, a client can\nsend the capability name without an '=' or value, in which case\nget_capability() supplies NULL and strbuf_split_str() dereferences it.\n\nReject the missing argument before parsing it, and add a test covering\nthis case.\n\nSigned-off-by: Elijah Newren <newren@gmail.com>\n---\n    serve: reject valueless promisor-remote capability\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2199%2Fnewren%2Fpromisor-remote-require-argument-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2199/newren/promisor-remote-require-argument-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2199\n\n serve.c              |  3 +++\n t/t5701-git-serve.sh | 11 +++++++++++\n 2 files changed, 14 insertions(+)\n\ndiff --git a/serve.c b/serve.c\nindex 2b07d922b3..5a64344467 100644\n--- a/serve.c\n+++ b/serve.c\n@@ -46,6 +46,9 @@ static int promisor_remote_advertise(struct repository *r,\n static void promisor_remote_receive(struct repository *r,\n \t\t\t\t    const char *remotes)\n {\n+\tif (!remotes)\n+\t\tdie(\"promisor-remote capability requires an argument\");\n+\n \tmark_promisor_remotes_as_accepted(r, remotes);\n }\n \ndiff --git a/t/t5701-git-serve.sh b/t/t5701-git-serve.sh\nindex 9a575aa098..d888cc5c3c 100755\n--- a/t/t5701-git-serve.sh\n+++ b/t/t5701-git-serve.sh\n@@ -71,6 +71,17 @@ test_expect_success 'request invalid capability' '\n \ttest_grep \"unknown capability\" err\n '\n \n+test_expect_success 'promisor-remote capability requires an argument' '\n+\ttest-tool pkt-line pack >in <<-EOF &&\n+\tcommand=ls-refs\n+\tobject-format=$(test_oid algo)\n+\tpromisor-remote\n+\t0000\n+\tEOF\n+\ttest_must_fail test-tool serve-v2 --stateless-rpc 2>err <in &&\n+\ttest_grep \"promisor-remote capability requires an argument\" err\n+'\n+\n test_expect_success 'request with no command' '\n \ttest-tool pkt-line pack >in <<-EOF &&\n \tagent=git/test\n\nbase-commit: 2c78326f810173a4f3aefd8021f1e07575412481\n-- \ngitgitgadget\n"},{"id":"550452","messageId":"CABPp-BGKfojr8wbQdkSegm_bL5r0t51_+qc7k74JMoKp4MDw3g@mail.gmail.com","threadId":"66160","inReplyTo":"pull.2199.git.1786516783909.gitgitgadget@gmail.com","subject":"Re: [PATCH] serve: reject valueless promisor-remote capability","fromName":"Elijah Newren","fromEmail":"newren@gmail.com","sentAt":"2026-08-12T21:27:43Z","receivedAt":"2026-08-12T21:27:57Z","isPatch":true,"body":"On Tue, Aug 11, 2026 at 11:39 PM Elijah Newren via GitGitGadget\n<gitgitgadget@gmail.com> wrote:\n>\n> From: Elijah Newren <newren@gmail.com>\n>\n> d460267613da (Add 'promisor-remote' capability to protocol v2,\n> 2025-02-18) added a receive callback which passes the capability value\n> directly to mark_promisor_remotes_as_accepted(). However, a client can\n> send the capability name without an '=' or value, in which case\n> get_capability() supplies NULL and strbuf_split_str() dereferences it.\n\nOops, I previously forgot to CC Christian as the author of\nd460267613da.  Doing that now.\n"},{"id":"550526","messageId":"CAP8UFD0+iXC3VxWmuuuB7La-pP6hdz58tr6vaEJSKpXJ_4ZH2w@mail.gmail.com","threadId":"66160","inReplyTo":"pull.2199.git.1786516783909.gitgitgadget@gmail.com","subject":"Re: [PATCH] serve: reject valueless promisor-remote capability","fromName":"Christian Couder","fromEmail":"christian.couder@gmail.com","sentAt":"2026-08-13T15:27:47Z","receivedAt":"2026-08-13T15:28:00Z","isPatch":true,"body":"On Wed, Aug 12, 2026 at 8:42 AM Elijah Newren via GitGitGadget\n<gitgitgadget@gmail.com> wrote:\n>\n> From: Elijah Newren <newren@gmail.com>\n>\n> d460267613da (Add 'promisor-remote' capability to protocol v2,\n> 2025-02-18) added a receive callback which passes the capability value\n> directly to mark_promisor_remotes_as_accepted(). However, a client can\n> send the capability name without an '=' or value, in which case\n> get_capability() supplies NULL and strbuf_split_str() dereferences it.\n\nYeah, the original code you mention used strbuf_split_str(), but since\n68a746e9a8 (promisor-remote: use string_list_split() in\nmark_remotes_as_accepted(), 2025-09-08), string_list_split() is used\ninstead. Anyway string_list_split() also crashes when a NULL is passed\nas its `const char *string` argument.\n\n> Reject the missing argument before parsing it, and add a test covering\n> this case.\n\nYeah, the fix and its test look right to me. Thanks.\n"}]}