git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 5/5] xdiff: NUL-terminate buffers read by read_mmfile()

From
Jeff King <peff@peff.net>
Date
Sep 29, 2026, 06:55 UTC
Message-ID
<20260929065504.GE1697497@coredump.intra.peff.net>
In-Reply-To
<20260929064935.GA1276867@coredump.intra.peff.net>

Since an mmfile_t is a ptr/len pair, our read_mmfile() allocates exactly the number of bytes we claim to store. But in many other places in Git, we add an extra NUL "just in case", which can help avoid read overruns due to off-by-ones or the use of string functions.

I don't know of any path that would benefit from this, but I noticed it while converting ll_ext_merge() to use read_mmfile(), since its original code did add a NUL byte (even though I cannot find any case where it would have mattered). Let's teach read_mmfile() to add this defensive NUL; it probably doesn't help anything, but nor should it hurt.

Note that the matching read_mmblob() doesn't need the same treatment. Its buffers already have a NUL from the object-reading code (which uses the same defensive trick).

As a bonus, we can get rid of the hack in read_mmfile() to handle empty files by allocating a single byte.

Signed-off-by: Jeff King <peff@peff.net>
---
This one is obviously optional, which is why I put it last.
 xdiff-interface.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/xdiff-interface.c b/xdiff-interface.c
index bc340d5a8a..b3e9f1952b 100644
--- a/xdiff-interface.c
+++ b/xdiff-interface.c
@@ -166,7 +166,7 @@ int read_mmfile(mmfile_t *ptr, const char *filename)
 	if (!(f = fopen(filename, "rb")))
 		return error_errno("Could not open %s", filename);
 	sz = xsize_t(st.st_size);
-	ptr->ptr = xmalloc(sz ? sz : 1);
+	ptr->ptr = xmallocz(sz);
 	if (sz && fread(ptr->ptr, sz, 1, f) != 1) {
 		FREE_AND_NULL(ptr->ptr);
 		fclose(f);
-- 
2.56.0.325.g545d7e68bc
Previous: Jeff KingNext: D. Ben Knoble
Message 6 of 37 in “use size_t for xdiff mmfile_t”
  1. 0/5 use size_t for xdiff mmfile_tJeff King, Sep 29, 2026
  2. 1/5 xdiff: clean up read_mmfile() allocations on errorJeff King, Sep 29, 2026
  3. 2/5 xdiff: replace mmbuffer_t with mmfile_tJeff King, Sep 29, 2026
  4. 3/5 xdiff: use size_t for buffer sizesJeff King, Sep 29, 2026
  5. 4/5 merge-ll: use read_mmfile() to read external merge resultsJeff King, Sep 29, 2026
  6. 5/5 xdiff: NUL-terminate buffers read by read_mmfile()Jeff King, Sep 29, 2026
  7. D. Ben KnobleSep 29, 2026
  8. Junio C HamanoSep 29, 2026
  9. Junio C HamanoSep 29, 2026
  10. Junio C HamanoSep 29, 2026
  11. Jeff KingSep 29, 2026
  12. Jeff KingSep 29, 2026
  13. 6/5 merge-ll: handle external driver status before reading resultJeff King, Sep 29, 2026
  14. 7/5 merge-ll: report an error when reading external merge results failsJeff King, Sep 29, 2026
  15. Junio C HamanoSep 29, 2026
  16. Jeff KingSep 29, 2026
  17. Patrick SteinhardtSep 30, 2026
  18. Patrick SteinhardtSep 30, 2026
  19. Patrick SteinhardtSep 30, 2026
  20. Junio C HamanoSep 30, 2026
  21. Junio C HamanoSep 30, 2026
  22. Jeff KingSep 30, 2026
  23. Jeff KingSep 30, 2026
  24. Jeff KingSep 30, 2026
  25. Jeff KingSep 30, 2026
  26. 0/7 use size_t for xdiff mmfile_tJeff King, Sep 30, 2026
  27. 1/7 xdiff: clean up read_mmfile() allocations on errorJeff King, Sep 30, 2026
  28. 2/7 xdiff: replace mmbuffer_t with mmfile_tJeff King, Sep 30, 2026
  29. 3/7 xdiff: use size_t for buffer sizesJeff King, Sep 30, 2026
  30. 4/7 xdiff: NUL-terminate buffers read by read_mmfile()Jeff King, Sep 30, 2026
  31. 5/7 merge-ll: use read_mmfile() to read external merge resultsJeff King, Sep 30, 2026
  32. 6/7 merge-ll: handle external driver status before reading resultJeff King, Sep 30, 2026
  33. 7/7 merge-ll: report an error when reading external merge results failsJeff King, Sep 30, 2026
  34. Patrick SteinhardtOct 1, 2026
  35. Patrick SteinhardtOct 1, 2026
  36. Junio C HamanoOct 1, 2026
  37. Junio C HamanoOct 1, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.