From: Phillip Wood Date: Mon, 08 Sep 2025 14:23:10 GMT Subject: Re: [PATCH 7/9] submodule: remove validate_submodule_git_dir() Message-ID: In-Reply-To: <20250816213642.3517822-8-adrian.ratiu@collabora.com> Hi Adrian On 16/08/2025 22:36, Adrian Ratiu wrote: > > + /* Trigger a BUG if these invariants do not hold */ > + p = buf->buf + buf->len - encoded_len; > + if (buf->len <= encoded_len || p[-1] != '/' || strcmp(p, encoded_sub_name.buf)) if buf->len is less than encoded_len then the pointer p is invalid. As a valid program cannot create an invalid pointer the compiler may assume that buf->len >= encoded_len. We should check the lengths before creating the pointer as the original code in validate_submodule_git_dir() did which looked like > if (len <= suffix_len || (p = git_dir + len - suffix_len)[-1] != '/' || > strcmp(p, submodule_name)) Thanks Phillip > + BUG("encoded submodule name '%s' is not a suffix of git dir '%s'", > + encoded_sub_name.buf, buf->buf); > + > strbuf_release(&encoded_sub_name); > } > diff --git a/submodule.h b/submodule.h > index b10e16e6c0..0b7692bc20 100644 > --- a/submodule.h > +++ b/submodule.h > @@ -137,11 +137,6 @@ int submodule_to_gitdir(struct repository *repo, > void submodule_name_to_gitdir(struct strbuf *buf, struct repository *r, > const char *submodule_name); > > -/* > - * Make sure that no submodule's git dir is nested in a sibling submodule's. > - */ > -int validate_submodule_git_dir(char *git_dir, const char *submodule_name); > - > /* > * Make sure that the given submodule path does not follow symlinks. > */