From: Patrick Steinhardt Date: Thu, 01 Oct 2026 13:15:51 GMT Subject: Re: [PATCH v2 4/7] xdiff: NUL-terminate buffers read by read_mmfile() Message-ID: In-Reply-To: <20260930234413.GD1347555@coredump.intra.peff.net> On Wed, Sep 30, 2026 at 07:44:13PM -0400, Jeff King wrote: > Since an mmfile_t is a ptr/len pair, our read_mmfile() allocates exactly > the number of bytes we claim to store. But in many other places in Git, > we add an extra NUL "just in case", which can help avoid read overruns > due to off-by-ones or the use of string functions. > > I don't know of any path that would benefit from this, but I noticed it > while converting ll_ext_merge() to use read_mmfile(), since its original > code did add a NUL byte (even though I cannot find any case where it > would have mattered). Let's add the same defensive NUL in read_mmfile() > by using xmallocz() instead of xmalloc(). Nit: I guess this is an artifact from the reorder, but this sounds as if `ll_ext_merge()` wouldn't append the NUL byte anymore. But at this step it still does, as the change to `read_mmfile()` now happens before the change to `ll_ext_merge()`. Patrick