git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 16:56 UTC

[PATCH v2 3/7] xdiff: use size_t for buffer sizes

From
Jeff King <peff@peff.net>
Date
Sep 30, 2026, 23:44 UTC
Message-ID
<20260930234410.GC1347555@coredump.intra.peff.net>
In-Reply-To
<20260930234348.GA1340390@coredump.intra.peff.net>

An mmfile_t stores its size as a signed long, but the more natural type for a buffer size is size_t. This not only limits the size of entry we can hold, but also creates some possible integer overflow issues.

For example, read_mmfile() checks that the file size fits in a size_t before allocating, but then assigns it to a long. Likewise, read_mmblob() and fill_mmfile() copy sizes from other types without checking that they fit.

On LP64 systems like Linux, this is mostly academic. You could wrap to a negative long value, but you'd need an object that's 2^63 bytes, which is impractical.

But on an LLP64 system like Windows, a 2^31+1-byte blob could perhaps cause mischief. We do prevent large values from entering the xdiff code due to MAX_XDIFF_SIZE (which is itself marked as unsigned, so we'd convert any negative "long" back to a large unsigned value). But if you ask for binary diffs, that negative long value could instead be converted to a huge 64-bit size_t when passed to memcmp(), diff_delta(), etc. So probably there are paths that can cause an out-of-bounds read, given the right set of options, but I didn't really dig for them.

On a 32-bit system things are less clear. Because "long" and "size_t" have the same width, any time we implicitly convert to size_t, we should get back the original size (even if the intermediate "long" is itself negative). Probably iterating using a long could be a problem, but most of that happens inside xdiff, which is protected by MAX_XDIFF_SIZE (which, again, compares in the unsigned space).

Let's just use the obvious size_t type for counting the bytes. I suspect you could still find truncation problems on LLP64 systems due to the use of "unsigned long" throughout the code, but that's a larger problem. This should at least nudge us in the right direction.

Note that we have to update the printf format in emit_binary_diff_body() to accommodate the new type. Curiously it was using "%lu", even though the type was signed (I guess compiler printf-linting is happy enough if just the width of the format and the type match).

Signed-off-by: Jeff King <peff@peff.net>
---
 diff.c        | 2 +-
 xdiff/xdiff.h | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/diff.c b/diff.c
index 414532d09f..b4ac17f8ef 100644
--- a/diff.c
+++ b/diff.c
@@ -3646,7 +3646,7 @@ static void emit_binary_diff_body(struct diff_options *o,
 		data = delta;
 		data_size = delta_size;
 	} else {
-		char *s = xstrfmt("%lu", two->size);
+		char *s = xstrfmt("%"PRIuMAX, (uintmax_t)two->size);
 		emit_diff_symbol(o, DIFF_SYMBOL_BINARY_DIFF_HEADER_LITERAL,
 				 s, strlen(s), 0);
 		free(s);
diff --git a/xdiff/xdiff.h b/xdiff/xdiff.h
index 334eb436f6..8fa513fc4e 100644
--- a/xdiff/xdiff.h
+++ b/xdiff/xdiff.h
@@ -70,7 +70,7 @@ extern "C" {
 
 typedef struct s_mmfile {
 	char *ptr;
-	long size;
+	size_t size;
 } mmfile_t;
 
 typedef struct s_xpparam {
-- 
2.56.0.354.gb6b32d5be5
Previous: Jeff KingNext: Jeff King
Message 29 of 37 in “use size_t for xdiff mmfile_t”
  1. 0/5 use size_t for xdiff mmfile_tJeff King, Sep 29, 2026
  2. 1/5 xdiff: clean up read_mmfile() allocations on errorJeff King, Sep 29, 2026
  3. 2/5 xdiff: replace mmbuffer_t with mmfile_tJeff King, Sep 29, 2026
  4. 3/5 xdiff: use size_t for buffer sizesJeff King, Sep 29, 2026
  5. 4/5 merge-ll: use read_mmfile() to read external merge resultsJeff King, Sep 29, 2026
  6. 5/5 xdiff: NUL-terminate buffers read by read_mmfile()Jeff King, Sep 29, 2026
  7. D. Ben KnobleSep 29, 2026
  8. Junio C HamanoSep 29, 2026
  9. Junio C HamanoSep 29, 2026
  10. Junio C HamanoSep 29, 2026
  11. Jeff KingSep 29, 2026
  12. Jeff KingSep 29, 2026
  13. 6/5 merge-ll: handle external driver status before reading resultJeff King, Sep 29, 2026
  14. 7/5 merge-ll: report an error when reading external merge results failsJeff King, Sep 29, 2026
  15. Junio C HamanoSep 29, 2026
  16. Jeff KingSep 29, 2026
  17. Patrick SteinhardtSep 30, 2026
  18. Patrick SteinhardtSep 30, 2026
  19. Patrick SteinhardtSep 30, 2026
  20. Junio C HamanoSep 30, 2026
  21. Junio C HamanoSep 30, 2026
  22. Jeff KingSep 30, 2026
  23. Jeff KingSep 30, 2026
  24. Jeff KingSep 30, 2026
  25. Jeff KingSep 30, 2026
  26. 0/7 use size_t for xdiff mmfile_tJeff King, Sep 30, 2026
  27. 1/7 xdiff: clean up read_mmfile() allocations on errorJeff King, Sep 30, 2026
  28. 2/7 xdiff: replace mmbuffer_t with mmfile_tJeff King, Sep 30, 2026
  29. 3/7 xdiff: use size_t for buffer sizesJeff King, Sep 30, 2026
  30. 4/7 xdiff: NUL-terminate buffers read by read_mmfile()Jeff King, Sep 30, 2026
  31. 5/7 merge-ll: use read_mmfile() to read external merge resultsJeff King, Sep 30, 2026
  32. 6/7 merge-ll: handle external driver status before reading resultJeff King, Sep 30, 2026
  33. 7/7 merge-ll: report an error when reading external merge results failsJeff King, Sep 30, 2026
  34. Patrick SteinhardtOct 1, 2026
  35. Patrick SteinhardtOct 1, 2026
  36. Junio C HamanoOct 1, 2026
  37. Junio C HamanoOct 1, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.