{"thread":{"id":"66496","subject":"[PATCH] wincred: fix line split of secret blob content","startedAt":"2026-10-09T13:45:18Z","lastAt":"2026-10-10T11:47:30Z","messageCount":3,"participants":["Marc Becker via GitGitGadget","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"554603","messageId":"pull.2251.git.1791553518774.gitgitgadget@gmail.com","threadId":"66496","inReplyTo":null,"subject":"[PATCH] wincred: fix line split of secret blob content","fromName":"Marc Becker via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-10-09T13:45:18Z","receivedAt":"2026-10-09T13:45:18Z","isPatch":true,"sender":{"key":"marc.becker@astos.de","avatar":null},"body":"From: Marc Becker <becm@gmx.de>\n\noperate on immutable blob data (wcsncpy_s still had invalid target size)\nsplit on newline character to avoid bleed-over on multi-line content\n\nSigned-off-by: Marc Becker <becm@gmx.de>\n---\n    wincred: fix line split of secret blob content\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2251%2Fbecm%2Ffix-wincred-secret-linesplit-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2251/becm/fix-wincred-secret-linesplit-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2251\n\n .../wincred/git-credential-wincred.c          | 86 ++++++++++++-------\n 1 file changed, 55 insertions(+), 31 deletions(-)\n\ndiff --git a/contrib/credential/wincred/git-credential-wincred.c b/contrib/credential/wincred/git-credential-wincred.c\nindex 22eb27ca31..584f457774 100644\n--- a/contrib/credential/wincred/git-credential-wincred.c\n+++ b/contrib/credential/wincred/git-credential-wincred.c\n@@ -6,6 +6,7 @@\n #include <stdio.h>\n #include <io.h>\n #include <fcntl.h>\n+#include <wchar.h>\n #include <wincred.h>\n \n /* common helpers */\n@@ -148,51 +149,74 @@ static void get_credential(void)\n {\n \tCREDENTIALW **creds;\n \tDWORD num_creds;\n-\tint i;\n-\tCREDENTIAL_ATTRIBUTEW *attr;\n-\tWCHAR *secret;\n-\tWCHAR *line;\n-\tWCHAR *remaining_lines;\n-\tWCHAR *part;\n-\tWCHAR *remaining_parts;\n \n \tif (!CredEnumerateW(L\"git:*\", 0, &num_creds, &creds))\n \t\treturn;\n \n-\t/* search for the first credential that matches username */\n-\tfor (i = 0; i < num_creds; ++i)\n+\t/* search for the first credential that matches target and username */\n+\tfor (int i = 0; i < num_creds; ++i) {\n \t\tif (match_cred(creds[i], 0)) {\n-\t\t\twrite_item(\"username\", creds[i]->UserName,\n-\t\t\t\tcreds[i]->UserName ? wcslen(creds[i]->UserName) : 0);\n-\t\t\tif (creds[i]->CredentialBlobSize > 0) {\n-\t\t\t\tsecret = xmalloc(creds[i]->CredentialBlobSize + sizeof(WCHAR));\n-\t\t\t\twcsncpy_s(secret, creds[i]->CredentialBlobSize, (LPCWSTR)creds[i]->CredentialBlob, creds[i]->CredentialBlobSize / sizeof(WCHAR));\n-\t\t\t\tline = wcstok_s(secret, L\"\\r\\n\", &remaining_lines);\n-\t\t\t\twrite_item(\"password\", line, line ? wcslen(line) : 0);\n-\t\t\t\twhile(line != NULL) {\n-\t\t\t\t\tpart = wcstok_s(line, L\"=\", &remaining_parts);\n-\t\t\t\t\tif (!wcscmp(part, L\"oauth_refresh_token\")) {\n-\t\t\t\t\t\twrite_item(\"oauth_refresh_token\", remaining_parts, remaining_parts ? wcslen(remaining_parts) : 0);\n-\t\t\t\t\t}\n-\t\t\t\t\tline = wcstok_s(NULL, L\"\\r\\n\", &remaining_lines);\n-\t\t\t\t}\n-\t\t\t\tfree(secret);\n+\t\t\tLPCWSTR username = creds[i]->UserName;\n+\t\t\tLPCWSTR blob = (LPCWSTR)creds[i]->CredentialBlob;\n+\t\t\tLPCWSTR end;\n+\t\t\tDWORD wlen;\n+\n+\t\t\twrite_item(\"username\", username, username ? wcslen(username) : 0);\n+\n+\t\t\twlen = creds[i]->CredentialBlobSize / sizeof(WCHAR);\n+\n+\t\t\t// check if content is single line\n+\t\t\tif ((end = wmemchr(blob, '\\n', wlen)) == NULL) {\n+\t\t\t\twrite_item(\"password\", blob, wlen);\n \t\t\t} else {\n-\t\t\t\twrite_item(\"password\",\n-\t\t\t\t\t\t(LPCWSTR)creds[i]->CredentialBlob,\n-\t\t\t\t\t\tcreds[i]->CredentialBlobSize / sizeof(WCHAR));\n+\t\t\t\tDWORD length = end++ - blob;\n+\n+\t\t\t\t// correct remaining size and drop carriage return at line end\n+\t\t\t\twlen -= length + 1;\n+\t\t\t\tif (length && blob[length - 1] == '\\r') {\n+\t\t\t\t\t--length;\n+\t\t\t\t}\n+\t\t\t\twrite_item(\"password\", blob, length);\n+\n+\t\t\t\t// key/value content starting on next line\n+\t\t\t\tblob = end;\n+\t\t\t\tdo {\n+\t\t\t\t\tLPCWSTR value;\n+\n+\t\t\t\t\t// find line end\n+\t\t\t\t\tif ((end = wmemchr(blob, '\\n', wlen)) == NULL) {\n+\t\t\t\t\t\tlength = wlen;\n+\t\t\t\t\t} else {\n+\t\t\t\t\t\tlength = end++ - blob;\n+\t\t\t\t\t\t// correct remaining size and drop carriage return at line end\n+\t\t\t\t\t\twlen -= length + 1;\n+\t\t\t\t\t\tif (length && blob[length - 1] == '\\r') {\n+\t\t\t\t\t\t\t--length;\n+\t\t\t\t\t\t}\n+\t\t\t\t\t}\n+\t\t\t\t\t// find key/value separator for extended credential info\n+\t\t\t\t\tif ((value = wmemchr(blob, '=', length)) != NULL) {\n+\t\t\t\t\t\tstatic const LPCWSTR refresh = L\"oauth_refresh_token\";\n+\t\t\t\t\t\tDWORD klen = value - blob;\n+\n+\t\t\t\t\t\t// write entries known to git credential protocol\n+\t\t\t\t\t\tif (klen == wcslen(refresh) && memcmp(blob, refresh, klen) == 0) {\n+\t\t\t\t\t\t\twrite_item(\"oauth_refresh_token\", value + 1, length - klen - 1);\n+\t\t\t\t\t\t}\n+\t\t\t\t\t}\n+\t\t\t\t} while ((blob = end));\n \t\t\t}\n \t\t\tfor (int j = 0; j < creds[i]->AttributeCount; j++) {\n-\t\t\t\tattr = creds[i]->Attributes + j;\n+\t\t\t\tCREDENTIAL_ATTRIBUTEW *attr = creds[i]->Attributes + j;\n+\n \t\t\t\tif (!wcscmp(attr->Keyword, L\"git_password_expiry_utc\")) {\n-\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value,\n-\t\t\t\t\tattr->ValueSize / sizeof(WCHAR));\n+\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value, attr->ValueSize / sizeof(WCHAR));\n \t\t\t\t\tbreak;\n \t\t\t\t}\n \t\t\t}\n \t\t\tbreak;\n \t\t}\n-\n+\t}\n \tCredFree(creds);\n }\n \n\nbase-commit: 6de20f6092dcf9bdb1c8efe03db4b70c82b423dd\n-- \ngitgitgadget\n\n"},{"id":"554661","messageId":"xmqq1p9ymv6r.fsf@gitster.g","threadId":"66496","inReplyTo":"pull.2251.git.1791553518774.gitgitgadget@gmail.com","subject":"Re: [PATCH] wincred: fix line split of secret blob content","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-10-09T21:16:12Z","receivedAt":"2026-10-09T21:16:12Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Marc Becker via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n\n> From: Marc Becker <becm@gmx.de>\n>\n> operate on immutable blob data (wcsncpy_s still had invalid target size)\n> split on newline character to avoid bleed-over on multi-line content\n\nThis needs a bit more work to make it more readable than a bulleted\nlist of lowercase fragments.\n\nWhen in doubt, keep in mind that the usual way to compose a log\nmessage of this project is to:\n\n - Give an observation on how the current system works in the\n   present tense (so no need to say \"Currently X is Y\", or\n   \"Previously X was Y\" to describe the state before your change;\n   just \"X is Y\" is enough), and discuss what you perceive as a\n   problem in it.\n\n - Propose a solution (optional---often, problem description\n   trivially leads to an obvious solution in reader's minds).\n\n - Give commands to somebody editing the codebase to \"make it so\",\n   instead of saying \"This commit does X\".\n\nin this order.\n\n - It mentions wcsncpy_s having an invalid target size, but does not\n   explain why it was invalid or the consequences. Is the issue that\n   wcsncpy_s expects the buffer size in wide characters, but was\n   being passed a size in bytes, which obviously cannot always\n   agree?\n\n - It mentions \"bleed-over on multi-line content\", but does not\n   describe the observable symptoms.  Is the issue that when the\n   password is empty, the skipping by wcstok_s delimiter would cause\n   the oauth_refresh_token line to be erroneously parsed as the\n   password?\n\n - The final sentence should be an imperative command to the\n   codebase, e.g., \"Parse the blob in-place without copying and\n   split lines manually using wmemchr().\"\n\n>\n> Signed-off-by: Marc Becker <becm@gmx.de>\n> ---\n>     wincred: fix line split of secret blob content\n>\n> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-2251%2Fbecm%2Ffix-wincred-secret-linesplit-v1\n> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2251/becm/fix-wincred-secret-linesplit-v1\n> Pull-Request: https://github.com/gitgitgadget/git/pull/2251\n>\n>  .../wincred/git-credential-wincred.c          | 86 ++++++++++++-------\n>  1 file changed, 55 insertions(+), 31 deletions(-)\n>\n> diff --git a/contrib/credential/wincred/git-credential-wincred.c b/contrib/credential/wincred/git-credential-wincred.c\n> index 22eb27ca31..584f457774 100644\n> --- a/contrib/credential/wincred/git-credential-wincred.c\n> +++ b/contrib/credential/wincred/git-credential-wincred.c\n> @@ -6,6 +6,7 @@\n>  #include <stdio.h>\n>  #include <io.h>\n>  #include <fcntl.h>\n> +#include <wchar.h>\n>  #include <wincred.h>\n>  \n>  /* common helpers */\n> @@ -148,51 +149,74 @@ static void get_credential(void)\n>  {\n>  \tCREDENTIALW **creds;\n>  \tDWORD num_creds;\n> -\tint i;\n> -\tCREDENTIAL_ATTRIBUTEW *attr;\n> -\tWCHAR *secret;\n> -\tWCHAR *line;\n> -\tWCHAR *remaining_lines;\n> -\tWCHAR *part;\n> -\tWCHAR *remaining_parts;\n>  \n>  \tif (!CredEnumerateW(L\"git:*\", 0, &num_creds, &creds))\n>  \t\treturn;\n>  \n> -\t/* search for the first credential that matches username */\n> -\tfor (i = 0; i < num_creds; ++i)\n> +\t/* search for the first credential that matches target and username */\n> +\tfor (int i = 0; i < num_creds; ++i) {\n>  \t\tif (match_cred(creds[i], 0)) {\n> -\t\t\twrite_item(\"username\", creds[i]->UserName,\n> -\t\t\t\tcreds[i]->UserName ? wcslen(creds[i]->UserName) : 0);\n> -\t\t\tif (creds[i]->CredentialBlobSize > 0) {\n> -\t\t\t\tsecret = xmalloc(creds[i]->CredentialBlobSize + sizeof(WCHAR));\n> -\t\t\t\twcsncpy_s(secret, creds[i]->CredentialBlobSize, (LPCWSTR)creds[i]->CredentialBlob, creds[i]->CredentialBlobSize / sizeof(WCHAR));\n> -\t\t\t\tline = wcstok_s(secret, L\"\\r\\n\", &remaining_lines);\n> -\t\t\t\twrite_item(\"password\", line, line ? wcslen(line) : 0);\n> -\t\t\t\twhile(line != NULL) {\n> -\t\t\t\t\tpart = wcstok_s(line, L\"=\", &remaining_parts);\n> -\t\t\t\t\tif (!wcscmp(part, L\"oauth_refresh_token\")) {\n> -\t\t\t\t\t\twrite_item(\"oauth_refresh_token\", remaining_parts, remaining_parts ? wcslen(remaining_parts) : 0);\n> -\t\t\t\t\t}\n> -\t\t\t\t\tline = wcstok_s(NULL, L\"\\r\\n\", &remaining_lines);\n> -\t\t\t\t}\n> -\t\t\t\tfree(secret);\n\nThe original was already bad, but this makes it even worse to have\nthe code nested too deeply.  Would separating out the body of the\nfor loop into a separate helper function, or perhaps standard tricks\nlike this\n\n\tfor (...) {\n\t\tif (!match_cred(...))\n\t\t\tcontinue;\n\t\t... rest of the loop dedented by one tab stop ...\n\t}\n\nmake it readable?\n\n> +\t\t\tLPCWSTR username = creds[i]->UserName;\n> +\t\t\tLPCWSTR blob = (LPCWSTR)creds[i]->CredentialBlob;\n> +\t\t\tLPCWSTR end;\n> +\t\t\tDWORD wlen;\n> +\n> +\t\t\twrite_item(\"username\", username, username ? wcslen(username) : 0);\n> +\n> +\t\t\twlen = creds[i]->CredentialBlobSize / sizeof(WCHAR);\n> +\n> +\t\t\t// check if content is single line\n\n\t\t\t/* our single line comment should look like this */\n\n> +\t\t\tif ((end = wmemchr(blob, '\\n', wlen)) == NULL) {\n\nI do not do Windows and I do not often deal with wchar_t, so I do\nnot know how much practitioners of code like this one cares, but\nwould it be better to make the fact clear that we are not dealing\nwith a regular 'char' by writing a wchar_t literal like this as\nL'\\n'?  This is not a correctness suggestion, but a readability one.\nHaving a function prototype would coerse the parameter types, so\nyou may end up passing L'\\n' either way.\n\n> +\t\t\t\twrite_item(\"password\", blob, wlen);\n>  \t\t\t} else {\n> -\t\t\t\twrite_item(\"password\",\n> -\t\t\t\t\t\t(LPCWSTR)creds[i]->CredentialBlob,\n> -\t\t\t\t\t\tcreds[i]->CredentialBlobSize / sizeof(WCHAR));\n> +\t\t\t\tDWORD length = end++ - blob;\n\nHere, \"end\" is of LPCWSTR type, aka \"wchar_t *\".  So is \"blob\".  The\ndifference would give us how many wide characters are in there.\nThat is not necessarily number of bytes starting at &blob[0].\n\n> +\t\t\t\t// correct remaining size and drop carriage return at line end\n> +\t\t\t\twlen -= length + 1;\n> +\t\t\t\tif (length && blob[length - 1] == '\\r') {\n\nThis CR is also side, right?\n\n> +\t\t\t\t\t--length;\n> +\t\t\t\t}\n> +\t\t\t\twrite_item(\"password\", blob, length);\n> +\n> +\t\t\t\t// key/value content starting on next line\n> +\t\t\t\tblob = end;\n> +\t\t\t\tdo {\n> +\t\t\t\t\tLPCWSTR value;\n> +\n> +\t\t\t\t\t// find line end\n> +\t\t\t\t\tif ((end = wmemchr(blob, '\\n', wlen)) == NULL) {\n> +\t\t\t\t\t\tlength = wlen;\n> +\t\t\t\t\t} else {\n> +\t\t\t\t\t\tlength = end++ - blob;\n> +\t\t\t\t\t\t// correct remaining size and drop carriage return at line end\n> +\t\t\t\t\t\twlen -= length + 1;\n> +\t\t\t\t\t\tif (length && blob[length - 1] == '\\r') {\n> +\t\t\t\t\t\t\t--length;\n> +\t\t\t\t\t\t}\n> +\t\t\t\t\t}\n> +\t\t\t\t\t// find key/value separator for extended credential info\n> +\t\t\t\t\tif ((value = wmemchr(blob, '=', length)) != NULL) {\n> +\t\t\t\t\t\tstatic const LPCWSTR refresh = L\"oauth_refresh_token\";\n> +\t\t\t\t\t\tDWORD klen = value - blob;\n\nValue is also \"wchar_t *\", so klen counts the length in wchar_t,\nwhich may be wider than a byte.  So is\n\n> +\t\t\t\t\t\t// write entries known to git credential protocol\n> +\t\t\t\t\t\tif (klen == wcslen(refresh) && memcmp(blob, refresh, klen) == 0) {\n\nklen that counts number of wchar_t letters in refresh[] string.\n\nSo, is the memcmp() used to check if early part of blob[] match the\nrefresh[] as a whole correct, or is it only checking an early half\n(or one fourth, depending on how much wider your wchar_t is compared\nto char) of the string?\n\n> +\t\t\t\t\t\t\twrite_item(\"oauth_refresh_token\", value + 1, length - klen - 1);\n> +\t\t\t\t\t\t}\n> +\t\t\t\t\t}\n> +\t\t\t\t} while ((blob = end));\n>  \t\t\t}\n>  \t\t\tfor (int j = 0; j < creds[i]->AttributeCount; j++) {\n> -\t\t\t\tattr = creds[i]->Attributes + j;\n> +\t\t\t\tCREDENTIAL_ATTRIBUTEW *attr = creds[i]->Attributes + j;\n> +\n>  \t\t\t\tif (!wcscmp(attr->Keyword, L\"git_password_expiry_utc\")) {\n> -\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value,\n> -\t\t\t\t\tattr->ValueSize / sizeof(WCHAR));\n> +\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value, attr->ValueSize / sizeof(WCHAR));\n>  \t\t\t\t\tbreak;\n>  \t\t\t\t}\n>  \t\t\t}\n>  \t\t\tbreak;\n>  \t\t}\n> -\n> +\t}\n>  \tCredFree(creds);\n>  }\n>  \n>\n> base-commit: 6de20f6092dcf9bdb1c8efe03db4b70c82b423dd\n\n"},{"id":"554688","messageId":"pull.2251.v2.git.1791632850780.gitgitgadget@gmail.com","threadId":"66496","inReplyTo":"pull.2251.git.1791553518774.gitgitgadget@gmail.com","subject":"[PATCH v2] wincred: refactor credential blob processing","fromName":"Marc Becker via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-10-10T11:47:30Z","receivedAt":"2026-10-10T11:47:30Z","isPatch":true,"sender":{"key":"marc.becker@astos.de","avatar":null},"body":"From: Marc Becker <becm@gmx.de>\n\nInvalid target size check (bytes instead of characters) for `wcsncpy_s`\nalready led to memory corruption; d22a4884 just hid the error by making\nsure the target is always big enough.\nSingle invocation of `wcstok_s` only cuts out first hit delimiter.\nConsecutive items would always start with a line feed character if\nseparation consists of CRLF.\nOnly exception is 1st item (due to following bug).\nAdvancement to end of password line is missing. Password value is reused\nas extended credential item but likely filtered out due to value\nmismatch with accepted key.\n\nLine split needs to be deterministic and code should be split up into\nsmaller blocks.\n\nCreate separate methods for writing credential items and the complete\ncredential blob content to tighten code in main credential loop.\nReduce variable scope and nesting level. Use early continue/return to\nimprove code readability.\nUse `wmemchr` to reliably detect wide-character-newline in immutable\nblob data without need to create a further copy.\n\nSigned-off-by: Marc Becker <becm@gmx.de>\n---\n    wincred: fix line split of secret blob content\n    \n    Changes since v1:\n    \n     * move credential blob dissection and output to separate methods\n       (maintainer request)\n     * mark character constants as wide char\n     * consistently treat sizes/lengths as (wide) character count\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2251%2Fbecm%2Ffix-wincred-secret-linesplit-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2251/becm/fix-wincred-secret-linesplit-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/2251\n\nRange-diff vs v1:\n\n 1:  fb80cfc32a ! 1:  01a1039f70 wincred: fix line split of secret blob content\n     @@ Metadata\n      Author: Marc Becker <becm@gmx.de>\n      \n       ## Commit message ##\n     -    wincred: fix line split of secret blob content\n     +    wincred: refactor credential blob processing\n      \n     -    operate on immutable blob data (wcsncpy_s still had invalid target size)\n     -    split on newline character to avoid bleed-over on multi-line content\n     +    Invalid target size check (bytes instead of characters) for `wcsncpy_s`\n     +    already led to memory corruption; d22a4884 just hid the error by making\n     +    sure the target is always big enough.\n     +    Single invocation of `wcstok_s` only cuts out first hit delimiter.\n     +    Consecutive items would always start with a line feed character if\n     +    separation consists of CRLF.\n     +    Only exception is 1st item (due to following bug).\n     +    Advancement to end of password line is missing. Password value is reused\n     +    as extended credential item but likely filtered out due to value\n     +    mismatch with accepted key.\n     +\n     +    Line split needs to be deterministic and code should be split up into\n     +    smaller blocks.\n     +\n     +    Create separate methods for writing credential items and the complete\n     +    credential blob content to tighten code in main credential loop.\n     +    Reduce variable scope and nesting level. Use early continue/return to\n     +    improve code readability.\n     +    Use `wmemchr` to reliably detect wide-character-newline in immutable\n     +    blob data without need to create a further copy.\n      \n          Signed-off-by: Marc Becker <becm@gmx.de>\n      \n     @@ contrib/credential/wincred/git-credential-wincred.c\n       #include <wincred.h>\n       \n       /* common helpers */\n     +@@ contrib/credential/wincred/git-credential-wincred.c: static void write_item(const char *what, LPCWSTR wbuf, int wlen)\n     + \tfree(buf);\n     + }\n     + \n     ++/*\n     ++ * Write known credential item.\n     ++ */\n     ++static void write_credential_item(LPCWSTR data, int wlen)\n     ++{\n     ++\tstatic const LPCWSTR refresh_token = L\"oauth_refresh_token\";\n     ++\tLPCWSTR value;\n     ++\tDWORD klen;\n     ++\tDWORD vlen;\n     ++\n     ++\t/* find key/value separator for credential item */\n     ++\tif ((value = wmemchr(data, L'=', wlen)) == NULL)\n     ++\t\treturn;\n     ++\tklen = value++ - data;\n     ++\tvlen = wlen - klen - 1;\n     ++\n     ++\t/* write items known to git credential protocol */\n     ++\tif (klen == wcslen(refresh_token) && wmemcmp(data, refresh_token, klen) == 0)\n     ++\t\twrite_item(\"oauth_refresh_token\", value, vlen);\n     ++}\n     ++\n     ++/*\n     ++ * Write single credential block\n     ++ * consisting of password and further (accepted) credential items.\n     ++ */\n     ++static void write_credential(const CREDENTIALW *cred)\n     ++{\n     ++\tLPCWSTR end;\n     ++\tDWORD length;\n     ++\tLPCWSTR blob = (LPCWSTR)cred->CredentialBlob;\n     ++\tDWORD wlen = cred->CredentialBlobSize / sizeof(WCHAR);\n     ++\n     ++\t/* check if content is single line */\n     ++\tif ((end = wmemchr(blob, L'\\n', wlen)) == NULL) {\n     ++\t\twrite_item(\"password\", blob, wlen);\n     ++\t\treturn;\n     ++\t}\n     ++\t/* determine current line length and remaining data size */\n     ++\tlength = end++ - blob;\n     ++\twlen -= length + 1;\n     ++\n     ++\t/* skip carriage return at line end */\n     ++\tif (length && blob[length - 1] == L'\\r')\n     ++\t\t--length;\n     ++\twrite_item(\"password\", blob, length);\n     ++\n     ++\twhile (1) {\n     ++\t\t/* key/value content starts on next line */\n     ++\t\tblob = end;\n     ++\n     ++\t\t/* find line end */\n     ++\t\tif ((end = wmemchr(blob, L'\\n', wlen)) == NULL) {\n     ++\t\t\twrite_credential_item(blob, wlen);\n     ++\t\t\treturn;\n     ++\t\t}\n     ++\t\t/* determine current line length and remaining data size */\n     ++\t\tlength = end++ - blob;\n     ++\t\twlen -= length + 1;\n     ++\n     ++\t\t// skip carriage return at line end\n     ++\t\tif (length && blob[length - 1] == L'\\r')\n     ++\t\t\t--length;\n     ++\t\twrite_credential_item(blob, length);\n     ++\t}\n     ++}\n     ++\n     + /*\n     +  * Match an (optional) expected string and a delimiter in the target string,\n     +  * consuming the matched text by updating the target pointer.\n      @@ contrib/credential/wincred/git-credential-wincred.c: static void get_credential(void)\n       {\n       \tCREDENTIALW **creds;\n     @@ contrib/credential/wincred/git-credential-wincred.c: static void get_credential(\n       \n      -\t/* search for the first credential that matches username */\n      -\tfor (i = 0; i < num_creds; ++i)\n     -+\t/* search for the first credential that matches target and username */\n     -+\tfor (int i = 0; i < num_creds; ++i) {\n     - \t\tif (match_cred(creds[i], 0)) {\n     +-\t\tif (match_cred(creds[i], 0)) {\n      -\t\t\twrite_item(\"username\", creds[i]->UserName,\n      -\t\t\t\tcreds[i]->UserName ? wcslen(creds[i]->UserName) : 0);\n      -\t\t\tif (creds[i]->CredentialBlobSize > 0) {\n     @@ contrib/credential/wincred/git-credential-wincred.c: static void get_credential(\n      -\t\t\t\t\tline = wcstok_s(NULL, L\"\\r\\n\", &remaining_lines);\n      -\t\t\t\t}\n      -\t\t\t\tfree(secret);\n     -+\t\t\tLPCWSTR username = creds[i]->UserName;\n     -+\t\t\tLPCWSTR blob = (LPCWSTR)creds[i]->CredentialBlob;\n     -+\t\t\tLPCWSTR end;\n     -+\t\t\tDWORD wlen;\n     -+\n     -+\t\t\twrite_item(\"username\", username, username ? wcslen(username) : 0);\n     -+\n     -+\t\t\twlen = creds[i]->CredentialBlobSize / sizeof(WCHAR);\n     -+\n     -+\t\t\t// check if content is single line\n     -+\t\t\tif ((end = wmemchr(blob, '\\n', wlen)) == NULL) {\n     -+\t\t\t\twrite_item(\"password\", blob, wlen);\n     - \t\t\t} else {\n     +-\t\t\t} else {\n      -\t\t\t\twrite_item(\"password\",\n      -\t\t\t\t\t\t(LPCWSTR)creds[i]->CredentialBlob,\n      -\t\t\t\t\t\tcreds[i]->CredentialBlobSize / sizeof(WCHAR));\n     -+\t\t\t\tDWORD length = end++ - blob;\n     +-\t\t\t}\n     +-\t\t\tfor (int j = 0; j < creds[i]->AttributeCount; j++) {\n     +-\t\t\t\tattr = creds[i]->Attributes + j;\n     +-\t\t\t\tif (!wcscmp(attr->Keyword, L\"git_password_expiry_utc\")) {\n     +-\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value,\n     +-\t\t\t\t\tattr->ValueSize / sizeof(WCHAR));\n     +-\t\t\t\t\tbreak;\n     +-\t\t\t\t}\n     ++\t/* search for the first credential that matches target and username */\n     ++\tfor (int i = 0; i < num_creds; ++i) {\n     ++\t\tLPCWSTR username;\n      +\n     -+\t\t\t\t// correct remaining size and drop carriage return at line end\n     -+\t\t\t\twlen -= length + 1;\n     -+\t\t\t\tif (length && blob[length - 1] == '\\r') {\n     -+\t\t\t\t\t--length;\n     -+\t\t\t\t}\n     -+\t\t\t\twrite_item(\"password\", blob, length);\n     ++\t\tif (!match_cred(creds[i], 0))\n     ++\t\t\tcontinue;\n      +\n     -+\t\t\t\t// key/value content starting on next line\n     -+\t\t\t\tblob = end;\n     -+\t\t\t\tdo {\n     -+\t\t\t\t\tLPCWSTR value;\n     ++\t\tusername = creds[i]->UserName;\n     ++\t\twrite_item(\"username\", username, username ? wcslen(username) : 0);\n      +\n     -+\t\t\t\t\t// find line end\n     -+\t\t\t\t\tif ((end = wmemchr(blob, '\\n', wlen)) == NULL) {\n     -+\t\t\t\t\t\tlength = wlen;\n     -+\t\t\t\t\t} else {\n     -+\t\t\t\t\t\tlength = end++ - blob;\n     -+\t\t\t\t\t\t// correct remaining size and drop carriage return at line end\n     -+\t\t\t\t\t\twlen -= length + 1;\n     -+\t\t\t\t\t\tif (length && blob[length - 1] == '\\r') {\n     -+\t\t\t\t\t\t\t--length;\n     -+\t\t\t\t\t\t}\n     -+\t\t\t\t\t}\n     -+\t\t\t\t\t// find key/value separator for extended credential info\n     -+\t\t\t\t\tif ((value = wmemchr(blob, '=', length)) != NULL) {\n     -+\t\t\t\t\t\tstatic const LPCWSTR refresh = L\"oauth_refresh_token\";\n     -+\t\t\t\t\t\tDWORD klen = value - blob;\n     ++\t\twrite_credential(creds[i]);\n      +\n     -+\t\t\t\t\t\t// write entries known to git credential protocol\n     -+\t\t\t\t\t\tif (klen == wcslen(refresh) && memcmp(blob, refresh, klen) == 0) {\n     -+\t\t\t\t\t\t\twrite_item(\"oauth_refresh_token\", value + 1, length - klen - 1);\n     -+\t\t\t\t\t\t}\n     -+\t\t\t\t\t}\n     -+\t\t\t\t} while ((blob = end));\n     - \t\t\t}\n     - \t\t\tfor (int j = 0; j < creds[i]->AttributeCount; j++) {\n     --\t\t\t\tattr = creds[i]->Attributes + j;\n     -+\t\t\t\tCREDENTIAL_ATTRIBUTEW *attr = creds[i]->Attributes + j;\n     ++\t\tfor (int j = 0; j < creds[i]->AttributeCount; j++) {\n     ++\t\t\tCREDENTIAL_ATTRIBUTEW *attr = creds[i]->Attributes + j;\n      +\n     - \t\t\t\tif (!wcscmp(attr->Keyword, L\"git_password_expiry_utc\")) {\n     --\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value,\n     --\t\t\t\t\tattr->ValueSize / sizeof(WCHAR));\n     -+\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value, attr->ValueSize / sizeof(WCHAR));\n     - \t\t\t\t\tbreak;\n     - \t\t\t\t}\n     ++\t\t\tif (!wcscmp(attr->Keyword, L\"git_password_expiry_utc\")) {\n     ++\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value, attr->ValueSize / sizeof(WCHAR));\n     ++\t\t\t\tbreak;\n       \t\t\t}\n     - \t\t\tbreak;\n     +-\t\t\tbreak;\n       \t\t}\n      -\n     ++\t\tbreak;\n      +\t}\n       \tCredFree(creds);\n       }\n\n\n .../wincred/git-credential-wincred.c          | 126 ++++++++++++------\n 1 file changed, 87 insertions(+), 39 deletions(-)\n\ndiff --git a/contrib/credential/wincred/git-credential-wincred.c b/contrib/credential/wincred/git-credential-wincred.c\nindex 22eb27ca31..cd72e71ecd 100644\n--- a/contrib/credential/wincred/git-credential-wincred.c\n+++ b/contrib/credential/wincred/git-credential-wincred.c\n@@ -6,6 +6,7 @@\n #include <stdio.h>\n #include <io.h>\n #include <fcntl.h>\n+#include <wchar.h>\n #include <wincred.h>\n \n /* common helpers */\n@@ -69,6 +70,72 @@ static void write_item(const char *what, LPCWSTR wbuf, int wlen)\n \tfree(buf);\n }\n \n+/*\n+ * Write known credential item.\n+ */\n+static void write_credential_item(LPCWSTR data, int wlen)\n+{\n+\tstatic const LPCWSTR refresh_token = L\"oauth_refresh_token\";\n+\tLPCWSTR value;\n+\tDWORD klen;\n+\tDWORD vlen;\n+\n+\t/* find key/value separator for credential item */\n+\tif ((value = wmemchr(data, L'=', wlen)) == NULL)\n+\t\treturn;\n+\tklen = value++ - data;\n+\tvlen = wlen - klen - 1;\n+\n+\t/* write items known to git credential protocol */\n+\tif (klen == wcslen(refresh_token) && wmemcmp(data, refresh_token, klen) == 0)\n+\t\twrite_item(\"oauth_refresh_token\", value, vlen);\n+}\n+\n+/*\n+ * Write single credential block\n+ * consisting of password and further (accepted) credential items.\n+ */\n+static void write_credential(const CREDENTIALW *cred)\n+{\n+\tLPCWSTR end;\n+\tDWORD length;\n+\tLPCWSTR blob = (LPCWSTR)cred->CredentialBlob;\n+\tDWORD wlen = cred->CredentialBlobSize / sizeof(WCHAR);\n+\n+\t/* check if content is single line */\n+\tif ((end = wmemchr(blob, L'\\n', wlen)) == NULL) {\n+\t\twrite_item(\"password\", blob, wlen);\n+\t\treturn;\n+\t}\n+\t/* determine current line length and remaining data size */\n+\tlength = end++ - blob;\n+\twlen -= length + 1;\n+\n+\t/* skip carriage return at line end */\n+\tif (length && blob[length - 1] == L'\\r')\n+\t\t--length;\n+\twrite_item(\"password\", blob, length);\n+\n+\twhile (1) {\n+\t\t/* key/value content starts on next line */\n+\t\tblob = end;\n+\n+\t\t/* find line end */\n+\t\tif ((end = wmemchr(blob, L'\\n', wlen)) == NULL) {\n+\t\t\twrite_credential_item(blob, wlen);\n+\t\t\treturn;\n+\t\t}\n+\t\t/* determine current line length and remaining data size */\n+\t\tlength = end++ - blob;\n+\t\twlen -= length + 1;\n+\n+\t\t// skip carriage return at line end\n+\t\tif (length && blob[length - 1] == L'\\r')\n+\t\t\t--length;\n+\t\twrite_credential_item(blob, length);\n+\t}\n+}\n+\n /*\n  * Match an (optional) expected string and a delimiter in the target string,\n  * consuming the matched text by updating the target pointer.\n@@ -148,51 +215,32 @@ static void get_credential(void)\n {\n \tCREDENTIALW **creds;\n \tDWORD num_creds;\n-\tint i;\n-\tCREDENTIAL_ATTRIBUTEW *attr;\n-\tWCHAR *secret;\n-\tWCHAR *line;\n-\tWCHAR *remaining_lines;\n-\tWCHAR *part;\n-\tWCHAR *remaining_parts;\n \n \tif (!CredEnumerateW(L\"git:*\", 0, &num_creds, &creds))\n \t\treturn;\n \n-\t/* search for the first credential that matches username */\n-\tfor (i = 0; i < num_creds; ++i)\n-\t\tif (match_cred(creds[i], 0)) {\n-\t\t\twrite_item(\"username\", creds[i]->UserName,\n-\t\t\t\tcreds[i]->UserName ? wcslen(creds[i]->UserName) : 0);\n-\t\t\tif (creds[i]->CredentialBlobSize > 0) {\n-\t\t\t\tsecret = xmalloc(creds[i]->CredentialBlobSize + sizeof(WCHAR));\n-\t\t\t\twcsncpy_s(secret, creds[i]->CredentialBlobSize, (LPCWSTR)creds[i]->CredentialBlob, creds[i]->CredentialBlobSize / sizeof(WCHAR));\n-\t\t\t\tline = wcstok_s(secret, L\"\\r\\n\", &remaining_lines);\n-\t\t\t\twrite_item(\"password\", line, line ? wcslen(line) : 0);\n-\t\t\t\twhile(line != NULL) {\n-\t\t\t\t\tpart = wcstok_s(line, L\"=\", &remaining_parts);\n-\t\t\t\t\tif (!wcscmp(part, L\"oauth_refresh_token\")) {\n-\t\t\t\t\t\twrite_item(\"oauth_refresh_token\", remaining_parts, remaining_parts ? wcslen(remaining_parts) : 0);\n-\t\t\t\t\t}\n-\t\t\t\t\tline = wcstok_s(NULL, L\"\\r\\n\", &remaining_lines);\n-\t\t\t\t}\n-\t\t\t\tfree(secret);\n-\t\t\t} else {\n-\t\t\t\twrite_item(\"password\",\n-\t\t\t\t\t\t(LPCWSTR)creds[i]->CredentialBlob,\n-\t\t\t\t\t\tcreds[i]->CredentialBlobSize / sizeof(WCHAR));\n-\t\t\t}\n-\t\t\tfor (int j = 0; j < creds[i]->AttributeCount; j++) {\n-\t\t\t\tattr = creds[i]->Attributes + j;\n-\t\t\t\tif (!wcscmp(attr->Keyword, L\"git_password_expiry_utc\")) {\n-\t\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value,\n-\t\t\t\t\tattr->ValueSize / sizeof(WCHAR));\n-\t\t\t\t\tbreak;\n-\t\t\t\t}\n+\t/* search for the first credential that matches target and username */\n+\tfor (int i = 0; i < num_creds; ++i) {\n+\t\tLPCWSTR username;\n+\n+\t\tif (!match_cred(creds[i], 0))\n+\t\t\tcontinue;\n+\n+\t\tusername = creds[i]->UserName;\n+\t\twrite_item(\"username\", username, username ? wcslen(username) : 0);\n+\n+\t\twrite_credential(creds[i]);\n+\n+\t\tfor (int j = 0; j < creds[i]->AttributeCount; j++) {\n+\t\t\tCREDENTIAL_ATTRIBUTEW *attr = creds[i]->Attributes + j;\n+\n+\t\t\tif (!wcscmp(attr->Keyword, L\"git_password_expiry_utc\")) {\n+\t\t\t\twrite_item(\"password_expiry_utc\", (LPCWSTR)attr->Value, attr->ValueSize / sizeof(WCHAR));\n+\t\t\t\tbreak;\n \t\t\t}\n-\t\t\tbreak;\n \t\t}\n-\n+\t\tbreak;\n+\t}\n \tCredFree(creds);\n }\n \n\nbase-commit: 6de20f6092dcf9bdb1c8efe03db4b70c82b423dd\n-- \ngitgitgadget\n\n"}]}