git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] builtin/mv: fix out of bounds write

From
John Keeping <john@keeping.me.uk>
Date
Mar 8, 2014, 18:35 UTC
Message-ID
<20140308183501.GH18371@serenity.lan>
In-Reply-To
<20140308181218.GG18371@serenity.lan>

When commit a88c915 (mv: move submodules using a gitfile, 2013-07-30) added the submodule_gitfile array, it was not added to the block that enlarges the arrays when we are moving a directory so that we do not have to worry about it being a directory when we perform the actual move. After this, the loop continues over the enlarged set of sources.

Since we assume that submodule_gitfile has size argc, if any of the items in the source directory are submodules we are guaranteed to write beyond the end of submodule_gitfile.

Fix this by realloc'ing submodule_gitfile at the same time as the other arrays.

Reported-by: Guillaume Gelin <contact@ramnes.eu>
Signed-off-by: John Keeping <john@keeping.me.uk>
---
On Sat, Mar 08, 2014 at 06:12:18PM +0000, John Keeping wrote:
> This fixes it for me:
Here it is as a proper patch.
 builtin/mv.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/builtin/mv.c b/builtin/mv.c
index 21c46d1..f99c91e 100644
--- a/builtin/mv.c
+++ b/builtin/mv.c
@@ -179,6 +179,9 @@ int cmd_mv(int argc, const char **argv, const char *prefix)
 						modes = xrealloc(modes,
 								(argc + last - first)
 								* sizeof(enum update_mode));
+						submodule_gitfile = xrealloc(submodule_gitfile,
+								(argc + last - first)
+								* sizeof(char *));
 					}
 
 					dst = add_slash(dst);
-- 
1.9.0.6.g037df60.dirty
Previous: John KeepingNext: brian m. carlson
Message 4 of 21 in “git 1.9.0 segfault”
  1. Guillaume GelinMar 8, 2014
  2. brian m. carlsonMar 8, 2014
  3. John KeepingMar 8, 2014
  4. builtin/mv: fix out of bounds writeJohn Keeping, Mar 8, 2014
  5. brian m. carlsonMar 8, 2014
  6. builtin/mv: fix out of bounds writeJohn Keeping, Mar 8, 2014
  7. mv: prevent mismatched data when ignoring errors.brian m. carlson, Mar 8, 2014
  8. Jeff KingMar 11, 2014
  9. brian m. carlsonMar 11, 2014
  10. Junio C HamanoMar 11, 2014
  11. brian m. carlsonMar 12, 2014
  12. Thomas RastMar 15, 2014
  13. Jeff KingMar 16, 2014
  14. Junio C HamanoMar 16, 2014
  15. Junio C HamanoMar 17, 2014
  16. Michael HaggertyMar 17, 2014
  17. Eric SunshineMar 17, 2014
  18. Jeff KingMar 17, 2014
  19. Junio C HamanoMar 18, 2014
  20. mv: prevent mismatched data when ignoring errors.brian m. carlson, Mar 15, 2014
  21. Jeff KingMar 16, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.