Re: [PATCH v2 1/3] merge-ll: use strbuf to read back external merge result
Elijah Newren <newren@gmail.com> writes:
Show 9 quoted lines
> The old code narrows before xmallocz() , so it requests an impossibly
> large allocation and dies. The new code allocates the actual buffer
> first, then records a negative size; callers converting that size back
> to size_t could read past the allocation.
>
> Would a simple fail-fast make sense?
>
> if (result_buf.len > LONG_MAX)
> die(_("external merge result is too large"));Intereting find. That does sound sensible.