git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 2/6] archive-tar: use match_config_key when parsing config

From
Jeff King <peff@peff.net>
Date
Jan 14, 2013, 15:02 UTC
Message-ID
<20130114150256.GB16828@sigill.intra.peff.net>
In-Reply-To
<20130114145845.GA16497@sigill.intra.peff.net>

This is fewer lines of code, but more importantly, fixes a bogus pointer offset. We are looking for "tar." in the section, but later assume that the dot we found is at offset 9, not 3. This is a holdover from an earlier iteration of 767cf45 which called the section "tarfilter".

As a result, we could erroneously reject some filters with dots in their name, as well as read uninitialized memory.

Reported by (and test by) René Scharfe.
Signed-off-by: Jeff King <peff@peff.net>
---
This obviously replaces René's patch. It might make more sense to just
put his patch onto maint, and build this on top; then this patch can get
squashed into the next one (which just updates the uninteresting
callsites).
 archive-tar.c       | 10 +---------
 t/t5000-tar-tree.sh |  3 ++-
 2 files changed, 3 insertions(+), 10 deletions(-)
diff --git a/archive-tar.c b/archive-tar.c
index 0ba3f25..68dbe59 100644
--- a/archive-tar.c
+++ b/archive-tar.c
@@ -325,20 +325,12 @@ static int tar_filter_config(const char *var, const char *value, void *data)
 static int tar_filter_config(const char *var, const char *value, void *data)
 {
 	struct archiver *ar;
-	const char *dot;
 	const char *name;
 	const char *type;
 	int namelen;
 
-	if (prefixcmp(var, "tar."))
+	if (match_config_key(var, "tar", &name, &namelen, &type) < 0 || !name)
 		return 0;
-	dot = strrchr(var, '.');
-	if (dot == var + 9)
-		return 0;
-
-	name = var + 4;
-	namelen = dot - name;
-	type = dot + 1;
 
 	ar = find_tar_filter(name, namelen);
 	if (!ar) {
diff --git a/t/t5000-tar-tree.sh b/t/t5000-tar-tree.sh
index ecf00ed..517ae04 100755
--- a/t/t5000-tar-tree.sh
+++ b/t/t5000-tar-tree.sh
@@ -283,7 +283,8 @@ test_expect_success 'setup tar filters' '
 test_expect_success 'setup tar filters' '
 	git config tar.tar.foo.command "tr ab ba" &&
 	git config tar.bar.command "tr ab ba" &&
-	git config tar.bar.remote true
+	git config tar.bar.remote true &&
+	git config tar.invalid baz
 '
 
 test_expect_success 'archive --list mentions user filter' '
-- 
1.8.1.rc1.10.g7d71f7b
Previous: Jonathan NiederNext: Jeff King
Message 24 of 31 in “archive-tar: fix sanity check in config parsing”
  1. archive-tar: fix sanity check in config parsingRené Scharfe, Jan 13, 2013
  2. Jeff KingJan 13, 2013
  3. Joachim SchmitzJan 14, 2013
  4. Jeff KingJan 14, 2013
  5. Jeff KingJan 14, 2013
  6. 1/6 config: add helper function for parsing key namesJeff King, Jan 14, 2013
  7. Junio C HamanoJan 14, 2013
  8. Jeff KingJan 15, 2013
  9. Junio C HamanoJan 15, 2013
  10. Junio C HamanoJan 18, 2013
  11. 0/8 config key-parsing cleanupsJeff King, Jan 23, 2013
  12. 1/8 config: add helper function for parsing key namesJeff King, Jan 23, 2013
  13. 2/8 archive-tar: use parse_config_key when parsing configJeff King, Jan 23, 2013
  14. 3/8 convert some config callbacks to parse_config_keyJeff King, Jan 23, 2013
  15. 4/8 userdiff: drop parse_driver functionJeff King, Jan 23, 2013
  16. 5/8 submodule: use parse_config_key when parsing configJeff King, Jan 23, 2013
  17. Jens LehmannJan 23, 2013
  18. 6/8 submodule: simplify memory handling in config parsingJeff King, Jan 23, 2013
  19. Jens LehmannJan 23, 2013
  20. 7/8 help: use parse_config_key for man configJeff King, Jan 23, 2013
  21. 8/8 reflog: use parse_config_key in config callbackJeff King, Jan 23, 2013
  22. Junio C HamanoJan 23, 2013
  23. Jonathan NiederJan 23, 2013
  24. 2/6 archive-tar: use match_config_key when parsing configJeff King, Jan 14, 2013
  25. 3/6 convert some config callbacks to match_config_keyJeff King, Jan 14, 2013
  26. Jonathan NiederJan 14, 2013
  27. Jeff KingJan 14, 2013
  28. Jeff KingJan 14, 2013
  29. 4/6 userdiff: drop parse_driver functionJeff King, Jan 14, 2013
  30. 5/6 submodule: use match_config_key when parsing configJeff King, Jan 14, 2013
  31. 6/6 submodule: simplify memory handling in config parsingJeff King, Jan 14, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.