git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 0/3] fixing some parse_commit() timestamp corner cases

From
Jeff King <peff@peff.net>
Date
Apr 25, 2023, 05:54 UTC
Message-ID
<20230425055442.GA4015600@coredump.intra.peff.net>
In-Reply-To
<20230425055244.GA4014505@coredump.intra.peff.net>
On Tue, Apr 25, 2023 at 01:52:45AM -0400, Jeff King wrote:
Show 15 quoted lines
> Here's a v2 of my series. The behavior should be identical, but I've
> incorporated some comment and small code tweaks based on feedback from
> the first round.
> 
> I also added a fourth patch which adds a new comment explaining some of
> the cases that were alluded to in the earlier round's patch 3.
> 
>   [1/4]: t4212: avoid putting git on left-hand side of pipe
>   [2/4]: parse_commit(): parse timestamp from end of line
>   [3/4]: parse_commit(): handle broken whitespace-only timestamp
>   [4/4]: parse_commit(): describe more date-parsing failure modes
> 
>  commit.c               | 47 +++++++++++++++++++++++++++++++++++-------
>  t/t4212-log-corrupt.sh | 39 +++++++++++++++++++++++++++++++++--
>  2 files changed, 76 insertions(+), 10 deletions(-)

Whoops, forgot my range-diff (though nothing should be too surprising based on the round 1 discussion):

1:  07932cf666 = 1:  ac38ce133d t4212: avoid putting git on left-hand side of pipe
2:  7ee34c7d5f ! 2:  f59e61262d parse_commit(): parse timestamp from end of line
    @@ Commit message
         parse back to the final ">". In theory we could use split_ident_line()
         here, but it's actually a bit more strict. In particular, it requires a
         valid time-zone token, too. That should be present, of course, but we
    -    wouldn't want to break --until for malformed cases that are working
    -    currently.
    +    wouldn't want to break --until for cases that are working currently.
     
         We might want to teach split_ident_line() to become more lenient there,
         but it would require checking its many callers (since right now they can
    @@ commit.c: static timestamp_t parse_commit_date(const char *buf, const char *tail
     -	if (buf >= tail)
     +
     +	/*
    -+	 * parse to end-of-line and then walk backwards, which
    -+	 * handles some malformed cases.
    ++	 * Jump to end-of-line so that we can walk backwards to find the
    ++	 * end-of-email ">". This is more forgiving of malformed cases
    ++	 * because unexpected characters tend to be in the name and email
    ++	 * fields.
     +	 */
     +	eol = memchr(buf, '\n', tail - buf);
     +	if (!eol)
      		return 0;
     -	dateptr = buf;
     -	while (buf < tail && *buf++ != '\n')
    -+	for (dateptr = eol; dateptr > buf && dateptr[-1] != '>'; dateptr--)
    - 		/* nada */;
    +-		/* nada */;
     -	if (buf >= tail)
    ++	dateptr = eol;
    ++	while (dateptr > buf && dateptr[-1] != '>')
    ++		dateptr--;
     +	if (dateptr == buf || dateptr == eol)
      		return 0;
     -	/* dateptr < buf && buf[-1] == '\n', so parsing will stop at buf-1 */
3:  e8e94083f5 ! 3:  c62fc59bf1 parse_commit(): handle broken whitespace-only timestamp
    @@ Commit message
         It's not subject to the same bug, because it insists that there be one
         or more digits in the timestamp.
     
    -    We can use the same logic here. If there's a non-whitespace but
    -    non-digit value (say "committer name <email> foo"), then
    -    parse_timestamp() would already have returned 0 anyway. So the only
    -    change should be for this "whitespace only" case.
    -
         Signed-off-by: Jeff King <peff@peff.net>
     
      ## commit.c ##
     @@ commit.c: static timestamp_t parse_commit_date(const char *buf, const char *tail)
    - 	if (dateptr == buf || dateptr == eol)
    + 	dateptr = eol;
    + 	while (dateptr > buf && dateptr[-1] != '>')
    + 		dateptr--;
    +-	if (dateptr == buf || dateptr == eol)
    ++	if (dateptr == buf)
      		return 0;
      
    +-	/* dateptr < eol && *eol == '\n', so parsing will stop at eol */
     +	/*
    -+	 * trim leading whitespace; parse_timestamp() will do this itself, but
    -+	 * it will walk past the newline at eol while doing so. So we insist
    -+	 * that there is at least one digit here.
    ++	 * Trim leading whitespace; parse_timestamp() will do this itself, but
    ++	 * if we have _only_ whitespace, it will walk right past the newline
    ++	 * while doing so.
     +	 */
     +	while (dateptr < eol && isspace(*dateptr))
     +		dateptr++;
    -+	if (!strchr("0123456789", *dateptr))
    ++	if (dateptr == eol)
     +		return 0;
     +
    - 	/* dateptr < eol && *eol == '\n', so parsing will stop at eol */
    ++	/*
    ++	 * We know there is at least one non-whitespace character, so we'll
    ++	 * begin parsing there and stop at worst case at eol.
    ++	 */
      	return parse_timestamp(dateptr, NULL, 10);
      }
    + 
     
      ## t/t4212-log-corrupt.sh ##
     @@ t/t4212-log-corrupt.sh: test_expect_success 'absurdly far-in-future date' '
-:  ---------- > 4:  28ed51a2ca parse_commit(): describe more date-parsing failure modes
Previous: Jeff KingNext: Jeff King
Message 20 of 46 in “Weird behavior of 'git log --before' or 'git log --date-order': Commits from 2011 are treated to be before 1980”
  1. Thomas BockApr 14, 2023
  2. Jeff KingApr 15, 2023
  3. Jeff KingApr 15, 2023
  4. Kristoffer HaugsbakkApr 15, 2023
  5. Jeff KingApr 17, 2023
  6. Kristoffer HaugsbakkApr 17, 2023
  7. Jeff KingApr 17, 2023
  8. Kristoffer HaugsbakkApr 27, 2023
  9. Junio C HamanoApr 17, 2023
  10. Jeff KingApr 18, 2023
  11. Derrick StoleeApr 18, 2023
  12. Thomas BockApr 21, 2023
  13. 0/3 fixing some parse_commit() timestamp corner casesJeff King, Apr 22, 2023
  14. 1/3 t4212: avoid putting git on left-hand side of pipeJeff King, Apr 22, 2023
  15. 2/3 parse_commit(): parse timestamp from end of lineJeff King, Apr 22, 2023
  16. Junio C HamanoApr 24, 2023
  17. Jeff KingApr 25, 2023
  18. Junio C HamanoApr 24, 2023
  19. 0/3 fixing some parse_commit() timestamp corner casesJeff King, Apr 25, 2023
  20. Jeff KingApr 25, 2023
  21. 1/4 t4212: avoid putting git on left-hand side of pipeJeff King, Apr 25, 2023
  22. 2/4 parse_commit(): parse timestamp from end of lineJeff King, Apr 25, 2023
  23. 3/4 parse_commit(): handle broken whitespace-only timestampJeff King, Apr 25, 2023
  24. Phillip WoodApr 25, 2023
  25. Junio C HamanoApr 25, 2023
  26. Jeff KingApr 26, 2023
  27. Junio C HamanoApr 26, 2023
  28. 0/4 fixing some parse_commit() timestamp corner casesJeff King, Apr 27, 2023
  29. 1/4 t4212: avoid putting git on left-hand side of pipeJeff King, Apr 27, 2023
  30. 2/4 parse_commit(): parse timestamp from end of lineJeff King, Apr 27, 2023
  31. 3/4 parse_commit(): handle broken whitespace-only timestampJeff King, Apr 27, 2023
  32. Phillip WoodApr 27, 2023
  33. Phillip WoodApr 27, 2023
  34. Jeff KingApr 27, 2023
  35. Junio C HamanoApr 27, 2023
  36. Jeff KingApr 27, 2023
  37. Junio C HamanoApr 27, 2023
  38. Jeff KingApr 27, 2023
  39. 4/4 parse_commit(): describe more date-parsing failure modesJeff King, Apr 27, 2023
  40. Jeff KingApr 27, 2023
  41. Junio C HamanoApr 27, 2023
  42. Phillip WoodApr 26, 2023
  43. Andreas SchwabApr 26, 2023
  44. Phillip WoodApr 26, 2023
  45. 4/4 parse_commit(): describe more date-parsing failure modesJeff King, Apr 25, 2023
  46. Jeff KingApr 22, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.