git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] sha1_file: don't malloc the whole compressed result when writing out objects

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 21, 2010, 22:30 UTC
Message-ID
<7v3a0umdb8.fsf@alter.siamese.dyndns.org>
In-Reply-To
<alpine.LFD.2.00.1002211522120.1946@xanadu.home>
Nicolas Pitre <nico@fluxnic.net> writes:
Show 7 quoted lines
>  	/* Then the data itself.. */
>  	stream.next_in = buf;
>  	stream.avail_in = len;
>  	do {
> +		unsigned char *in0 = stream.next_in;
>  		ret = deflate(&stream, Z_FINISH);
> +		git_SHA1_Update(&c, in0, stream.next_in - in0);
Actually, I have to take my earlier comment back.  This is not "paranoia".

I do not see anything that protects the memory area between in0 and stream.next_in from getting modified while deflate() nor SHA1_Update() run from the outside. Unless you copy the data away to somewhere stable at the beginning of each iteration of this loop and run deflate() and SHA1_Update(), you cannot have "paranoia".

My comment about "trickier" is about determining the size of that buffer used as "somewhere stable".

Previous: Junio C HamanoNext: Nicolas Pitre
Message 5 of 13 in “sha1_file: don't malloc the whole compressed result when writing out objects”
  1. sha1_file: don't malloc the whole compressed result when writing out objectsNicolas Pitre, Feb 21, 2010
  2. Junio C HamanoFeb 21, 2010
  3. Nicolas PitreFeb 21, 2010
  4. Junio C HamanoFeb 21, 2010
  5. Junio C HamanoFeb 21, 2010
  6. Nicolas PitreFeb 22, 2010
  7. Junio C HamanoFeb 22, 2010
  8. Nicolas PitreFeb 22, 2010
  9. Junio C HamanoFeb 22, 2010
  10. Junio C HamanoFeb 22, 2010
  11. Nicolas PitreFeb 22, 2010
  12. Junio C HamanoFeb 22, 2010
  13. Dmitry PotapovFeb 22, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.