git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 1/4] fast-import: stricter parsing of integer options

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Nov 28, 2010, 19:42 UTC
Message-ID
<20101128194246.GB19998@burratino>
In-Reply-To
<20101128194131.GA19998@burratino>

Check the result from strtoul to avoid accepting arguments like --depth=-1 and --active-branches=foo,bar,baz.

Requested-by: Ramkumar Ramachandra <artagnon@gmail.com>
Signed-off-by: Jonathan Nieder <jrnieder@gmail.com>
---
See http://thread.gmane.org/gmane.comp.version-control.git/159117/focus=159236
for context.
 fast-import.c          |   13 +++++++++++--
 t/t9300-fast-import.sh |    8 ++++++++
 2 files changed, 19 insertions(+), 2 deletions(-)
diff --git a/fast-import.c b/fast-import.c
index 74f08bd..959afef 100644
--- a/fast-import.c
+++ b/fast-import.c
@@ -2745,16 +2745,25 @@ static void option_date_format(const char *fmt)
 		die("unknown --date-format argument %s", fmt);
 }
 
+static unsigned long ulong_arg(const char *option, const char *arg)
+{
+	char *endptr;
+	unsigned long rv = strtoul(arg, &endptr, 0);
+	if (strchr(arg, '-') || endptr == arg || *endptr)
+		die("%s: argument must be an unsigned integer", option);
+	return rv;
+}
+
 static void option_depth(const char *depth)
 {
-	max_depth = strtoul(depth, NULL, 0);
+	max_depth = ulong_arg("--depth", depth);
 	if (max_depth > MAX_DEPTH)
 		die("--depth cannot exceed %u", MAX_DEPTH);
 }
 
 static void option_active_branches(const char *branches)
 {
-	max_active_branches = strtoul(branches, NULL, 0);
+	max_active_branches = ulong_arg("--active-branches", branches);
 }
 
 static void option_export_marks(const char *marks)
diff --git a/t/t9300-fast-import.sh b/t/t9300-fast-import.sh
index 131f032..2c27da6 100755
--- a/t/t9300-fast-import.sh
+++ b/t/t9300-fast-import.sh
@@ -1528,6 +1528,14 @@ test_expect_success 'R: unknown commandline options are rejected' '\
     test_must_fail git fast-import --non-existing-option < /dev/null
 '
 
+test_expect_success 'R: die on invalid option argument' '
+	echo "option git active-branches=-5" |
+	test_must_fail git fast-import &&
+	echo "option git depth=" |
+	test_must_fail git fast-import &&
+	test_must_fail git fast-import --depth="5 elephants" </dev/null
+'
+
 cat >input <<EOF
 option non-existing-vcs non-existing-option
 EOF
Previous: Jonathan NiederNext: Junio C Hamano
Message 7 of 34 in “[PATCHv2] Add support for subversion dump format v3”
  1. David BarrOct 15, 2010
  2. 1/5 fast-import: Let importers retrieve blobsDavid Barr, Oct 15, 2010
  3. Ramkumar RamachandraOct 18, 2010
  4. Jonathan NiederOct 18, 2010
  5. Jonathan NiederOct 18, 2010
  6. 0/4 fast-import: Let importers retrieve blobsJonathan Nieder, Nov 28, 2010
  7. 1/4 fast-import: stricter parsing of integer optionsJonathan Nieder, Nov 28, 2010
  8. Junio C HamanoNov 30, 2010
  9. 2/4 fast-import: clarify documentation of "feature" commandJonathan Nieder, Nov 28, 2010
  10. 3/4 fast-import: let importers retrieve blobsJonathan Nieder, Nov 28, 2010
  11. fixup! fast-import: let importers retrieve blobsDavid Barr, Nov 29, 2010
  12. David BarrNov 30, 2010
  13. Jonathan NiederNov 30, 2010
  14. Thomas RastDec 3, 2010
  15. Jonathan NiederDec 3, 2010
  16. Junio C HamanoDec 3, 2010
  17. Jonathan NiederDec 3, 2010
  18. Thomas RastDec 4, 2010
  19. Jonathan NiederDec 4, 2010
  20. Documentation/fast-import: capitalize beginning of sentenceJonathan Nieder, Jan 16, 2011
  21. 4/4 fast-import: Allow cat-blob requests at arbitrary points in streamJonathan Nieder, Nov 28, 2010
  22. 2/5 vcs-svn: Extend svndump to parse version 3 formatDavid Barr, Oct 15, 2010
  23. 3/5 vcs-svn: Implement prop-delta handling.David Barr, Oct 15, 2010
  24. Ramkumar RamachandraOct 18, 2010
  25. 4/5 vcs-svn: Add outfile option to buffer_copy_bytes()David Barr, Oct 15, 2010
  26. Jonathan NiederOct 18, 2010
  27. 5/5 svn-fe: Use the cat-blob command to apply deltasDavid Barr, Oct 15, 2010
  28. Ramkumar RamachandraOct 18, 2010
  29. Jonathan NiederOct 18, 2010
  30. Ramkumar RamachandraOct 18, 2010
  31. Jonathan NiederOct 18, 2010
  32. 3/4 fast-import: let importers retrieve blobsJonathan Nieder, Nov 19, 2010
  33. 4/4 fast-import: Allow cat-blob requests at arbitrary points in streamJonathan Nieder, Nov 19, 2010
  34. Sverre RabbelierNov 19, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.