git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 3/4] sequencer: fix "rebase -i --root" corrupting author header timestamp

From
Eric Sunshine <sunshine@sunshineco.com>
Date
Jul 31, 2018, 07:33 UTC
Message-ID
<20180731073331.40007-4-sunshine@sunshineco.com>
In-Reply-To
<20180731073331.40007-1-sunshine@sunshineco.com>

When "git rebase -i --root" creates a new root commit, it corrupts the "author" header's timestamp by prepending a "@":

    author A U Thor <author@example.com> @1112912773 -0700

The commit parser is very strict about the format of the "author" header, and does not allow a "@" in that position.

The "@" comes from GIT_AUTHOR_DATE in "rebase-merge/author-script", signifying a Unix epoch-based timestamp, however, read_author_ident() incorrectly allows it to slip into the commit's "author" header, thus corrupting it.

One possible fix would be simply to filter out the "@" when constructing the "author" header timestamp, however, a more correct fix is to parse the GIT_AUTHOR_DATE date (via parse_date()) and format the parsed result into the "author" header. Since "rebase-merge/author-script" may be edited by the user, this approach has the extra benefit of catching other potential timestamp corruption due to hand-editing.

We can do better than calling parse_date() ourselves and constructing the "author" header manually, however, by instead taking advantage of fmt_ident() which does this work for us.

The benefits of using fmt_ident() are twofold. First, it simplifies the logic considerably by allowing us to avoid the complexity of building the "author" header in parallel with and in the same buffer from which "rebase-merge/author-script" is being parsed. Instead, fmt_ident() is invoked to compose the header after parsing is complete.

Second, fmt_ident() is careful to prevent "crud" from polluting the composed ident. As with validating GIT_AUTHOR_DATE, this "crud" avoidance prevents other (possibly hand-edited) bogus author information from "rebase-merge/author-script" from corrupting the commit object.

Signed-off-by: Eric Sunshine <sunshine@sunshineco.com>
---
 sequencer.c                   | 23 +++++++++--------------
 t/t3404-rebase-interactive.sh |  2 +-
 2 files changed, 10 insertions(+), 15 deletions(-)
diff --git a/sequencer.c b/sequencer.c
index 1008f6d71a..15a66a334c 100644
--- a/sequencer.c
+++ b/sequencer.c
@@ -709,14 +709,16 @@ static const char *read_author_ident(struct strbuf *buf)
 	const char *keys[] = {
 		"GIT_AUTHOR_NAME=", "GIT_AUTHOR_EMAIL=", "GIT_AUTHOR_DATE="
 	};
-	char *in, *out, *eol;
-	int i = 0, len;
+	struct strbuf out = STRBUF_INIT;
+	char *in, *eol;
+	const char *val[3];
+	int i = 0;
 
 	if (strbuf_read_file(buf, rebase_path_author_script(), 256) <= 0)
 		return NULL;
 
 	/* dequote values and construct ident line in-place */
-	for (in = out = buf->buf; i < 3 && in - buf->buf < buf->len; i++) {
+	for (in = buf->buf; i < 3 && in - buf->buf < buf->len; i++) {
 		if (!skip_prefix(in, keys[i], (const char **)&in)) {
 			warning("could not parse '%s' (looking for '%s'",
 				rebase_path_author_script(), keys[i]);
@@ -730,16 +732,7 @@ static const char *read_author_ident(struct strbuf *buf)
 				keys[i], rebase_path_author_script());
 			return NULL;
 		}
-		len = strlen(in);
-
-		if (i > 0) /* separate values by spaces */
-			*(out++) = ' ';
-		if (i == 1) /* email needs to be surrounded by <...> */
-			*(out++) = '<';
-		memmove(out, in, len);
-		out += len;
-		if (i == 1) /* email needs to be surrounded by <...> */
-			*(out++) = '>';
+		val[i] = in;
 		in = eol + 1;
 	}
 
@@ -749,7 +742,9 @@ static const char *read_author_ident(struct strbuf *buf)
 		return NULL;
 	}
 
-	strbuf_setlen(buf, out - buf->buf);
+	strbuf_addstr(&out, fmt_ident(val[0], val[1], val[2], 0));
+	strbuf_swap(buf, &out);
+	strbuf_release(&out);
 	return buf->buf;
 }
 
diff --git a/t/t3404-rebase-interactive.sh b/t/t3404-rebase-interactive.sh
index fd3a18154e..d340018781 100755
--- a/t/t3404-rebase-interactive.sh
+++ b/t/t3404-rebase-interactive.sh
@@ -1420,7 +1420,7 @@ test_expect_success 'valid author header after --root swap' '
 	set_fake_editor &&
 	FAKE_LINES="2 1" git rebase -i --root &&
 	git cat-file commit HEAD^ >out &&
-	grep "^author ..*> @[0-9][0-9]* [-+][0-9][0-9][0-9][0-9]$" out
+	grep "^author ..*> [0-9][0-9]* [-+][0-9][0-9][0-9][0-9]$" out
 '
 
 test_done
-- 
2.18.0.267.gbc8be36ecb
Previous: Eric SunshineNext: Phillip Wood
Message 9 of 57 in “fix "rebase -i --root" corrupting root commit”
  1. 0/4 fix "rebase -i --root" corrupting root commitEric Sunshine, Jul 31, 2018
  2. 1/4 sequencer: fix "rebase -i --root" corrupting author headerEric Sunshine, Jul 31, 2018
  3. 2/4 sequencer: fix "rebase -i --root" corrupting author header timezoneEric Sunshine, Jul 31, 2018
  4. Phillip WoodJul 31, 2018
  5. Eric SunshineJul 31, 2018
  6. 4/4 sequencer: don't die() on bogus user-edited timestampEric Sunshine, Jul 31, 2018
  7. Phillip WoodJul 31, 2018
  8. Eric SunshineJul 31, 2018
  9. 3/4 sequencer: fix "rebase -i --root" corrupting author header timestampEric Sunshine, Jul 31, 2018
  10. Phillip WoodJul 31, 2018
  11. Eric SunshineJul 31, 2018
  12. Phillip WoodJul 31, 2018
  13. Eric SunshineJul 31, 2018
  14. Phillip WoodJul 31, 2018
  15. Eric SunshineJul 31, 2018
  16. 0/2 Fix author script quotingPhillip Wood, Jul 31, 2018
  17. 1/2 sequencer: handle errors in read_author_ident()Phillip Wood, Jul 31, 2018
  18. Eric SunshineJul 31, 2018
  19. Phillip WoodAug 1, 2018
  20. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Jul 31, 2018
  21. Eric SunshineJul 31, 2018
  22. Phillip WoodAug 1, 2018
  23. Junio C HamanoAug 1, 2018
  24. Phillip WoodAug 1, 2018
  25. Eric SunshineAug 1, 2018
  26. Hilco WijbengaAug 1, 2018
  27. Eric SunshineAug 1, 2018
  28. Hilco WijbengaAug 7, 2018
  29. Eric SunshineAug 7, 2018
  30. Junio C HamanoAug 7, 2018
  31. Johannes SchindelinAug 27, 2018
  32. brian m. carlsonAug 1, 2018
  33. Eric SunshineAug 2, 2018
  34. 0/2 Fix author script quotingPhillip Wood, Aug 2, 2018
  35. 1/2 sequencer: handle errors in read_author_ident()Phillip Wood, Aug 2, 2018
  36. Eric SunshineAug 3, 2018
  37. Junio C HamanoAug 3, 2018
  38. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Aug 2, 2018
  39. Junio C HamanoAug 2, 2018
  40. Eric SunshineAug 3, 2018
  41. Phillip WoodAug 3, 2018
  42. Eric SunshineAug 3, 2018
  43. Phillip WoodAug 3, 2018
  44. Junio C HamanoAug 7, 2018
  45. 0/2 fix author-script quotingPhillip Wood, Aug 7, 2018
  46. 1/2 sequencer: handle errors from read_author_ident()Phillip Wood, Aug 7, 2018
  47. Eric SunshineAug 8, 2018
  48. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Aug 7, 2018
  49. Eric SunshineAug 7, 2018
  50. Phillip WoodAug 7, 2018
  51. Eric SunshineAug 8, 2018
  52. Junio C HamanoAug 8, 2018
  53. Phillip WoodAug 9, 2018
  54. Phillip WoodAug 9, 2018
  55. Eric SunshineAug 8, 2018
  56. Phillip WoodAug 9, 2018
  57. Eric SunshineAug 8, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.