git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] commit.c: ensure strchrnul() doesn't scan beyond range

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 8, 2024, 21:44 UTC
Message-ID
<xmqqcyt6my0f.fsf@gitster.g>
In-Reply-To
<20240208214137.GB1090198@coredump.intra.peff.net>
Jeff King <peff@peff.net> writes:
>   1. It is not possible for the buf/len pair we pass to check_nonce() to
>      contain a NUL. And thus there is no caller of find_header_mem()
>      that can contain an embedded NUL. So switching from strchrnul() to
>      just memchr() should be OK there.
Correct.
>   2. That raises the question of whether parse_signed_buffer() has a
>      similar walk-too-far problem. ;) The answer is no, because we feed
>      it from a strbuf. But it's not a great pattern overall.
True, too.
Thanks.
Previous: Jeff KingNext: Kyle Lippincott
Message 9 of 13 in “commit.c: ensure strchrnul() doesn't scan beyond range”
  1. commit.c: ensure strchrnul() doesn't scan beyond rangeChandra Pratap via GitGitGadget, Feb 5, 2024
  2. René ScharfeFeb 5, 2024
  3. Junio C HamanoFeb 6, 2024
  4. Jeff KingFeb 8, 2024
  5. René ScharfeFeb 8, 2024
  6. Junio C HamanoFeb 8, 2024
  7. Kyle LippincottFeb 8, 2024
  8. Jeff KingFeb 8, 2024
  9. Junio C HamanoFeb 8, 2024
  10. Kyle LippincottFeb 6, 2024
  11. commit.c: ensure find_header_mem() doesn't scan beyond given rangeChandra Pratap via GitGitGadget, Feb 7, 2024
  12. René ScharfeFeb 7, 2024
  13. Junio C HamanoFeb 7, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.