Re: [PATCH 2/2] fast-import: validate entire ident string
- From
Jonathan Nieder <jrnieder@gmail.com>
- Date
- Apr 26, 2010, 16:30 UTC
- Message-ID
- <20100426163032.GB10859@progeny.tock>
- In-Reply-To
- <20100426162422.GA10859@progeny.tock>
Jonathan Nieder wrote:
Show 9 quoted lines
> - lb = strstr(a + 8, " <");
> - rb = strstr(a + 8, "> ");
> - eol = strchr(a + 8, '\n');
> + n = a + strlen("\nauthor");
> + lb = strstr(n, " <");
> + rb = strstr(lb + 2, "> ");
> + eol = strchr(rb + 2, '\n');
> if (!lb || !rb || !eol)
> die("invalid commit: %s", use_message);Err, this will segv when it fails; better to use
lb = a + strlen("\nauthor ");
lb = strchrnul(lb, '<');
rb = strchrnul(lb, '>');
eol = strchrnul(rb, '\n');
if (!*lb || !*rb || !*eol)
die("invalid commit: %s", use_message);This is even more permissive, but I think that’s okay.
Sorry for the noise. Jonathan