git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 0/3] wildmatch: fix exponential behavior

From
PWPhillip Wood <phillip.wood123@gmail.com>
Date
Mar 20, 2023, 16:09 UTC
Message-ID
<cover.1679328580.git.phillip.wood@dunelm.org.uk>
From: Phillip Wood <phillip.wood@dunelm.org.uk>

The wildmatch implementation in git suffers from exponential behavior as described in [1] where the time taken for a failing match is exponential in the number of wildcards it contains. The original implementation imported from rsync is immune but the optimizations introduced by [2.3] failed to prevent unnecessary backtracking when handling '*' and '/**/'.

This bug was were discussed on the security list and the conclusion was that it only affects operations that are already potential DoS vectors.

In the long term it would be nice to get rid of the recursion in the wildmatch() code but the patches here focus on a minimal fix.

This series is based on maint. Unfortunately it conflicts with my/wildmatch-cleanups when merged with seen. There are sematic conflicts with the removal of dowild() in e303cf8092 (wildmatch: more cleanups after killing uchar, 2023-02-26) as well as textual conflicts around the change of uchar->char.

[1] https://research.swtch.com/glob [2] 6f1a31f0aa (wildmatch: advance faster in <asterisk> + <literal> patterns, 2013-01-01) [3] 46983441ae (wildmatch: make a special case for "*/" with FNM_PATHNAME, 2013-01-01)

Published-As: https://github.com/phillipwood/git/releases/tag/wildmatch-fixes%2Fv1
View-Changes-At: https://github.com/phillipwood/git/compare/73876f486...a74ab7138
Fetch-It-Via: git fetch https://github.com/phillipwood/git wildmatch-fixes/v1
Phillip Wood (3):
  wildmatch: fix exponential behavior
  wildmatch: avoid undefined behavior
  wildmatch: hide internal return values
 t/t3070-wildmatch.sh |  9 +++++++++
 wildmatch.c          | 23 ++++++++++++++++-------
 wildmatch.h          |  2 --
 3 files changed, 25 insertions(+), 9 deletions(-)
-- 
2.39.2
Next: Phillip Wood
Message 1 of 22 in “wildmatch: fix exponential behavior”
  1. 0/3 wildmatch: fix exponential behaviorPhillip Wood, Mar 20, 2023
  2. 2/3 wildmatch: avoid undefined behaviorPhillip Wood, Mar 20, 2023
  3. 1/3 wildmatch: fix exponential behaviorPhillip Wood, Mar 20, 2023
  4. t3070: make chain lint tester happyMichael J Gruber, Mar 24, 2023
  5. Jeff KingMar 25, 2023
  6. Eric SunshineMar 25, 2023
  7. Jeff KingMar 25, 2023
  8. Jeff KingMar 25, 2023
  9. Eric SunshineMar 25, 2023
  10. Jeff KingMar 25, 2023
  11. Jeff KingMar 25, 2023
  12. Eric SunshineMar 25, 2023
  13. Jeff KingMar 25, 2023
  14. Eric SunshineMar 25, 2023
  15. Phillip WoodMar 26, 2023
  16. Michael J GruberMar 26, 2023
  17. Eric SunshineMar 25, 2023
  18. Jeff KingMar 25, 2023
  19. 3/3 wildmatch: hide internal return valuesPhillip Wood, Mar 20, 2023
  20. Junio C HamanoMar 20, 2023
  21. Derrick StoleeMar 23, 2023
  22. Phillip WoodMar 24, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.