git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] setup_revisions(): do not access outside argv

From
Jeff King <peff@peff.net>
Date
May 22, 2009, 15:34 UTC
Message-ID
<20090522153426.GA10390@coredump.intra.peff.net>
In-Reply-To
<Ys7Cih8N_SClhy9WmlLefLAxz2_XjZb3KAO1jrRMNrMcLq4T98MuIA@cipher.nrlssc.navy.mil>
On Fri, May 22, 2009 at 10:33:22AM -0500, Brandon Casey wrote:
Show 17 quoted lines
> >  		if (S_ISLNK(st.st_mode)) {
> > -			int ret;
> > -			char buf[PATH_MAX + 1]; /* ought to be SYMLINK_MAX */
> > -			ret = readlink(name, buf, sizeof(buf));
> > -			if (ret < 0)
> > +			struct strbuf sb = STRBUF_INIT;
> > +			if (strbuf_readlink(&sb, name, st.st_size) < 0)
> >  				die("readlink(%s)", name);
> > -			if (ret == sizeof(buf))
> > -				die("symlink too long: %s", name);
> > -			prep_temp_blob(name, temp, buf, ret,
> > +			prep_temp_blob(name, temp, sb.buf, sb.len,
> >  				       (one->sha1_valid ?
> >  					one->sha1 : null_sha1),
> >  				       (one->sha1_valid ?
> 
> Don't you need to strbuf_release() ?
Urgh, yes, of course. Thanks for noticing.
-Peff
Previous: Brandon CaseyNext: Jeff King
Message 13 of 16 in “setup_revisions(): do not access outside argv”
  1. setup_revisions(): do not access outside argvNguyễn Thái Ngọc Duy, May 20, 2009
  2. Johannes SixtMay 20, 2009
  3. Nguyen Thai Ngoc DuyMay 20, 2009
  4. Junio C HamanoMay 21, 2009
  5. Miles BaderMay 21, 2009
  6. Nguyen Thai Ngoc DuyMay 21, 2009
  7. Jeff KingMay 21, 2009
  8. Thomas JaroschMay 21, 2009
  9. Jeff KingMay 22, 2009
  10. Jeff KingMay 22, 2009
  11. Thomas JaroschMay 22, 2009
  12. Brandon CaseyMay 22, 2009
  13. Jeff KingMay 22, 2009
  14. convert bare readlink to strbuf_readlinkJeff King, May 25, 2009
  15. Junio C HamanoMay 25, 2009
  16. Jeff KingJun 2, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.