git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] precompose_utf8: use a flex array for d_name

From
Torsten Bögershausen <tboegi@web.de>
Date
Jul 3, 2026, 05:08 UTC
Message-ID
<20260703050800.GA29216@tb-raspi4>
In-Reply-To
<20260703023554.36577-1-ihar.hrachyshka@gmail.com>
On Thu, Jul 02, 2026 at 10:35:54PM -0400, Ihar Hrachyshka wrote:
Show 23 quoted lines
> On macOS, git status may abort while reading a directory entry
> whose UTF-8 name grows past NAME_MAX bytes:
> 
>   __chk_fail_overflow
>   __strlcpy_chk
>   precompose_utf8_readdir
>   read_directory_recursive
>   wt_status_collect
>   cmd_status
> 
> The precompose wrapper already reallocates dirent_prec_psx for
> long names, but d_name is declared as char[NAME_MAX + 1]. A
> fortified libc can still see that declared object size and reject a
> larger strlcpy bound, even though the allocation was grown.
> 
> Make d_name a FLEX_ARRAY and size allocations from offsetof(). That
> matches the actual object layout with the dynamic allocation, so the
> fortified copy sees a destination whose size can grow with max_name_len.
> 
> Add a regression test that creates a 261-byte non-ASCII basename and
> runs status with core.precomposeunicode enabled.
> 
> Signed-off-by: Ihar Hrachyshka <ihar.hrachyshka@gmail.com>

Nice, thanks for the patch. One minor nit/question: Do we need a test_have_prereq PERL in t/t3910 ?

[]
Show 27 quoted lines
> diff --git a/t/t3910-mac-os-precompose.sh b/t/t3910-mac-os-precompose.sh
> index 6d5918c..fda4a76 100755
> --- a/t/t3910-mac-os-precompose.sh
> +++ b/t/t3910-mac-os-precompose.sh
> @@ -207,6 +207,21 @@ test_expect_success "Add long precomposed filename" '
>  	git commit -m "Long filename"
>  '
>  
> +test_expect_success "status with long non-ASCII filename" '
> +	test_when_finished "rm -rf long-utf8-status" &&
> +	git init long-utf8-status &&
> +	(
> +		cd long-utf8-status &&
> +		test "$(git config --bool core.precomposeunicode)" = true &&
> +		long_utf8_name=$(
> +			perl -e "print q(a) x 249, qq(\342\200\224) x 3, q(.md)"
> +		) &&
> +		test "$(printf "%s" "$long_utf8_name" | wc -c | tr -d " ")" = 261 &&
> +		printf "content\n" >"$long_utf8_name" &&
> +		git status --porcelain=v1 >actual
> +	)
> +'
> +
>  test_expect_failure 'handle existing decomposed filenames' '
>  	echo content >"verbatim.$Adiarnfd" &&
>  	git -c core.precomposeunicode=false add "verbatim.$Adiarnfd" &&
> 
Previous: Ihar HrachyshkaNext: Junio C Hamano
Message 2 of 6 in “precompose_utf8: use a flex array for d_name”
  1. precompose_utf8: use a flex array for d_nameIhar Hrachyshka, Jul 3, 2026
  2. Torsten BögershausenJul 3, 2026
  3. Junio C HamanoJul 3, 2026
  4. Patrick SteinhardtJul 3, 2026
  5. Ihar HrachyshkaJul 3, 2026
  6. precompose_utf8: use a flex array for d_nameIhar Hrachyshka, Jul 4, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.