git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 0/4] fix "rebase -i --root" corrupting root commit

From
PWPhillip Wood <phillip.wood@talktalk.net>
Date
Jul 31, 2018, 10:05 UTC
Message-ID
<f9a7e77d-3c67-082e-ed8d-701f4d0d1759@talktalk.net>
In-Reply-To
<20180731073331.40007-1-sunshine@sunshineco.com>
Hi Eric
On 31/07/18 08:33, Eric Sunshine wrote:
Show 48 quoted lines
> This is a re-roll of [1] which fixes sequencer bugs resulting in commit
> object corruption when "rebase -i --root" swaps in a new commit as root.
> Unfortunately, those bugs made it into v2.18.0 and have already
> corrupted at least one repository (a local project of mine). Patches 3/4
> and 4/4 are new.
> 
> v1 fixed these bugs:
> 
> * trailing garbage on the commit's "author" header
> 
> * extra trailing digit on "author" header's timezone (caused by two
>    separate bugs)
> 
> v2 fixes those same bugs, plus:
> 
> * eliminates a bogus "@" prepended to the "author" header timestamp
>    which renders the header corrupt
> 
> * takes care to validate information coming from
>    "rebase-merge/author-script" before incorporating it into the "author"
>    header since that file may be hand-edited, and bogus hand-edited
>    values could corrupt the commit object.
> 
> Patch 2/4 of this series conflicts with Akinori MUSHA's
> 'am/sequencer-author-script-fix' which takes a stab at fixing one of the
> four (or so) bugs fixed by this series (namely, adding a missing closing
> quote to GIT_AUTHOR_DATE in "rebase-merge/author-script"). That patch
> probably ought to be dropped (without prejudice) in favor of this series
> for the following reasons:
> 
> * It has the undesirable property of adding an unwanted extra blank line
>    to "rebase-merge/author-script"; this series doesn't make that
>    mistake.
> 
> * The fix in this series (patch 2/4) is more complete, also ensuring
>    that the return value of sq_dequote() is checked.
> 
> * And, most importantly, this series sells the change as a fix for a
>    genuine serious bug (commit object corruption), whereas that patch
>    talks only about adjusting the file content to make it parseable by
>    the shell. It's important for future readers of this change to
>    understand that the bug (missing closing quote) had much more dire
>    consequences than merely being syntactically invalid as a shell
>    script.
> 
> The test added by Akinori MUSHA's patch may still have value, and it may
> make sense to re-submit it, however, doing so need not hold up this
> (higher priority) series.

Yes I think it does, also the patch that Johannes and I have on top of it to fix the quoting of "'" in write_author_script() relies on fixing the missing trailing quote and handling of "'" at the same time, hopefully we can get that rebased on top of these asap.

Best Wishes
Phillip
Show 72 quoted lines
> Phillip's proposed[2] unification of parsers and other fixes and
> cleanups can easily be built atop this series and, likewise, need not
> prevent these (higher priority) patches from graduating independently.
> 
> [1]: https://public-inbox.org/git/20180730092929.71114-1-sunshine@sunshineco.com/
> [2]: https://public-inbox.org/git/1f172fc1-4b51-cdf7-e841-5ca41e209be4@talktalk.net/
> 
> Eric Sunshine (4):
>    sequencer: fix "rebase -i --root" corrupting author header
>    sequencer: fix "rebase -i --root" corrupting author header timezone
>    sequencer: fix "rebase -i --root" corrupting author header timestamp
>    sequencer: don't die() on bogus user-edited timestamp
> 
>   sequencer.c                   | 39 +++++++++++++++++++++--------------
>   t/t3404-rebase-interactive.sh | 10 ++++++++-
>   2 files changed, 33 insertions(+), 16 deletions(-)
> 
> Range-diff against v1:
> 1:  ba10ae4e5d ! 1:  8c47555bcf sequencer: fix "rebase -i --root" corrupting author header
>      @@ -11,8 +11,8 @@
>           This is a result of read_author_ident() neglecting to NUL-terminate the
>           buffer into which it composes the "author" header.
>       
>      -    (Note that the extra "0" in the timezone is a separate bug which will be
>      -    fixed subsequently.)
>      +    (Note that the "@" preceding the timestamp and the extra "0" in the
>      +    timezone are separate bugs which will be fixed subsequently.)
>       
>           Security considerations: Construction of the "author" header by
>           read_author_ident() happens in-place and in parallel with parsing the
>      @@ -26,6 +26,7 @@
>           inserted as part of the parsing process.
>       
>           Signed-off-by: Eric Sunshine <sunshine@sunshineco.com>
>      +    Acked-by: Johannes Schindelin <johannes.schindelin@gmx.de>
>       
>       diff --git a/sequencer.c b/sequencer.c
>       --- a/sequencer.c
>      @@ -61,7 +62,7 @@
>       +	set_fake_editor &&
>       +	FAKE_LINES="2 1" git rebase -i --root &&
>       +	git cat-file commit HEAD^ >out &&
>      -+	grep "^author ..* @[0-9][0-9]* [-+][0-9][0-9]*$" out
>      ++	grep "^author ..*> @[0-9][0-9]* [-+][0-9][0-9]*$" out
>       +'
>       +
>        test_done
> 2:  c0400cda85 ! 2:  1d4064147e sequencer: fix "rebase -i --root" corrupting author header timezone
>      @@ -22,6 +22,9 @@
>           a NUL-terminator at the end of the shifted content, which explains the
>           duplicated last digit in the timezone.
>       
>      +    (Note that the "@" preceding the timestamp is a separate bug which
>      +    will be fixed subsequently.)
>      +
>           Signed-off-by: Eric Sunshine <sunshine@sunshineco.com>
>       
>       diff --git a/sequencer.c b/sequencer.c
>      @@ -56,8 +59,8 @@
>        	set_fake_editor &&
>        	FAKE_LINES="2 1" git rebase -i --root &&
>        	git cat-file commit HEAD^ >out &&
>      --	grep "^author ..* @[0-9][0-9]* [-+][0-9][0-9]*$" out
>      -+	grep "^author ..* @[0-9][0-9]* [-+][0-9][0-9][0-9][0-9]$" out
>      +-	grep "^author ..*> @[0-9][0-9]* [-+][0-9][0-9]*$" out
>      ++	grep "^author ..*> @[0-9][0-9]* [-+][0-9][0-9][0-9][0-9]$" out
>        '
>        
>        test_done
> -:  ---------- > 3:  cb65c7dd98 sequencer: fix "rebase -i --root" corrupting author header timestamp
> -:  ---------- > 4:  3a624da9f4 sequencer: don't die() on bogus user-edited timestamp
> 
Previous: Eric SunshineNext: Eric Sunshine
Message 12 of 57 in “fix "rebase -i --root" corrupting root commit”
  1. 0/4 fix "rebase -i --root" corrupting root commitEric Sunshine, Jul 31, 2018
  2. 1/4 sequencer: fix "rebase -i --root" corrupting author headerEric Sunshine, Jul 31, 2018
  3. 2/4 sequencer: fix "rebase -i --root" corrupting author header timezoneEric Sunshine, Jul 31, 2018
  4. Phillip WoodJul 31, 2018
  5. Eric SunshineJul 31, 2018
  6. 4/4 sequencer: don't die() on bogus user-edited timestampEric Sunshine, Jul 31, 2018
  7. Phillip WoodJul 31, 2018
  8. Eric SunshineJul 31, 2018
  9. 3/4 sequencer: fix "rebase -i --root" corrupting author header timestampEric Sunshine, Jul 31, 2018
  10. Phillip WoodJul 31, 2018
  11. Eric SunshineJul 31, 2018
  12. Phillip WoodJul 31, 2018
  13. Eric SunshineJul 31, 2018
  14. Phillip WoodJul 31, 2018
  15. Eric SunshineJul 31, 2018
  16. 0/2 Fix author script quotingPhillip Wood, Jul 31, 2018
  17. 1/2 sequencer: handle errors in read_author_ident()Phillip Wood, Jul 31, 2018
  18. Eric SunshineJul 31, 2018
  19. Phillip WoodAug 1, 2018
  20. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Jul 31, 2018
  21. Eric SunshineJul 31, 2018
  22. Phillip WoodAug 1, 2018
  23. Junio C HamanoAug 1, 2018
  24. Phillip WoodAug 1, 2018
  25. Eric SunshineAug 1, 2018
  26. Hilco WijbengaAug 1, 2018
  27. Eric SunshineAug 1, 2018
  28. Hilco WijbengaAug 7, 2018
  29. Eric SunshineAug 7, 2018
  30. Junio C HamanoAug 7, 2018
  31. Johannes SchindelinAug 27, 2018
  32. brian m. carlsonAug 1, 2018
  33. Eric SunshineAug 2, 2018
  34. 0/2 Fix author script quotingPhillip Wood, Aug 2, 2018
  35. 1/2 sequencer: handle errors in read_author_ident()Phillip Wood, Aug 2, 2018
  36. Eric SunshineAug 3, 2018
  37. Junio C HamanoAug 3, 2018
  38. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Aug 2, 2018
  39. Junio C HamanoAug 2, 2018
  40. Eric SunshineAug 3, 2018
  41. Phillip WoodAug 3, 2018
  42. Eric SunshineAug 3, 2018
  43. Phillip WoodAug 3, 2018
  44. Junio C HamanoAug 7, 2018
  45. 0/2 fix author-script quotingPhillip Wood, Aug 7, 2018
  46. 1/2 sequencer: handle errors from read_author_ident()Phillip Wood, Aug 7, 2018
  47. Eric SunshineAug 8, 2018
  48. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Aug 7, 2018
  49. Eric SunshineAug 7, 2018
  50. Phillip WoodAug 7, 2018
  51. Eric SunshineAug 8, 2018
  52. Junio C HamanoAug 8, 2018
  53. Phillip WoodAug 9, 2018
  54. Phillip WoodAug 9, 2018
  55. Eric SunshineAug 8, 2018
  56. Phillip WoodAug 9, 2018
  57. Eric SunshineAug 8, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.