git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git string manipulation functions wrong?

From
Petr Baudis <pasky@suse.cz>
Date
May 21, 2007, 14:36 UTC
Message-ID
<20070521143616.GG4489@pasky.or.cz>
In-Reply-To
<20070521131103.GN8200@gateway.home>
On Mon, May 21, 2007 at 03:11:03PM CEST, Erik Mouw wrote:
Show 17 quoted lines
> Hi,
> 
> I got this forwarded from a friend who is subscribed to the Dovecot
> mailing lists (dovecot is a pop3/imap server).
> 
>   http://www.dovecot.org/list/dovecot/2007-May/022853.html
>   http://www.dovecot.org/list/dovecot/2007-May/022856.html
> 
> The Dovecot author claims there are "basic string manipulation errors"
> in the git code and that's a reason for him not to use git.
> 
> I can see his problem with *snprintf() functions in the case where the
> amount of output is larger than the buffer size: *snprintf() will
> return the number of characters written if there would have been enough
> space to write them, which will lead to problems with code like "len +=
> snprintf(buf, max, bla, ...)". I don't see his problems with strncpy(),
> though.

It's the opposite for me - we don't properly set the NUL byte for smoe of our strncpy() calls, but I don't really see his problem with snprintf(), we seem to handle its return value correctly everywhere (except diff.c, but there the buffer sizes should be designed in such a way that an overflow should be impossible).

-- 
				Petr "Pasky the Sleepy" Baudis
Stuff: http://pasky.or.cz/
Ever try. Ever fail. No matter. // Try again. Fail again. Fail better.
		-- Samuel Beckett
Previous: Erik MouwNext: Karl Hasselström
Message 2 of 4 in “Git string manipulation functions wrong?”
  1. Erik MouwMay 21, 2007
  2. Petr BaudisMay 21, 2007
  3. Karl HasselströmMay 21, 2007
  4. Kyle MoffettMay 23, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.