git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] remote-curl: Add a format check to parsing of info/refs

From
Julian Phillips <julian@quantumfyre.co.uk>
Date
Jul 16, 2011, 18:23 UTC
Message-ID
<20110716182352.85371.18215.julian@quantumfyre.co.uk>

When parsing info/refs, no checks were applied that the file was in the requried format. Since the file is read from a remote webserver, this isn't guarenteed to be true. Add a check that the file at least only contains lines that consist of 40 characters followed by a tab and then the ref name.

Signed-off-by: Julian Phillips <julian@quantumfyre.co.uk>
---

If you happen to try, for example, git ls-remote http://example.com/foo, when http://example.com/foo/info/refs exists - but isn't part of a git repository you get a very strange response as remote-curl.c attempts to parse refs out of the file. This may be an unlikely situtation, but that doesn't mean it can't be hanlded a little better.

Julian
 remote-curl.c |    2 ++
 1 files changed, 2 insertions(+), 0 deletions(-)
diff --git a/remote-curl.c b/remote-curl.c
index b5be25c..8ac5028 100644
--- a/remote-curl.c
+++ b/remote-curl.c
@@ -227,6 +227,8 @@ static struct ref *parse_info_refs(struct discovery *heads)
 		if (data[i] == '\t')
 			mid = &data[i];
 		if (data[i] == '\n') {
+			if (mid - start != 40)
+				die("%sinfo/refs not valid: is this a git repository?", url);
 			data[i] = 0;
 			ref_name = mid + 1;
 			ref = xmalloc(sizeof(struct ref) +
-- 
1.7.6
Message 1 of 1 in “remote-curl: Add a format check to parsing of info/refs”
  1. remote-curl: Add a format check to parsing of info/refsJulian Phillips, Jul 16, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.