git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH GSoC 2/5] fetch-object-info: parse type from server response

From
Pablo Sabater <pabloosabaterr@gmail.com>
Date
Jul 29, 2026, 12:05 UTC
Message-ID
<DKB1II4Z88SG.38KG7RAF9Q7VW@gmail.com>
In-Reply-To
<CA+J6zkSQYuK-ZJoiQkEJDS9fBypOrBEmgYZRj1yYU00ws2u_HA@mail.gmail.com>
On Wed Jul 29, 2026 at 11:57 AM CEST, Chandra Pratap wrote:
Show 54 quoted lines
> On Sat, 25 Jul 2026 at 17:25, Pablo Sabater <pabloosabaterr@gmail.com> wrote:
>>
>> The server can handle type requests but does not advertise the
>> capability yet. Prepare the client to know how to parse the server
>> response once the server advertises the capability.
>>
>> Mentored-by: Karthik Nayak <karthik.188@gmail.com>
>> Mentored-by: Chandra Pratap <chandrapratap3519@gmail.com>
>> Signed-off-by: Pablo Sabater <pabloosabaterr@gmail.com>
>> ---
>>  fetch-object-info.c | 12 +++++++++++-
>>  1 file changed, 11 insertions(+), 1 deletion(-)
>>
>> diff --git a/fetch-object-info.c b/fetch-object-info.c
>> index ba7e179c44..cf6b94afb8 100644
>> --- a/fetch-object-info.c
>> +++ b/fetch-object-info.c
>> @@ -50,6 +50,7 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>>                       const int stateless_rpc, const int fd_out)
>>  {
>>         int size_index = -1;
>> +       int type_index = -1;
>>
>>         switch (version) {
>>         case protocol_v2:
>> @@ -101,8 +102,13 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>>                         for (size_t j = 0; j < args->oids->nr; j++)
>>                                 object_info_data[j].sizep =
>>                                         xcalloc(1, sizeof(*object_info_data[j].sizep));
>> +               } else if (!strcmp(reader->line, "type")) {
>> +                       type_index = (int)i;
>> +                       for (size_t j = 0; j < args->oids->nr; j++)
>> +                               object_info_data[j].typep =
>> +                                       xcalloc(1, sizeof(*object_info_data[j].typep));
>>                 } else {
>> -                       BUG("only size is supported");
>> +                       BUG("unexpected object-info option: %s", reader->line);
>>                 }
>>         }
>>
>> @@ -148,6 +154,10 @@ int fetch_object_info(const enum protocol_version version, struct object_info_ar
>>                             object_info_values.items[0].string,
>>                             object_info_values.items[size_index + 1].string);
>>
>> +               if (type_index >= 0)
>> +                       *object_info_data[i].typep =
>> +                               type_from_string(object_info_values.items[type_index + 1].string);
>> +
>>                 string_list_clear(&object_info_values, 0);
>
> Is there a risk of an out-of-bounds array access here if the server
> responds with a truncated or malformed packet?
>
> If object_info_values.nr <= type_index + 1, this will segfault.
This shouldn't be a possible case because of:
fetch_object_info()
	for (size_t i = 0; i < args->object_info_options->nr; i++) {
		[snip]
		} else if (!strcmp(reader->line, "type")) {
			type_index = (int)i;
		[snip]
type_index is set based of the range of object_info_options->nr so:
  type_index < object_info_options->nr
and a few lines below:
	if (args->object_info_options->nr + 1 != object_info_values.nr)
		die("object-info: unexpected number of attributes: %s",
		    reader->line);

so we also know that type_index + 1 < object_info_values.nr. After that we get to those lines that this patch introduced:

 +               if (type_index >= 0)
 +                       *object_info_data[i].typep =
 +                               type_from_string(object_info_values.items[type_index + 1].string);
 And because type_index + 1 < object_info_values.nr we can be sure that
 this cannot segfault once we reach this code.
Show 6 quoted lines
>
> If there isn't a bounds check slightly higher up in this loop, we should
> add one. Either way, we should definitely add a test using a mocked
> server response (e.g., via test-tool pkt-line) to ensure the client
> gracefully dies with a protocol error rather than segfaulting when it
> receives a malformed packet.

Ok, that's sounds a good test, I think there's none where a malicious server is simulated, in part because I don't know how and I think I haven't seen a test that does that yet. test-tool and pkt-line are used for the opposite: simulating the client to test the real server.

I'll see what I can do about it.

Thanks for the feedback, Pablo

Previous: Chandra PratapNext: Chandra Pratap
Message 9 of 112 in “cat-file: extend remote-object-info to support %(objecttype)”
  1. 0/5 cat-file: extend remote-object-info to support %(objecttype)Pablo Sabater, Jul 25, 2026
  2. 1/5 protocol-caps: add type support to object-infoPablo Sabater, Jul 25, 2026
  3. Chandra PratapJul 29, 2026
  4. Pablo SabaterJul 29, 2026
  5. Junio C HamanoJul 29, 2026
  6. Karthik NayakJul 29, 2026
  7. 2/5 fetch-object-info: parse type from server responsePablo Sabater, Jul 25, 2026
  8. Chandra PratapJul 29, 2026
  9. Pablo SabaterJul 29, 2026
  10. Chandra PratapJul 29, 2026
  11. Karthik NayakJul 29, 2026
  12. Karthik NayakJul 29, 2026
  13. 3/5 fetch-object-info: request all supported options dynamicallyPablo Sabater, Jul 25, 2026
  14. Chandra PratapJul 29, 2026
  15. Pablo SabaterJul 29, 2026
  16. 4/5 serve: advertise type capabilityPablo Sabater, Jul 25, 2026
  17. Chandra PratapJul 29, 2026
  18. Pablo SabaterJul 29, 2026
  19. 5/5 cat-file: unify default formatPablo Sabater, Jul 25, 2026
  20. Chandra PratapJul 29, 2026
  21. Pablo SabaterJul 29, 2026
  22. Chandra PratapJul 29, 2026
  23. Pablo SabaterJul 29, 2026
  24. 0/6 cat-file: extend remote-object-info to support %(objecttype)Pablo Sabater, Jul 31, 2026
  25. 1/6 fetch-object-info: request all supported options dynamicallyPablo Sabater, Jul 31, 2026
  26. Junio C HamanoJul 31, 2026
  27. 2/6 t5701: use the test_file_size() helperPablo Sabater, Jul 31, 2026
  28. Junio C HamanoAug 1, 2026
  29. Pablo SabaterAug 1, 2026
  30. 3/6 protocol-caps: add type support to object-infoPablo Sabater, Jul 31, 2026
  31. Junio C HamanoAug 1, 2026
  32. 4/6 fetch-object-info: parse type from server responsePablo Sabater, Jul 31, 2026
  33. Junio C HamanoAug 1, 2026
  34. Junio C HamanoAug 1, 2026
  35. Pablo SabaterAug 1, 2026
  36. Jeff KingAug 1, 2026
  37. Jeff KingAug 1, 2026
  38. Junio C HamanoAug 2, 2026
  39. Pablo SabaterAug 2, 2026
  40. Jeff KingAug 2, 2026
  41. Junio C HamanoAug 2, 2026
  42. Junio C HamanoAug 2, 2026
  43. Jeff KingAug 2, 2026
  44. Junio C HamanoAug 2, 2026
  45. Pablo SabaterAug 1, 2026
  46. 5/6 serve: advertise type capabilityPablo Sabater, Jul 31, 2026
  47. Chandra PratapAug 1, 2026
  48. Pablo SabaterAug 1, 2026
  49. 6/6 cat-file: unify default formatPablo Sabater, Jul 31, 2026
  50. 0/8 cat-file: extend remote-object-info to support %(objecttype)Pablo Sabater, Aug 3, 2026
  51. 1/8 t5701: use test_file_size() to get the size of a filePablo Sabater, Aug 3, 2026
  52. Junio C HamanoAug 3, 2026
  53. Pablo SabaterAug 3, 2026
  54. 2/8 fetch-object-info: detect truncated server responsesPablo Sabater, Aug 3, 2026
  55. Junio C HamanoAug 3, 2026
  56. Pablo SabaterAug 3, 2026
  57. 3/8 fetch-object-info: pass arguments directly instead of a structPablo Sabater, Aug 3, 2026
  58. Junio C HamanoAug 3, 2026
  59. Karthik NayakAug 4, 2026
  60. Pablo SabaterAug 4, 2026
  61. 4/8 fetch-object-info: use dedicated struct for the resultsPablo Sabater, Aug 3, 2026
  62. Junio C HamanoAug 3, 2026
  63. Pablo SabaterAug 3, 2026
  64. 5/8 protocol-caps: add type support to object-infoPablo Sabater, Aug 3, 2026
  65. 6/8 fetch-object-info: parse type from server responsePablo Sabater, Aug 3, 2026
  66. 7/8 serve: advertise type capabilityPablo Sabater, Aug 3, 2026
  67. 8/8 cat-file: unify default formatPablo Sabater, Aug 3, 2026
  68. 0/9 cat-file: extend remote-object-info to support %(objecttype)Pablo Sabater, Aug 4, 2026
  69. 1/9 t5701: use test_file_size() to get the size of a filePablo Sabater, Aug 4, 2026
  70. 2/9 fetch-object-info: detect malformed server responsesPablo Sabater, Aug 4, 2026
  71. Junio C HamanoAug 4, 2026
  72. 3/9 fetch-object-info: pass arguments directly instead of a structPablo Sabater, Aug 4, 2026
  73. Junio C HamanoAug 4, 2026
  74. Karthik NayakAug 6, 2026
  75. 5/9 fetch-object-info: die() on the remaining error pathPablo Sabater, Aug 4, 2026
  76. 4/9 fetch-object-info: use dedicated struct for the resultsPablo Sabater, Aug 4, 2026
  77. Junio C HamanoAug 4, 2026
  78. Pablo SabaterAug 4, 2026
  79. 6/9 protocol-caps: add type support to object-infoPablo Sabater, Aug 4, 2026
  80. 7/9 fetch-object-info: parse type from server responsePablo Sabater, Aug 4, 2026
  81. 8/9 serve: advertise type capabilityPablo Sabater, Aug 4, 2026
  82. 9/9 cat-file: unify default formatPablo Sabater, Aug 4, 2026
  83. Jeff KingAug 6, 2026
  84. Pablo SabaterAug 7, 2026
  85. Jeff KingAug 7, 2026
  86. 00/10 cat-file: extend remote-object-info to support %(objecttype)Pablo Sabater, Aug 7, 2026
  87. 01/10 t5701: use test_file_size() to get the size of a filePablo Sabater, Aug 7, 2026
  88. 02/10 fetch-object-info: detect malformed server responsesPablo Sabater, Aug 7, 2026
  89. 03/10 fetch-object-info: pass arguments directly instead of a structPablo Sabater, Aug 7, 2026
  90. 04/10 fetch-object-info: use dedicated struct for the resultsPablo Sabater, Aug 7, 2026
  91. 05/10 fetch-object-info: die() on the remaining error pathPablo Sabater, Aug 7, 2026
  92. 06/10 transport: drop remote object-info fields from transport structPablo Sabater, Aug 7, 2026
  93. 07/10 protocol-caps: add type support to object-infoPablo Sabater, Aug 7, 2026
  94. 08/10 fetch-object-info: parse type from server responsePablo Sabater, Aug 7, 2026
  95. 09/10 serve: advertise type capabilityPablo Sabater, Aug 7, 2026
  96. 10/10 cat-file: unify default formatPablo Sabater, Aug 7, 2026
  97. Pablo SabaterAug 7, 2026
  98. 00/10 cat-file: extend remote-object-info to support %(objecttype)Pablo Sabater, Aug 8, 2026
  99. 01/10 t5701: use test_file_size() to get the size of a filePablo Sabater, Aug 8, 2026
  100. 02/10 fetch-object-info: detect malformed server responsesPablo Sabater, Aug 8, 2026
  101. 03/10 fetch-object-info: pass arguments directly instead of a structPablo Sabater, Aug 8, 2026
  102. 04/10 fetch-object-info: use dedicated struct for the resultsPablo Sabater, Aug 8, 2026
  103. 05/10 fetch-object-info: die() on the remaining error pathPablo Sabater, Aug 8, 2026
  104. 06/10 transport: drop remote object-info fields from transport structPablo Sabater, Aug 8, 2026
  105. Junio C HamanoAug 8, 2026
  106. Chandra PratapAug 8, 2026
  107. Karthik NayakAug 11, 2026
  108. 07/10 protocol-caps: add type support to object-infoPablo Sabater, Aug 8, 2026
  109. 08/10 fetch-object-info: parse type from server responsePablo Sabater, Aug 8, 2026
  110. 09/10 serve: advertise type capabilityPablo Sabater, Aug 8, 2026
  111. 10/10 cat-file: unify default formatPablo Sabater, Aug 8, 2026
  112. Jeff KingAug 8, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.