git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 3/3] Do not create commits whose message contains NUL

From
Junio C Hamano <gitster@pobox.com>
Date
Dec 15, 2011, 19:35 UTC
Message-ID
<7v62hhocgm.fsf@alter.siamese.dyndns.org>
In-Reply-To
<7vehw5oepj.fsf@alter.siamese.dyndns.org>
Junio C Hamano <gitster@pobox.com> writes:
Show 10 quoted lines
>> My gut feeling is that it should store the literal binary contents.
>> However, I don't think this has ever been the case. Even in the initial
>> version of commit-tree.c, we read the input line-by-line and sprintf it
>> into place.
>
> Yeah, you are right. Perhaps we should tweak updated 3/3 to check at the
> lower level commit_tree() then.
>
> I've rewrote the log message for 2/3 as follows so we can go either way
> ;-)
s/rewrote/rewritten/ obviously...
Show 11 quoted lines
>     Convert commit_tree() to take strbuf as message
>     
>     There wan't a way for commit_tree() to notice if the message the caller
>     prepared contained a NUL byte, as it did not take the length of the
>     message as a parameter. Use a pointer to a strbuf instead, so that we can
>     either choose to allow low-level plumbing commands to make commits
>     that contain NUL byte in its message, or forbid NUL everywhere by
>     adding the check in commit_tree(), in later patches.
>     
>     Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
>     Signed-off-by: Junio C Hamano <gitster@pobox.com>
And 3/3 looks like this:
    commit_tree(): refuse commit messages that contain NULs
    
    Current implementation sees NUL as terminator. If users give a message
    with NUL byte in it (e.g. editor set to save as UTF-16), the new commit
    message will have NULs. However following operations (displaying or
    amending a commit for example) will not keep anything after the first NUL.
    
    Stop user right when they do this. If NUL is added by mistake, they have
    their chance to fix. Otherwise, log messages will no longer be text "git
    log" and friends would grok.
    
    Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
    Signed-off-by: Junio C Hamano <gitster@pobox.com>
Previous: Junio C HamanoNext: Miles Bader
Message 20 of 23 in “Do not create commits whose message contains NUL”
  1. Do not create commits whose message contains NULNguyễn Thái Ngọc Duy, Dec 13, 2011
  2. Jeff KingDec 13, 2011
  3. Miles BaderDec 14, 2011
  4. Jeff KingDec 14, 2011
  5. Drew NorthupJan 1, 2012
  6. Jeff KingJan 3, 2012
  7. 0/3 git-commit rejects messages with NULsNguyễn Thái Ngọc Duy, Dec 14, 2011
  8. 1/3 Make commit_tree() take message length in addition to the commit messageNguyễn Thái Ngọc Duy, Dec 14, 2011
  9. Junio C HamanoDec 14, 2011
  10. 1/3 merge: abort if fails to commitNguyễn Thái Ngọc Duy, Dec 15, 2011
  11. 2/3 Convert commit_tree() to take strbuf as messageNguyễn Thái Ngọc Duy, Dec 15, 2011
  12. 3/3 commit: refuse commit messages that contain NULsNguyễn Thái Ngọc Duy, Dec 15, 2011
  13. Junio C HamanoDec 15, 2011
  14. 2/3 merge: abort if fails to commitNguyễn Thái Ngọc Duy, Dec 14, 2011
  15. Junio C HamanoDec 14, 2011
  16. 3/3 Do not create commits whose message contains NULNguyễn Thái Ngọc Duy, Dec 14, 2011
  17. Junio C HamanoDec 14, 2011
  18. Jeff KingDec 14, 2011
  19. Junio C HamanoDec 15, 2011
  20. Junio C HamanoDec 15, 2011
  21. Miles BaderDec 15, 2011
  22. Jeff KingDec 15, 2011
  23. Junio C HamanoDec 15, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.