git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] mingw-multibyte: fix memory acces violation and path length limits.

From
Wataru Noguchi <wnoguchi.0727@gmail.com>
Date
Sep 29, 2013, 02:56 UTC
Message-ID
<524796DC.5020302@gmail.com>
In-Reply-To
<alpine.DEB.1.00.1309290112380.1191@s15462909.onlinehome-server.info>
Hi,
Thanks for comments.
My currently working repository is
https://github.com/wnoguchi/git/tree/hotfix/mingw-multibyte-path-checkout-failure

I have revert commits to 1f10da3. I'll try failure step.

- gcc optimization level is O2.(fail)
- gcc O0, O1 works fine.
$ gdb git-clone
GNU gdb 6.8
Copyright (C) 2008 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "i686-pc-mingw32"...
(gdb) r https://github.com/wnoguchi/mingw-checkout-crash.git
Starting program: C:\msysgit\git/git-clone.exe https://github.com/wnoguchi/mingw
-checkout-crash.git
[New thread 800.0xa10]
Error: dll starting at 0x779f0000 not found.
Error: dll starting at 0x75900000 not found.
Error: dll starting at 0x779f0000 not found.
Error: dll starting at 0x778f0000 not found.
[New thread 800.0x92c]
Cloning into 'mingw-checkout-crash'...
Error: dll starting at 0x29f0000 not found.
remote: Counting objects: 8, done.
remote: Compressing objects: 100% (7/7), done.
remote: Total 8 (delta 0), reused 8 (delta 0)
Unpacking objects: 100% (8/8), done.
Checking connectivity... done
[New thread 800.0xea0]
Program received signal SIGSEGV, Segmentation fault.
0x004d5200 in git_check_attr (
     path=0xacc6a0 ""..., num=5, check=0x572440) at attr.c:754
754                     const char *value = check_all_attr[check[i].attr->attr_n
r].value;
(gdb) list
749             int i;
750
751             collect_all_attrs(path);
752
753             for (i = 0; i < num; i++) {
754                     const char *value = check_all_attr[check[i].attr->attr_n
r].value;
755                     if (value == ATTR__UNKNOWN)
756                             value = ATTR__UNSET;
757                     check[i].value = value;
758             }
(gdb) up
#1  0x004a796b in convert_attrs (ca=0x28f950,
     path=0xacc6a0 ""...) at convert.c:740
740             if (!git_check_attr(path, NUM_CONV_ATTRS, ccheck)) {
(gdb) list
735                             ccheck[i].attr = git_attr(conv_attr_name[i]);
736                     user_convert_tail = &user_convert;
737                     git_config(read_convert_config, NULL);
738             }
739
740             if (!git_check_attr(path, NUM_CONV_ATTRS, ccheck)) {
741                     ca->crlf_action = git_path_check_crlf(path, ccheck + 4);

742 if (ca->crlf_action == CRLF_GUESS) 743 ca->crlf_action = git_path_check_crlf(path, cche ck + 0); 744 ca->ident = git_path_check_ident(path, ccheck + 1); (gdb) list - 725 int i; 726 static struct git_attr_check ccheck[NUM_CONV_ATTRS]; 727 728 // if (NUM_CONV_ATTRS != 0) { 729 // ccheck[0].attr = NULL; 730 // ccheck[0].value = NULL; 731 // } 732 733 if (!ccheck[0].attr) { 734 for (i = 0; i < NUM_CONV_ATTRS; i++) (gdb) p ccheck[0].attr $1 = (struct git_attr *) 0xa081e38f

Next, change PATH_MAX value to 4096 if MinGW environment.(6cae216) Works fine. Is this failure caused by PATH_MAX length too short? or my repository directory depth too deep? But when optimization disabled(O0) in Makefile , works fine...(bf0acff) Do you know what's happen?

Thanks.
(2013/09/29 8:18), Johannes Schindelin wrote:
Show 56 quoted lines
> Hi,
>
> On Sun, 29 Sep 2013, Wataru Noguchi wrote:
>
>> --- a/convert.c
>> +++ b/convert.c
>> @@ -724,6 +724,11 @@ static void convert_attrs(struct conv_attrs *ca, const char *path)
>>   {
>>   	int i;
>>   	static struct git_attr_check ccheck[NUM_CONV_ATTRS];
>> +	
>> +	if (NUM_CONV_ATTRS != 0) {
>> +		ccheck[0].attr = NULL;
>> +		ccheck[0].value = NULL;
>> +	}
>
> I wonder whether it would make more sense to use
>
> 	memset(ccheck, 0, sizeof(ccheck))
>
> ? But then, ccheck is static and *should* be initialized to all 0
> according to the C standard. And re-initializing it to NULL would
> invalidate the values that were set earlier.
>
> Also, if NUM_CONV_ATTRS == 0, I would expect
>
>>   	if (!ccheck[0].attr) {
>
> to access an invalid location...
>
>> diff --git a/git-compat-util.h b/git-compat-util.h
>> index a31127f..ba02c69 100644
>> --- a/git-compat-util.h
>> +++ b/git-compat-util.h
>> @@ -237,6 +237,16 @@ extern char *gitbasename(char *);
>>   #ifndef PATH_MAX
>>   #define PATH_MAX 4096
>>   #endif
>> +#ifdef GIT_WINDOWS_NATIVE
>> +/* Git for Windows checkout PATH_MAX is reduce to 260.
>> + * but if checkout relative long path name, its length too short.
>> + * thus, expand length.
>> + */
>> +#ifdef PATH_MAX
>> +#undef PATH_MAX
>> +#endif
>> +#define PATH_MAX 4096
>> +#endif
>
> This looks fine, but I am wary... did you not say that a crash was caused
> by this? In that case, we would have a user that accesses the respective
> buffer without checking the size and we would still have to fix that bug..
>
> Ciao,
> Dscho
>
-- 
=========================================
   Wataru Noguchi
   wnoguchi.0727@gmail.com
   http://wnoguchi.github.io/
=========================================

-- 
-- 
*** Please reply-to-all at all times ***
*** (do not pretend to know who is subscribed and who is not) ***
*** Please avoid top-posting. ***
The msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.

You received this message because you are subscribed to the Google
Groups "msysGit" group.
To post to this group, send email to msysgit@googlegroups.com
To unsubscribe from this group, send email to
msysgit+unsubscribe@googlegroups.com
For more options, and view previous threads, visit this group at
http://groups.google.com/group/msysgit?hl=en_US?hl=en

--- 
You received this message because you are subscribed to the Google Groups "msysGit" group.
To unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.
Previous: Johannes SchindelinNext: Stefan Beller
Message 3 of 44 in “mingw-multibyte: fix memory acces violation and path length limits.”
  1. mingw-multibyte: fix memory acces violation and path length limits.Wataru Noguchi, Sep 28, 2013
  2. Johannes SchindelinSep 28, 2013
  3. Wataru NoguchiSep 29, 2013
  4. Stefan BellerSep 29, 2013
  5. Wataru NoguchiOct 1, 2013
  6. René ScharfeSep 30, 2013
  7. Erik Faye-LundSep 30, 2013
  8. Wataru NoguchiOct 1, 2013
  9. Wataru NoguchiOct 2, 2013
  10. Antoine PelisseOct 3, 2013
  11. Erik Faye-LundOct 3, 2013
  12. Wataru NoguchiOct 5, 2013
  13. Prevent buffer overflows when path is too bigAntoine Pelisse, Oct 19, 2013
  14. Torsten BögershausenOct 20, 2013
  15. Ondřej BílkaOct 20, 2013
  16. Torsten BögershausenOct 20, 2013
  17. Ondřej BílkaOct 20, 2013
  18. Duy NguyenOct 20, 2013
  19. Antoine PelisseOct 20, 2013
  20. Duy NguyenOct 21, 2013
  21. Johannes SixtOct 21, 2013
  22. Erik Faye-LundOct 21, 2013
  23. Jeff KingOct 21, 2013
  24. Jeff KingOct 21, 2013
  25. 1/2 entry.c: convert checkout_entry to use strbufNguyễn Thái Ngọc Duy, Oct 23, 2013
  26. 2/2 entry.c: convert write_entry to use strbufNguyễn Thái Ngọc Duy, Oct 23, 2013
  27. Junio C HamanoOct 23, 2013
  28. Duy NguyenOct 24, 2013
  29. Junio C HamanoOct 24, 2013
  30. Duy NguyenOct 24, 2013
  31. Antoine PelisseOct 23, 2013
  32. Duy NguyenOct 23, 2013
  33. Antoine PelisseOct 23, 2013
  34. Jeff KingOct 23, 2013
  35. Erik Faye-LundOct 23, 2013
  36. Jeff KingOct 23, 2013
  37. Junio C HamanoOct 23, 2013
  38. Jeff KingOct 23, 2013
  39. entry.c: convert checkout_entry to use strbufNguyễn Thái Ngọc Duy, Oct 24, 2013
  40. Duy NguyenOct 23, 2013
  41. Prevent buffer overflows when path is too longAntoine Pelisse, Nov 26, 2013
  42. Junio C HamanoNov 26, 2013
  43. Antoine PelisseNov 29, 2013
  44. Prevent buffer overflows when path is too longAntoine Pelisse, Dec 14, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.