git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] fast-import: validate entire ident string

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Apr 26, 2010, 16:30 UTC
Message-ID
<20100426163032.GB10859@progeny.tock>
In-Reply-To
<20100426162422.GA10859@progeny.tock>
Jonathan Nieder wrote:
Show 9 quoted lines
> -		lb = strstr(a + 8, " <");
> -		rb = strstr(a + 8, "> ");
> -		eol = strchr(a + 8, '\n');
> +		n = a + strlen("\nauthor");
> +		lb = strstr(n, " <");
> +		rb = strstr(lb + 2, "> ");
> +		eol = strchr(rb + 2, '\n');
>  		if (!lb || !rb || !eol)
>  			die("invalid commit: %s", use_message);
Err, this will segv when it fails; better to use
	lb = a + strlen("\nauthor ");
	lb = strchrnul(lb, '<');
	rb = strchrnul(lb, '>');
	eol = strchrnul(rb, '\n');
	if (!*lb || !*rb || !*eol)
		die("invalid commit: %s", use_message);
This is even more permissive, but I think that’s okay.

Sorry for the noise. Jonathan

Previous: Jonathan NiederNext: Junio C Hamano
Message 10 of 13 in “fast-import docs: LT is valid in email, GT is not”
  1. fast-import docs: LT is valid in email, GT is notMark Lodato, Apr 24, 2010
  2. fsck: check ident lines in commit objectsJonathan Nieder, Apr 24, 2010
  3. Jonathan NiederApr 24, 2010
  4. Shawn O. PearceApr 24, 2010
  5. 0/2 fast-import: tighten up parsing ident lineJonathan Nieder, Apr 24, 2010
  6. 1/2 fast-import: be strict about formatting of raw datesJonathan Nieder, Apr 24, 2010
  7. 2/2 fast-import: validate entire ident stringJonathan Nieder, Apr 24, 2010
  8. Shawn O. PearceApr 26, 2010
  9. Jonathan NiederApr 26, 2010
  10. Jonathan NiederApr 26, 2010
  11. Junio C HamanoMay 4, 2010
  12. Jonathan NiederApr 24, 2010
  13. Mark LodatoApr 24, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.