git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] attr: avoid recursion when expanding attribute macros

From
Junio C Hamano <gitster@pobox.com>
Date
Nov 12, 2025, 17:40 UTC
Message-ID
<xmqqjyzvqhdc.fsf@gitster.g>
In-Reply-To
<aRQvyvMq61syGT7_@pks.im>
Patrick Steinhardt <ps@pks.im> writes:
Show 7 quoted lines
> That's fair, and as you demonstrate it's easy enough to turn recursion
> into iteration. But it doesn't really solve the main problem: given
> malicious input we'd now still crash eventually, even though we
> ...
> So the evil garbage would continue to be a nuisance for users who want
> to clone such a repository, but now it's going to be more of a nuisance
> for hosting sites given that it could lead to out-of-memory situations.

That assumes there are users who want to clone such a repository with evil garbage in it, doesn't it? I am not sure how likely there exist such people, and even less sure if we want to actively support such users or discourage them.

I like the conversion from recursion to iteraiton as a general principle, but somehow I do not think this particular one is an issue that warrants more than minimum effort on it.

I also wonder how common the use of attribute macros (other than the built-in ones) are. Are folks working at hosting sites have easy access to public data (i.e., super "git grep" that lets them sample some random subset among many public repositories and work on them)?

Thanks.
Previous: Patrick Steinhardt
Message 8 of 8 in “attr: avoid recursion when expanding attribute macros”
  1. attr: avoid recursion when expanding attribute macrosJeff King, Nov 11, 2025
  2. Ben KnobleNov 12, 2025
  3. Jeff KingNov 12, 2025
  4. Jeff KingNov 12, 2025
  5. Patrick SteinhardtNov 12, 2025
  6. Jeff KingNov 12, 2025
  7. Patrick SteinhardtNov 12, 2025
  8. Junio C HamanoNov 12, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.