git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] diff: fix out-of-bounds reads and NULL deref in diffstat UTF-8 truncation

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 17, 2026, 22:21 UTC
Message-ID
<xmqq4il9w7ls.fsf@gitster.g>
In-Reply-To
<CABPp-BHt-O=CCnGHjoXBOHCe5CbD7beyrd_gX51g9Xg7cn_eFg@mail.gmail.com>
Elijah Newren <newren@gmail.com> writes:
> Makes sense, though I think my simpler alternative might be easier.
> I'll send in a re-roll.

As long as "an invalid UTF-8" and "a control character" behaves more or less the same (i.e., "eek, we cannot measure the width of the UTF-8 character at this byte position, so let's do X as a fallback", where X is the same regardless of the exact reason why we cannot measure the width), I'll be happy. If we see a slash after the problematic position, advancing to that slash might be the simplest, as that is in line with how the code works when there is no such problem, but we also need to be prepared for a filename whose last component is sufficiently long that we see no such slash after the problematic byte.

Previous: Elijah NewrenNext: Elijah Newren via GitGitGadget
Message 4 of 9 in “diff: fix out-of-bounds reads and NULL deref in diffstat UTF-8 truncation”
  1. diff: fix out-of-bounds reads and NULL deref in diffstat UTF-8 truncationElijah Newren via GitGitGadget, Apr 17, 2026
  2. Junio C HamanoApr 17, 2026
  3. Elijah NewrenApr 17, 2026
  4. Junio C HamanoApr 17, 2026
  5. diff: fix out-of-bounds reads and NULL deref in diffstat UTF-8 truncationElijah Newren via GitGitGadget, Apr 17, 2026
  6. Lorenzo PegorariApr 19, 2026
  7. Elijah NewrenApr 20, 2026
  8. diff: fix out-of-bounds reads and NULL deref in diffstat UTF-8 truncationElijah Newren via GitGitGadget, Apr 20, 2026
  9. Junio C HamanoApr 20, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.