git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] http.c: don't rewrite the user:passwd string multiple times

From
Jeff King <peff@peff.net>
Date
Jun 19, 2013, 05:26 UTC
Message-ID
<20130619052613.GA17500@sigill.intra.peff.net>
In-Reply-To
<1371609829-31813-1-git-send-email-bcasey@nvidia.com>
On Tue, Jun 18, 2013 at 07:43:49PM -0700, Brandon Casey wrote:
Show 19 quoted lines
> From: Brandon Casey <drafnel@gmail.com>
> 
> Curl older than 7.17 (RHEL 4.X provides 7.12 and RHEL 5.X provides
> 7.15) requires that we manage any strings that we pass to it as
> pointers.  So, we really shouldn't be modifying this strbuf after we
> have passed it to curl.
> 
> Our interaction with curl is currently safe (before or after this
> patch) since the pointer that is passed to curl is never invalidated;
> it is repeatedly rewritten with the same sequence of characters but
> the strbuf functions never need to allocate a larger string, so the
> same memory buffer is reused.
> 
> This "guarantee" of safety is somewhat subtle and could be overlooked
> by someone who may want to add a more complex handling of the username
> and password.  So, let's stop modifying this strbuf after we have
> passed it to curl, but also leave a note to describe the assumptions
> that have been made about username/password lifetime and to draw
> attention to the code.
Thanks.
Acked-by: Jeff King <peff@peff.net>
-Peff
Previous: Brandon CaseyNext: Daniel Stenberg
Message 10 of 11 in “http.c: don't rewrite the user:passwd string multiple times”
  1. http.c: don't rewrite the user:passwd string multiple timesBrandon Casey, Jun 18, 2013
  2. Eric SunshineJun 18, 2013
  3. Jeff KingJun 18, 2013
  4. Daniel StenbergJun 18, 2013
  5. Junio C HamanoJun 18, 2013
  6. Brandon CaseyJun 18, 2013
  7. Jeff KingJun 18, 2013
  8. Brandon CaseyJun 19, 2013
  9. http.c: don't rewrite the user:passwd string multiple timesBrandon Casey, Jun 19, 2013
  10. Jeff KingJun 19, 2013
  11. Daniel StenbergJun 19, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.