git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] commit.c: ensure strchrnul() doesn't scan beyond range

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 8, 2024, 19:48 UTC
Message-ID
<xmqqil2yn3ey.fsf@gitster.g>
In-Reply-To
<8313d9d6-f6bd-4fae-be9c-e7a8129768eb@web.de>
René Scharfe <l.s.r@web.de> writes:
Show 6 quoted lines
> But anyway: If NULs are of no concern and we currently end parsing when
> we see one in all cases, why do we need a _mem function at all?  The
> original version of the function, find_commit_header(), should suffice.
> check_nonce() could be run against the NUL-terminated sigcheck.payload
> and check_cert_push_options() parses an entire strbuf, so there is no
> risk of out-of-bounds access.

If I recall correctly, the caller that does not pass strlen() as the payload length gives a length that is shorter than the buffer, i.e. "stop the parsing here, do not get confused into thinking the garbage after this point contains useful payload" was the reason why we have a separate "len".

Previous: René ScharfeNext: Kyle Lippincott
Message 6 of 13 in “commit.c: ensure strchrnul() doesn't scan beyond range”
  1. commit.c: ensure strchrnul() doesn't scan beyond rangeChandra Pratap via GitGitGadget, Feb 5, 2024
  2. René ScharfeFeb 5, 2024
  3. Junio C HamanoFeb 6, 2024
  4. Jeff KingFeb 8, 2024
  5. René ScharfeFeb 8, 2024
  6. Junio C HamanoFeb 8, 2024
  7. Kyle LippincottFeb 8, 2024
  8. Jeff KingFeb 8, 2024
  9. Junio C HamanoFeb 8, 2024
  10. Kyle LippincottFeb 6, 2024
  11. commit.c: ensure find_header_mem() doesn't scan beyond given rangeChandra Pratap via GitGitGadget, Feb 7, 2024
  12. René ScharfeFeb 7, 2024
  13. Junio C HamanoFeb 7, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.