git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] setup_revisions(): do not access outside argv

From
Jeff King <peff@peff.net>
Date
May 21, 2009, 04:18 UTC
Message-ID
<20090521041812.GE8091@sigill.intra.peff.net>
In-Reply-To
<7v7i0btdwu.fsf@alter.siamese.dyndns.org>
On Wed, May 20, 2009 at 06:58:41PM -0700, Junio C Hamano wrote:
Show 14 quoted lines
> If a function takes (int ac, char **av), then people should be able to
> depend on the usual convention of
> 
>  (1) for any i < ac, av[i] is not NULL; and
>  (2) av[ac] is NULL.
> 
> With your patch, a broken caller's wish is simply discarded and nobody
> will notice.  Without your patch, at least you will know that the caller
> passed an inconsistent pair of ac and av to this function by seeing a
> coalmine canary segfault.
> 
> I would not mind a patch that adds an assertion that protects this
> function from broken callers, so that we can find them, but your patch
> makes me feel very uneasy.
I agree.

Having just fixed a segfault in the GIT_TRACE code caused by a non-terminated argv generated by the alias code, I think I would prefer that we just consistently do the NULL-termination. You are otherwise creating a maintenance pitfall when somebody later passes the value to unsuspecting code.

-Peff
Previous: Nguyen Thai Ngoc DuyNext: Thomas Jarosch
Message 7 of 16 in “setup_revisions(): do not access outside argv”
  1. setup_revisions(): do not access outside argvNguyễn Thái Ngọc Duy, May 20, 2009
  2. Johannes SixtMay 20, 2009
  3. Nguyen Thai Ngoc DuyMay 20, 2009
  4. Junio C HamanoMay 21, 2009
  5. Miles BaderMay 21, 2009
  6. Nguyen Thai Ngoc DuyMay 21, 2009
  7. Jeff KingMay 21, 2009
  8. Thomas JaroschMay 21, 2009
  9. Jeff KingMay 22, 2009
  10. Jeff KingMay 22, 2009
  11. Thomas JaroschMay 22, 2009
  12. Brandon CaseyMay 22, 2009
  13. Jeff KingMay 22, 2009
  14. convert bare readlink to strbuf_readlinkJeff King, May 25, 2009
  15. Junio C HamanoMay 25, 2009
  16. Jeff KingJun 2, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.