Re: [PATCH] diff: fix out-of-bounds reads and NULL deref in diffstat UTF-8 truncation
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Apr 17, 2026, 22:21 UTC
- Message-ID
- <xmqq4il9w7ls.fsf@gitster.g>
- In-Reply-To
- <CABPp-BHt-O=CCnGHjoXBOHCe5CbD7beyrd_gX51g9Xg7cn_eFg@mail.gmail.com>
Elijah Newren <newren@gmail.com> writes:
> Makes sense, though I think my simpler alternative might be easier. > I'll send in a re-roll.
As long as "an invalid UTF-8" and "a control character" behaves more or less the same (i.e., "eek, we cannot measure the width of the UTF-8 character at this byte position, so let's do X as a fallback", where X is the same regardless of the exact reason why we cannot measure the width), I'll be happy. If we see a slash after the problematic position, advancing to that slash might be the simplest, as that is in line with how the code works when there is no such problem, but we also need to be prepared for a filename whose last component is sufficiently long that we see no such slash after the problematic byte.