git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 5/5] xdiff: NUL-terminate buffers read by read_mmfile()

From
Patrick Steinhardt <ps@pks.im>
Date
Sep 30, 2026, 15:32 UTC
Message-ID
<ar0rp1cSIKuCMZyQ@pks.im>
In-Reply-To
<20260929065504.GE1697497@coredump.intra.peff.net>
On Tue, Sep 29, 2026 at 02:55:04AM -0400, Jeff King wrote:
Show 21 quoted lines
> Since an mmfile_t is a ptr/len pair, our read_mmfile() allocates exactly
> the number of bytes we claim to store. But in many other places in Git,
> we add an extra NUL "just in case", which can help avoid read overruns
> due to off-by-ones or the use of string functions.
> 
> I don't know of any path that would benefit from this, but I noticed it
> while converting ll_ext_merge() to use read_mmfile(), since its original
> code did add a NUL byte (even though I cannot find any case where it
> would have mattered). Let's teach read_mmfile() to add this defensive
> NUL; it probably doesn't help anything, but nor should it hurt.
> 
> Note that the matching read_mmblob() doesn't need the same treatment.
> Its buffers already have a NUL from the object-reading code (which uses
> the same defensive trick).
> 
> As a bonus, we can get rid of the hack in read_mmfile() to handle empty
> files by allocating a single byte.
> 
> Signed-off-by: Jeff King <peff@peff.net>
> ---
> This one is obviously optional, which is why I put it last.

Hm, I'm somewhat indifferent here. It always feels a bit weird to be this defensive because "programming errors", as the next question then is "but what about all the other errors where we're not defensive?" But the xdiff code is complex enough with a bunch of pointer arithmetics, so maybe it's not even that bad of an idea.

That being said, I feel like a better course of action could be to use a fuzzer for this code, because as far as I'm aware we have none yet, and that would potentially shake out a bunch of bugs. But that still doesn't really help us to catch platform-specific bugs due to different integer sizes.

The counterargument is that before your 3/5 we used to use xmallocz, so you're essentially just reinstating the previous safety guards.

Show 10 quoted lines
> diff --git a/xdiff-interface.c b/xdiff-interface.c
> index bc340d5a8a..b3e9f1952b 100644
> --- a/xdiff-interface.c
> +++ b/xdiff-interface.c
> @@ -166,7 +166,7 @@ int read_mmfile(mmfile_t *ptr, const char *filename)
>  	if (!(f = fopen(filename, "rb")))
>  		return error_errno("Could not open %s", filename);
>  	sz = xsize_t(st.st_size);
> -	ptr->ptr = xmalloc(sz ? sz : 1);
> +	ptr->ptr = xmallocz(sz);

I was staring at this code a while before I noticed the added `z` at the end of this function.

Patrick
Previous: Jeff KingNext: Junio C Hamano
Message 25 of 37 in “use size_t for xdiff mmfile_t”
  1. 0/5 use size_t for xdiff mmfile_tJeff King, Sep 29, 2026
  2. 1/5 xdiff: clean up read_mmfile() allocations on errorJeff King, Sep 29, 2026
  3. Junio C HamanoSep 29, 2026
  4. 2/5 xdiff: replace mmbuffer_t with mmfile_tJeff King, Sep 29, 2026
  5. D. Ben KnobleSep 29, 2026
  6. Junio C HamanoSep 29, 2026
  7. Patrick SteinhardtSep 30, 2026
  8. Jeff KingSep 30, 2026
  9. Junio C HamanoOct 1, 2026
  10. 3/5 xdiff: use size_t for buffer sizesJeff King, Sep 29, 2026
  11. 4/5 merge-ll: use read_mmfile() to read external merge resultsJeff King, Sep 29, 2026
  12. Junio C HamanoSep 29, 2026
  13. Jeff KingSep 29, 2026
  14. Jeff KingSep 29, 2026
  15. 6/5 merge-ll: handle external driver status before reading resultJeff King, Sep 29, 2026
  16. 7/5 merge-ll: report an error when reading external merge results failsJeff King, Sep 29, 2026
  17. Junio C HamanoSep 29, 2026
  18. Jeff KingSep 29, 2026
  19. Junio C HamanoSep 30, 2026
  20. Jeff KingSep 30, 2026
  21. Junio C HamanoOct 1, 2026
  22. Patrick SteinhardtSep 30, 2026
  23. Jeff KingSep 30, 2026
  24. 5/5 xdiff: NUL-terminate buffers read by read_mmfile()Jeff King, Sep 29, 2026
  25. Patrick SteinhardtSep 30, 2026
  26. Junio C HamanoSep 30, 2026
  27. Jeff KingSep 30, 2026
  28. 0/7 use size_t for xdiff mmfile_tJeff King, Sep 30, 2026
  29. 1/7 xdiff: clean up read_mmfile() allocations on errorJeff King, Sep 30, 2026
  30. 2/7 xdiff: replace mmbuffer_t with mmfile_tJeff King, Sep 30, 2026
  31. 3/7 xdiff: use size_t for buffer sizesJeff King, Sep 30, 2026
  32. 4/7 xdiff: NUL-terminate buffers read by read_mmfile()Jeff King, Sep 30, 2026
  33. Patrick SteinhardtOct 1, 2026
  34. 5/7 merge-ll: use read_mmfile() to read external merge resultsJeff King, Sep 30, 2026
  35. Patrick SteinhardtOct 1, 2026
  36. 6/7 merge-ll: handle external driver status before reading resultJeff King, Sep 30, 2026
  37. 7/7 merge-ll: report an error when reading external merge results failsJeff King, Sep 30, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.