git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 3/3] commit: refuse commit messages that contain NULs

From
Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
Date
Dec 15, 2011, 13:47 UTC
Message-ID
<1323956843-5326-3-git-send-email-pclouds@gmail.com>
In-Reply-To
<1323956843-5326-1-git-send-email-pclouds@gmail.com>

Current implementation sees NUL as terminator. If users give a NUL-included message (e.g. editor accidentally set to save as UTF-16), the new commit message will have NULs. However following operations (displaying or amending a commit for example) will not show anything after the first NUL.

Stop user right when they do this. If NUL is added by mistake, they have their chance to fix. If they know that they are doing, commit-tree will gladly commit whatever is given.

Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
---
 Advice stuff dropped. I realized quite late that commit_tree() is
 also used for plumbing commands (also thanks to Junio's comments),
 while I wanted to check at porcelain level only. So I moved the check
 up to builtin/commit.c. If we need the same check for other commands,
 which I doubt, similar checks can be added.
 builtin/commit.c       |    7 +++++++
 t/t3900-i18n-commit.sh |    6 ++++++
 2 files changed, 13 insertions(+), 0 deletions(-)
diff --git a/builtin/commit.c b/builtin/commit.c
index 849151e..5db7673 100644
--- a/builtin/commit.c
+++ b/builtin/commit.c
@@ -1483,6 +1483,13 @@ int cmd_commit(int argc, const char **argv, const char *prefix)
 		exit(1);
 	}
 
+	if (memchr(sb.buf, '\0', sb.len)) {
+		rollback_index_files();
+		die(_("your commit message contains NUL characters.\n"
+		      "hint: This is often caused by using wide encodings such as\n"
+		      "hint: UTF-16. Please check your editor settings."));
+	}
+
 	if (commit_tree(&sb, active_cache_tree->sha1, parents, sha1,
 			author_ident.buf)) {
 		rollback_index_files();
diff --git a/t/t3900-i18n-commit.sh b/t/t3900-i18n-commit.sh
index 1f62c15..d48a7c0 100755
--- a/t/t3900-i18n-commit.sh
+++ b/t/t3900-i18n-commit.sh
@@ -34,6 +34,12 @@ test_expect_success 'no encoding header for base case' '
 	test z = "z$E"
 '
 
+test_expect_failure 'UTF-16 refused because of NULs' '
+	echo UTF-16 >F &&
+	git commit -a -F "$TEST_DIRECTORY"/t3900/UTF-16.txt
+'
+
+
 for H in ISO8859-1 eucJP ISO-2022-JP
 do
 	test_expect_success "$H setup" '
-- 
1.7.8.36.g69ee2
Previous: Nguyễn Thái Ngọc DuyNext: Junio C Hamano
Message 12 of 23 in “Do not create commits whose message contains NUL”
  1. Do not create commits whose message contains NULNguyễn Thái Ngọc Duy, Dec 13, 2011
  2. Jeff KingDec 13, 2011
  3. Miles BaderDec 14, 2011
  4. Jeff KingDec 14, 2011
  5. Drew NorthupJan 1, 2012
  6. Jeff KingJan 3, 2012
  7. 0/3 git-commit rejects messages with NULsNguyễn Thái Ngọc Duy, Dec 14, 2011
  8. 1/3 Make commit_tree() take message length in addition to the commit messageNguyễn Thái Ngọc Duy, Dec 14, 2011
  9. Junio C HamanoDec 14, 2011
  10. 1/3 merge: abort if fails to commitNguyễn Thái Ngọc Duy, Dec 15, 2011
  11. 2/3 Convert commit_tree() to take strbuf as messageNguyễn Thái Ngọc Duy, Dec 15, 2011
  12. 3/3 commit: refuse commit messages that contain NULsNguyễn Thái Ngọc Duy, Dec 15, 2011
  13. Junio C HamanoDec 15, 2011
  14. 2/3 merge: abort if fails to commitNguyễn Thái Ngọc Duy, Dec 14, 2011
  15. Junio C HamanoDec 14, 2011
  16. 3/3 Do not create commits whose message contains NULNguyễn Thái Ngọc Duy, Dec 14, 2011
  17. Junio C HamanoDec 14, 2011
  18. Jeff KingDec 14, 2011
  19. Junio C HamanoDec 15, 2011
  20. Junio C HamanoDec 15, 2011
  21. Miles BaderDec 15, 2011
  22. Jeff KingDec 15, 2011
  23. Junio C HamanoDec 15, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.