git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 03/27] parse_arg(): Really test that argument is properly terminated

From
Michael Haggerty <mhagger@alum.mit.edu>
Date
Mar 31, 2014, 22:11 UTC
Message-ID
<5339E7F4.1090805@alum.mit.edu>
In-Reply-To
<xmqqlhvq3vaj.fsf@gitster.dls.corp.google.com>
On 03/31/2014 11:36 PM, Junio C Hamano wrote:
Show 77 quoted lines
> Michael Haggerty <mhagger@alum.mit.edu> writes:
> 
>> Test that the argument is properly terminated by either whitespace or
>> a NUL character, even if it is quoted, to be consistent with the
>> non-quoted case.  Adjust the tests to expect the new error message.
>> Add a docstring to the function, incorporating the comments that were
>> formerly within the function plus some added information.
>>
>> Signed-off-by: Michael Haggerty <mhagger@alum.mit.edu>
>> ---
>>  builtin/update-ref.c  | 20 +++++++++++++++-----
>>  t/t1400-update-ref.sh |  4 ++--
>>  2 files changed, 17 insertions(+), 7 deletions(-)
>>
>> diff --git a/builtin/update-ref.c b/builtin/update-ref.c
>> index 1292cfe..02b5f95 100644
>> --- a/builtin/update-ref.c
>> +++ b/builtin/update-ref.c
>> @@ -62,16 +62,26 @@ static void update_store_old_sha1(struct ref_update *update,
>>  	update->have_old = *oldvalue || line_termination;
>>  }
>>  
>> +/*
>> + * Parse one whitespace- or NUL-terminated, possibly C-quoted argument
>> + * and append the result to arg.  Return a pointer to the terminator.
>> + * Die if there is an error in how the argument is C-quoted.  This
>> + * function is only used if not -z.
>> + */
>>  static const char *parse_arg(const char *next, struct strbuf *arg)
>>  {
>> -	/* Parse SP-terminated, possibly C-quoted argument */
>> -	if (*next != '"')
>> +	if (*next == '"') {
>> +		const char *orig = next;
>> +
>> +		if (unquote_c_style(arg, next, &next))
>> +			die("badly quoted argument: %s", orig);
>> +		if (*next && !isspace(*next))
>> +			die("unexpected character after quoted argument: %s", orig);
>> +	} else {
>>  		while (*next && !isspace(*next))
>>  			strbuf_addch(arg, *next++);
>> -	else if (unquote_c_style(arg, next, &next))
>> -		die("badly quoted argument: %s", next);
>> +	}
>>  
>> -	/* Return position after the argument */
>>  	return next;
>>  }
>>  
>> diff --git a/t/t1400-update-ref.sh b/t/t1400-update-ref.sh
>> index 29391c6..774f8c5 100755
>> --- a/t/t1400-update-ref.sh
>> +++ b/t/t1400-update-ref.sh
>> @@ -356,10 +356,10 @@ test_expect_success 'stdin fails on badly quoted input' '
>>  	grep "fatal: badly quoted argument: \\\"master" err
>>  '
>>  
>> -test_expect_success 'stdin fails on arguments not separated by space' '
>> +test_expect_success 'stdin fails on junk after quoted argument' '
>>  	echo "create \"$a\"master" >stdin &&
>>  	test_must_fail git update-ref --stdin <stdin 2>err &&
>> -	grep "fatal: expected SP but got: master" err
>> +	grep "fatal: unexpected character after quoted argument: \\\"$a\\\"master" err
>>  '
> 
> Interesting.
> 
> I would have expected that "We used to check only one of the two
> codepaths and the other was loose, fix it" to be accompanied by "So
> here is an _addition_ to the test suite to validate the other case
> that used to be loose, now tightened", not "We update one existing
> case".  The test before and after the patch is about a c-quoted
> string, so I am not sure if we are still testing the right thing.
> 
> The code in update-ref.c after the patch does look reasonable,
> though.
The old parse_arg(), when fed an argument
    "refs/heads/a"master

parsed 'refs/heads/a' off of the front of the argument and considered itself successful. It was only when parse_next_arg() tried to parse the *next* argument that a problem was noticed. But in fact, the definition of the input format requires arguments to be terminated by SP or NUL, so *this* argument is already erroneous and parse_arg() should diagnose the problem.

The point of this patch is to move the error detection for C-quoted arguments that have trailing junk to the parse_arg() call for the broken argument and to make the error message more descriptive of the situation.

There is no corresponding error case for non-C-quoted arguments, because the end of the argument is *by definition* a space or NUL, so there is no way to insert other junk between the "end" of the argument and the argument terminator.

Michael
-- 
Michael Haggerty
mhagger@alum.mit.edu
http://softwareswirl.blogspot.com/
Previous: Junio C HamanoNext: Michael Haggerty
Message 9 of 65 in “Clean up update-refs --stdin and implement ref_transaction”
  1. 00/27 Clean up update-refs --stdin and implement ref_transactionMichael Haggerty, Mar 24, 2014
  2. 01/27 t1400: Fix name and expected result of one testMichael Haggerty, Mar 24, 2014
  3. Junio C HamanoMar 31, 2014
  4. Michael HaggertyMar 31, 2014
  5. 02/27 t1400: Provide more usual input to the commandMichael Haggerty, Mar 24, 2014
  6. Junio C HamanoMar 31, 2014
  7. 03/27 parse_arg(): Really test that argument is properly terminatedMichael Haggerty, Mar 24, 2014
  8. Junio C HamanoMar 31, 2014
  9. Michael HaggertyMar 31, 2014
  10. 04/27 t1400: Add some more tests involving quoted argumentsMichael Haggerty, Mar 24, 2014
  11. 05/27 refs.h: Rename the action_on_err constantsMichael Haggerty, Mar 24, 2014
  12. 06/27 update_refs(): Fix constnessMichael Haggerty, Mar 24, 2014
  13. Junio C HamanoMar 31, 2014
  14. Michael HaggertyMar 31, 2014
  15. Junio C HamanoMar 31, 2014
  16. 07/27 update-ref --stdin: Read the whole input at onceMichael Haggerty, Mar 24, 2014
  17. 08/27 parse_cmd_verify(): Copy old_sha1 instead of evaluating <oldvalue> twiceMichael Haggerty, Mar 24, 2014
  18. 09/27 update-ref.c: Extract a new function, parse_refname()Michael Haggerty, Mar 24, 2014
  19. 10/27 update-ref --stdin: Improve error messages for invalid valuesMichael Haggerty, Mar 24, 2014
  20. 11/27 update-ref --stdin: Make error messages more consistentMichael Haggerty, Mar 24, 2014
  21. 12/27 update-ref --stdin: Simplify error messages for missing oldvaluesMichael Haggerty, Mar 24, 2014
  22. 13/27 t1400: Test that stdin -z update treats empty <newvalue> as zerosMichael Haggerty, Mar 24, 2014
  23. Junio C HamanoMar 31, 2014
  24. Michael HaggertyMar 31, 2014
  25. 14/27 update-ref.c: Extract a new function, parse_next_sha1()Michael Haggerty, Mar 24, 2014
  26. Brad KingMar 26, 2014
  27. 15/27 update-ref --stdin -z: Deprecate interpreting the empty string as zerosMichael Haggerty, Mar 24, 2014
  28. Junio C HamanoMar 31, 2014
  29. 16/27 t1400: Test one mistake at a timeMichael Haggerty, Mar 24, 2014
  30. Brad KingMar 26, 2014
  31. Junio C HamanoMar 31, 2014
  32. Michael HaggertyMar 31, 2014
  33. 17/27 update-ref --stdin: Improve the error message for unexpected EOFMichael Haggerty, Mar 24, 2014
  34. 18/27 update-ref --stdin: Harmonize error messagesMichael Haggerty, Mar 24, 2014
  35. Junio C HamanoMar 31, 2014
  36. Michael HaggertyMar 31, 2014
  37. Michael HaggertyApr 1, 2014
  38. Junio C HamanoApr 2, 2014
  39. 19/27 refs: Add a concept of a reference transactionMichael Haggerty, Mar 24, 2014
  40. Brad KingMar 26, 2014
  41. Michael HaggertyMar 26, 2014
  42. Junio C HamanoApr 1, 2014
  43. Michael HaggertyApr 2, 2014
  44. 20/27 update-ref --stdin: Reimplement using reference transactionsMichael Haggerty, Mar 24, 2014
  45. Junio C HamanoApr 1, 2014
  46. Michael HaggertyApr 2, 2014
  47. Junio C HamanoApr 3, 2014
  48. Michael HaggertyApr 4, 2014
  49. 21/27 refs: Remove API function update_refs()Michael Haggerty, Mar 24, 2014
  50. Junio C HamanoApr 1, 2014
  51. 22/27 struct ref_update: Rename field "ref_name" to "refname"Michael Haggerty, Mar 24, 2014
  52. Junio C HamanoApr 1, 2014
  53. Michael HaggertyApr 2, 2014
  54. 23/27 struct ref_update: Store refname as a FLEX_ARRAY.Michael Haggerty, Mar 24, 2014
  55. Junio C HamanoApr 1, 2014
  56. 24/27 ref_transaction_commit(): Introduce temporary variablesMichael Haggerty, Mar 24, 2014
  57. Junio C HamanoApr 1, 2014
  58. 25/27 struct ref_update: Add a lock memberMichael Haggerty, Mar 24, 2014
  59. 26/27 struct ref_update: Add type fieldMichael Haggerty, Mar 24, 2014
  60. Junio C HamanoApr 1, 2014
  61. Michael HaggertyApr 2, 2014
  62. Junio C HamanoApr 2, 2014
  63. 27/27 ref_transaction_commit(): Work with transaction->updates in placeMichael Haggerty, Mar 24, 2014
  64. Brad KingMar 26, 2014
  65. Michael HaggertyMar 26, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.