git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 1/4] convert: Safer handling of $Id$ contraction.

From
Henrik Grubbström <grubba@grubba.org>
Date
Mar 1, 2010, 16:16 UTC
Message-ID
<1267460218-1172-1-git-send-email-grubba@grubba.org>
From: Henrik Grubbström (Grubba) <grubba@grubba.org>

The code to contract $Id:xxxxx$ strings could eat an arbitrary amount of source text if the terminating $ was lost. It now refuses to contract $Id:xxxxx$ strings spanning multiple lines.

Signed-off-by: Henrik Grubbström <grubba@grubba.org>
---
 convert.c |   17 +++++++++++++++--
 1 files changed, 15 insertions(+), 2 deletions(-)
diff --git a/convert.c b/convert.c
index 4f8fcb7..91207ab 100644
--- a/convert.c
+++ b/convert.c
@@ -425,6 +425,7 @@ static int count_ident(const char *cp, unsigned long size)
 				cnt++;
 				break;
 			}
+			if (ch == '\n') break;
 		}
 	}
 	return cnt;
@@ -433,7 +434,7 @@ static int count_ident(const char *cp, unsigned long size)
 static int ident_to_git(const char *path, const char *src, size_t len,
                         struct strbuf *buf, int ident)
 {
-	char *dst, *dollar;
+	char *dst, *dollar, *nl;
 
 	if (!ident || !count_ident(src, len))
 		return 0;
@@ -455,6 +456,12 @@ static int ident_to_git(const char *path, const char *src, size_t len,
 			dollar = memchr(src + 3, '$', len - 3);
 			if (!dollar)
 				break;
+			nl = memchr(src + 3, '\n', len - 3);
+			if (nl && nl < dollar) {
+				/* Line break before the next dollar. */
+				continue;
+			}
+
 			memcpy(dst, "Id$", 3);
 			dst += 3;
 			len -= dollar + 1 - src;
@@ -470,7 +477,7 @@ static int ident_to_worktree(const char *path, const char *src, size_t len,
                              struct strbuf *buf, int ident)
 {
 	unsigned char sha1[20];
-	char *to_free = NULL, *dollar;
+	char *to_free = NULL, *dollar, *nl;
 	int cnt;
 
 	if (!ident)
@@ -514,6 +521,12 @@ static int ident_to_worktree(const char *path, const char *src, size_t len,
 				break;
 			}
 
+			nl = memchr(src + 3, '\n', len - 3);
+			if (nl && nl < dollar) {
+				/* Line break before the next dollar. */
+				continue;
+			}
+
 			len -= dollar + 1 - src;
 			src  = dollar + 1;
 		} else {
-- 
1.6.4.122.g6ffd7
Next: Henrik Grubbström
Message 1 of 9 in “convert: Safer handling of $Id$ contraction.”
  1. 1/4 convert: Safer handling of $Id$ contraction.Henrik Grubbström, Mar 1, 2010
  2. 2/4 convert: Keep foreign $Id$ on checkout.Henrik Grubbström, Mar 1, 2010
  3. 3/4 convert: Inhibit contraction of foreign $Id$ during stats.Henrik Grubbström, Mar 1, 2010
  4. 4/4 convert: Added core.refilteronadd feature.Henrik Grubbström, Mar 1, 2010
  5. Junio C HamanoMar 3, 2010
  6. Henrik GrubbströmMar 3, 2010
  7. Junio C HamanoMar 3, 2010
  8. Henrik GrubbströmMar 3, 2010
  9. Henrik GrubbströmMar 9, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.