git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 16/68] archive-tar: use xsnprintf for trivial formatting

From
Jeff King <peff@peff.net>
Date
Sep 24, 2015, 21:06 UTC
Message-ID
<20150924210624.GM30946@sigill.intra.peff.net>
In-Reply-To
<20150924210225.GA23624@sigill.intra.peff.net>

When we generate tar headers, we sprintf() values directly into a struct with the fixed-size header values. For the most part this is fine, as we are formatting small values (e.g., the octal format of "mode & 0x7777" is of fixed length). But it's still a good idea to use xsnprintf here. It communicates to readers what our expectation is, and it provides a run-time check that we are not overflowing the buffers.

The one exception here is the mtime, which comes from the epoch time of the commit we are archiving. For sane values, this fits into the 12-byte value allocated in the header. But since git can handle 64-bit times, if I claim to be a visitor from the year 10,000 AD, I can overflow the buffer. This turns out to be harmless, as we simply overflow into the chksum field, which is then overwritten.

This case is also best as an xsnprintf. It should never come up, short of extremely malformed dates, and in that case we are probably better off dying than silently truncating the date value (and we cannot expand the size of the buffer, since it is dictated by the ustar format). Our friends in the year 5138 (when we legitimately flip to a 12-digit epoch) can deal with that problem then.

Signed-off-by: Jeff King <peff@peff.net>
---
 archive-tar.c | 26 +++++++++++++-------------
 1 file changed, 13 insertions(+), 13 deletions(-)
diff --git a/archive-tar.c b/archive-tar.c
index d543f93..501ca97 100644
--- a/archive-tar.c
+++ b/archive-tar.c
@@ -167,21 +167,21 @@ static void prepare_header(struct archiver_args *args,
 			   struct ustar_header *header,
 			   unsigned int mode, unsigned long size)
 {
-	sprintf(header->mode, "%07o", mode & 07777);
-	sprintf(header->size, "%011lo", S_ISREG(mode) ? size : 0);
-	sprintf(header->mtime, "%011lo", (unsigned long) args->time);
+	xsnprintf(header->mode, sizeof(header->mode), "%07o", mode & 07777);
+	xsnprintf(header->size, sizeof(header->size), "%011lo", S_ISREG(mode) ? size : 0);
+	xsnprintf(header->mtime, sizeof(header->mtime), "%011lo", (unsigned long) args->time);
 
-	sprintf(header->uid, "%07o", 0);
-	sprintf(header->gid, "%07o", 0);
+	xsnprintf(header->uid, sizeof(header->uid), "%07o", 0);
+	xsnprintf(header->gid, sizeof(header->gid), "%07o", 0);
 	strlcpy(header->uname, "root", sizeof(header->uname));
 	strlcpy(header->gname, "root", sizeof(header->gname));
-	sprintf(header->devmajor, "%07o", 0);
-	sprintf(header->devminor, "%07o", 0);
+	xsnprintf(header->devmajor, sizeof(header->devmajor), "%07o", 0);
+	xsnprintf(header->devminor, sizeof(header->devminor), "%07o", 0);
 
 	memcpy(header->magic, "ustar", 6);
 	memcpy(header->version, "00", 2);
 
-	sprintf(header->chksum, "%07o", ustar_header_chksum(header));
+	snprintf(header->chksum, sizeof(header->chksum), "%07o", ustar_header_chksum(header));
 }
 
 static int write_extended_header(struct archiver_args *args,
@@ -193,7 +193,7 @@ static int write_extended_header(struct archiver_args *args,
 	memset(&header, 0, sizeof(header));
 	*header.typeflag = TYPEFLAG_EXT_HEADER;
 	mode = 0100666;
-	sprintf(header.name, "%s.paxheader", sha1_to_hex(sha1));
+	xsnprintf(header.name, sizeof(header.name), "%s.paxheader", sha1_to_hex(sha1));
 	prepare_header(args, &header, mode, size);
 	write_blocked(&header, sizeof(header));
 	write_blocked(buffer, size);
@@ -235,8 +235,8 @@ static int write_tar_entry(struct archiver_args *args,
 			memcpy(header.prefix, path, plen);
 			memcpy(header.name, path + plen + 1, rest);
 		} else {
-			sprintf(header.name, "%s.data",
-				sha1_to_hex(sha1));
+			xsnprintf(header.name, sizeof(header.name), "%s.data",
+				  sha1_to_hex(sha1));
 			strbuf_append_ext_header(&ext_header, "path",
 						 path, pathlen);
 		}
@@ -259,8 +259,8 @@ static int write_tar_entry(struct archiver_args *args,
 
 	if (S_ISLNK(mode)) {
 		if (size > sizeof(header.linkname)) {
-			sprintf(header.linkname, "see %s.paxheader",
-			        sha1_to_hex(sha1));
+			xsnprintf(header.linkname, sizeof(header.linkname),
+				  "see %s.paxheader", sha1_to_hex(sha1));
 			strbuf_append_ext_header(&ext_header, "linkpath",
 			                         buffer, size);
 		} else
-- 
2.6.0.rc3.454.g204ad51
Previous: Jeff KingNext: Jeff King
Message 17 of 93 in “war on sprintf”
  1. 0/68 war on sprintfJeff King, Sep 24, 2015
  2. 01/68 show-branch: avoid segfault with --reflog of unborn branchJeff King, Sep 24, 2015
  3. 02/68 mailsplit: fix FILE* leak in split_maildirJeff King, Sep 24, 2015
  4. 03/68 archive-tar: fix minor indentation violationJeff King, Sep 24, 2015
  5. 04/68 fsck: don't fsck alternates for connectivity-only checkJeff King, Sep 24, 2015
  6. 05/68 add xsnprintf helper functionJeff King, Sep 24, 2015
  7. 06/68 add git_path_buf helper functionJeff King, Sep 24, 2015
  8. 07/68 strbuf: make strbuf_complete_line more genericJeff King, Sep 24, 2015
  9. 08/68 add reentrant variants of sha1_to_hex and find_unique_abbrevJeff King, Sep 24, 2015
  10. 09/68 fsck: use strbuf to generate alternate directoriesJeff King, Sep 24, 2015
  11. 10/68 mailsplit: make PATH_MAX buffers dynamicJeff King, Sep 24, 2015
  12. 11/68 trace: use strbuf for quote_crnl outputJeff King, Sep 24, 2015
  13. 12/68 progress: store throughput display in a strbufJeff King, Sep 24, 2015
  14. 13/68 test-dump-cache-tree: avoid overflow of cache-tree nameJeff King, Sep 24, 2015
  15. 14/68 compat/inet_ntop: fix off-by-one in inet_ntop4Jeff King, Sep 24, 2015
  16. 15/68 convert trivial sprintf / strcpy calls to xsnprintfJeff King, Sep 24, 2015
  17. 16/68 archive-tar: use xsnprintf for trivial formattingJeff King, Sep 24, 2015
  18. 17/68 use xsnprintf for generating git object headersJeff King, Sep 24, 2015
  19. 18/68 find_short_object_filename: convert sprintf to xsnprintfJeff King, Sep 24, 2015
  20. 19/68 stop_progress_msg: convert sprintf to xsnprintfJeff King, Sep 24, 2015
  21. 20/68 compat/hstrerror: convert sprintf to snprintfJeff King, Sep 24, 2015
  22. 21/68 grep: use xsnprintf to format failure messageJeff King, Sep 24, 2015
  23. 22/68 entry.c: convert strcpy to xsnprintfJeff King, Sep 24, 2015
  24. 23/68 add_packed_git: convert strcpy into xsnprintfJeff King, Sep 24, 2015
  25. 24/68 http-push: replace strcat with xsnprintfJeff King, Sep 24, 2015
  26. 25/68 receive-pack: convert strncpy to xsnprintfJeff King, Sep 24, 2015
  27. 26/68 replace trivial malloc + sprintf / strcpy calls with xstrfmtJeff King, Sep 24, 2015
  28. 27/68 config: use xstrfmt in normalize_valueJeff King, Sep 24, 2015
  29. 28/68 fetch: replace static buffer with xstrfmtJeff King, Sep 24, 2015
  30. 29/68 use strip_suffix and xstrfmt to replace suffixJeff King, Sep 24, 2015
  31. 30/68 ref-filter: drop sprintf and strcpy callsJeff King, Sep 24, 2015
  32. 31/68 help: drop prepend function in favor of xstrfmtJeff King, Sep 24, 2015
  33. 32/68 mailmap: replace strcpy with xstrdupJeff King, Sep 24, 2015
  34. 33/68 read_branches_file: simplify string handlingJeff King, Sep 24, 2015
  35. 34/68 read_remotes_file: simplify string handlingJeff King, Sep 24, 2015
  36. 35/68 resolve_ref: use strbufs for internal buffersJeff King, Sep 24, 2015
  37. 36/68 upload-archive: convert sprintf to strbufJeff King, Sep 24, 2015
  38. 37/68 remote-ext: simplify git pkt-line generationJeff King, Sep 24, 2015
  39. 38/68 http-push: use strbuf instead of fwrite_bufferJeff King, Sep 24, 2015
  40. 39/68 http-walker: store url in a strbufJeff King, Sep 24, 2015
  41. 40/68 sha1_get_pack_name: use a strbufJeff King, Sep 24, 2015
  42. 41/68 init: use strbufs to store pathsJeff King, Sep 24, 2015
  43. Michael BlumeSep 29, 2015
  44. Jeff KingSep 30, 2015
  45. Junio C HamanoSep 30, 2015
  46. Jeff KingOct 1, 2015
  47. Torsten BögershausenOct 2, 2015
  48. Jeff KingOct 2, 2015
  49. Torsten BögershausenOct 3, 2015
  50. Junio C HamanoOct 3, 2015
  51. Torsten BögershausenOct 3, 2015
  52. Jeff KingOct 4, 2015
  53. Torsten BögershausenOct 4, 2015
  54. Jeff KingOct 5, 2015
  55. 1/3 precompose_utf8: drop unused variableJeff King, Oct 5, 2015
  56. Torsten BögershausenOct 6, 2015
  57. 2/3 probe_utf8_pathname_composition: use internal strbufJeff King, Oct 5, 2015
  58. 3/3 init: use strbufs to store pathsJeff King, Oct 5, 2015
  59. 42/68 apply: convert root string to strbufJeff King, Sep 24, 2015
  60. 43/68 transport: use strbufs for status table "quickref" stringsJeff King, Sep 24, 2015
  61. 44/68 merge-recursive: convert malloc / strcpy to strbufJeff King, Sep 24, 2015
  62. 45/68 enter_repo: convert fixed-size buffers to strbufsJeff King, Sep 24, 2015
  63. 46/68 remove_leading_path: use a strbuf for internal storageJeff King, Sep 24, 2015
  64. 47/68 write_loose_object: convert to strbufJeff King, Sep 24, 2015
  65. 48/68 diagnose_invalid_index_path: use strbuf to avoid strcpy/strcatJeff King, Sep 24, 2015
  66. 49/68 fetch-pack: use argv_array for index-pack / unpack-objectsJeff King, Sep 24, 2015
  67. 50/68 http-push: use an argv_array for setup_revisionsJeff King, Sep 24, 2015
  68. 51/68 stat_tracking_info: convert to argv_arrayJeff King, Sep 24, 2015
  69. 52/68 daemon: use cld->env_array when re-spawningJeff King, Sep 24, 2015
  70. 53/68 use sha1_to_hex_r() instead of strcpyJeff King, Sep 24, 2015
  71. 54/68 drop strcpy in favor of raw sha1_to_hexJeff King, Sep 24, 2015
  72. Eric SunshineSep 24, 2015
  73. Jeff KingSep 25, 2015
  74. 55/68 color: add overflow checks for parsing colorsJeff King, Sep 24, 2015
  75. 56/68 use alloc_ref rather than hand-allocating "struct ref"Jeff King, Sep 24, 2015
  76. 57/68 avoid sprintf and strcpy with flex arraysJeff King, Sep 24, 2015
  77. 58/68 receive-pack: simplify keep_arg computationJeff King, Sep 24, 2015
  78. 59/68 help: clean up kfmclient mungingJeff King, Sep 24, 2015
  79. 60/68 prefer memcpy to strcpyJeff King, Sep 24, 2015
  80. René ScharfeSep 27, 2015
  81. Torsten BögershausenSep 27, 2015
  82. René ScharfeSep 27, 2015
  83. René ScharfeSep 27, 2015
  84. Rasmus VillemoesSep 28, 2015
  85. 61/68 color: add color_set helper for copying raw colorsJeff King, Sep 24, 2015
  86. 62/68 notes: document length of fanout path with a constantJeff King, Sep 24, 2015
  87. 63/68 convert strncpy to memcpyJeff King, Sep 24, 2015
  88. 64/68 fsck: drop inode-sorting codeJeff King, Sep 24, 2015
  89. 65/68 Makefile: drop D_INO_IN_DIRENT build knobJeff King, Sep 24, 2015
  90. 66/68 fsck: use for_each_loose_file_in_objdirJeff King, Sep 24, 2015
  91. Jeff KingSep 26, 2015
  92. 67/68 use strbuf_complete to conditionally append slashJeff King, Sep 24, 2015
  93. 68/68 name-rev: use strip_suffix to avoid magic numbersJeff King, Sep 24, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.