git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3 2/2] sequencer: fix quoting in write_author_script

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 2, 2018, 17:27 UTC
Message-ID
<xmqqk1p83cig.fsf@gitster-ct.c.googlers.com>
In-Reply-To
<20180802112002.720-3-phillip.wood@talktalk.net>
Phillip Wood <phillip.wood@talktalk.net> writes:
Show 13 quoted lines
> From: Phillip Wood <phillip.wood@dunelm.org.uk>
>
> Single quotes should be escaped as \' not \\'. The bad quoting breaks
> the interactive version of 'rebase --root' (which is used when there is
> no '--onto' even if the user does not specify --interactive) for authors
> that contain "'" as sq_dequote() called read_author_ident() errors out
> on the bad quoting.
>
> For other interactive rebases this only affects external scripts that
> read the author script and users whose git is upgraded from the shell
> version of rebase -i while rebase was stopped when the author contains
> "'". This is because the parsing in read_env_script() expected the
> broken quoting.

I wasn't following the discussion, but is it the general consensus that reading the broken a-i file is a requirement for the new code? Not an objection phrased as a question.

I do not think it is worth worrying about the "upgrade while rebase was in progress" case, if it involves much more code than necessary without its support, especially if the only thing the user needs to do recover from such a situation is to say "rebase --abort" and then to retry the same rebase with the fixed version that was installed in the meantime. Let's see how much we need to bend over backwards to do this "transition" thing.

> Ideally rebase and am would share the same code for reading and
> writing the author script, but this commit just fixes the immediate
> bug.
OK.
Show 10 quoted lines
> diff --git a/git-rebase--interactive.sh b/git-rebase--interactive.sh
> index 06a7b79307..c1e3f947a5 100644
> --- a/git-rebase--interactive.sh
> +++ b/git-rebase--interactive.sh
> @@ -880,7 +880,7 @@ init_basic_state () {
>  	mkdir -p "$state_dir" || die "$(eval_gettext "Could not create temporary \$state_dir")"
>  	rm -f "$(git rev-parse --git-path REBASE_HEAD)"
>  
> -	: > "$state_dir"/interactive || die "$(gettext "Could not mark as interactive")"
> +	echo 1 > "$state_dir"/interactive || die "$(gettext "Could not mark as interactive")"

This impacts the work Alban is doing, which at the end removes this script altogether.

> +/*
> + * write_author_script() used to fail to terminate the GIT_AUTHOR_DATE line with
> + * a "'" and also escaped "'" incorrectly as "'\\\\''" rather than "'\\''". Fix

I think the comment here (for both the wrong and the right versions) is easier to read if you wrote the string as literal without C, i.e. The string is "'\\''" but as a string literal in C it is expressed as "'\\\\''".

Show 6 quoted lines
> +static int fix_bad_author_script(struct strbuf *script)
> +{
> +	const char *next;
> +	size_t off = 0;
> +
> +	while ((next = strstr(script->buf + off, "'\\\\''"))) {
This looks brittle.

We need assurance that the first "'\\''" we see on the line came from the attempt by the broken writer to write out a single "'", and not from anything else. The broken writer places its own "'" immediately after GIT_AUTHOR_NAME= (just like the corrected one does) before moving on to the end-user payload. Can the single quote at the beginning of the substring you are looking for be that one? If the end user's payload began with two backslashes, that would have produced a result that matches the first three bytes of the substring you are looking for. But there is no way for the end-user payload to make the next two bytes "''"---any byte other than a sq would result in a sq added to the result, and a byte that is a sq would give one sq followed by a bs.

OK, so this is probably doing the right thing, as long as we know we are reading from the old and broken writer. It still does look unnecessarily ugly and over-engineered to have this (and the "version" reading code), though, at least to me, but perhaps it is just me.

Thanks.
Previous: Phillip WoodNext: Eric Sunshine
Message 39 of 57 in “fix "rebase -i --root" corrupting root commit”
  1. 0/4 fix "rebase -i --root" corrupting root commitEric Sunshine, Jul 31, 2018
  2. 1/4 sequencer: fix "rebase -i --root" corrupting author headerEric Sunshine, Jul 31, 2018
  3. 2/4 sequencer: fix "rebase -i --root" corrupting author header timezoneEric Sunshine, Jul 31, 2018
  4. Phillip WoodJul 31, 2018
  5. Eric SunshineJul 31, 2018
  6. 4/4 sequencer: don't die() on bogus user-edited timestampEric Sunshine, Jul 31, 2018
  7. Phillip WoodJul 31, 2018
  8. Eric SunshineJul 31, 2018
  9. 3/4 sequencer: fix "rebase -i --root" corrupting author header timestampEric Sunshine, Jul 31, 2018
  10. Phillip WoodJul 31, 2018
  11. Eric SunshineJul 31, 2018
  12. Phillip WoodJul 31, 2018
  13. Eric SunshineJul 31, 2018
  14. Phillip WoodJul 31, 2018
  15. Eric SunshineJul 31, 2018
  16. 0/2 Fix author script quotingPhillip Wood, Jul 31, 2018
  17. 1/2 sequencer: handle errors in read_author_ident()Phillip Wood, Jul 31, 2018
  18. Eric SunshineJul 31, 2018
  19. Phillip WoodAug 1, 2018
  20. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Jul 31, 2018
  21. Eric SunshineJul 31, 2018
  22. Phillip WoodAug 1, 2018
  23. Junio C HamanoAug 1, 2018
  24. Phillip WoodAug 1, 2018
  25. Eric SunshineAug 1, 2018
  26. Hilco WijbengaAug 1, 2018
  27. Eric SunshineAug 1, 2018
  28. Hilco WijbengaAug 7, 2018
  29. Eric SunshineAug 7, 2018
  30. Junio C HamanoAug 7, 2018
  31. Johannes SchindelinAug 27, 2018
  32. brian m. carlsonAug 1, 2018
  33. Eric SunshineAug 2, 2018
  34. 0/2 Fix author script quotingPhillip Wood, Aug 2, 2018
  35. 1/2 sequencer: handle errors in read_author_ident()Phillip Wood, Aug 2, 2018
  36. Eric SunshineAug 3, 2018
  37. Junio C HamanoAug 3, 2018
  38. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Aug 2, 2018
  39. Junio C HamanoAug 2, 2018
  40. Eric SunshineAug 3, 2018
  41. Phillip WoodAug 3, 2018
  42. Eric SunshineAug 3, 2018
  43. Phillip WoodAug 3, 2018
  44. Junio C HamanoAug 7, 2018
  45. 0/2 fix author-script quotingPhillip Wood, Aug 7, 2018
  46. 1/2 sequencer: handle errors from read_author_ident()Phillip Wood, Aug 7, 2018
  47. Eric SunshineAug 8, 2018
  48. 2/2 sequencer: fix quoting in write_author_scriptPhillip Wood, Aug 7, 2018
  49. Eric SunshineAug 7, 2018
  50. Phillip WoodAug 7, 2018
  51. Eric SunshineAug 8, 2018
  52. Junio C HamanoAug 8, 2018
  53. Phillip WoodAug 9, 2018
  54. Phillip WoodAug 9, 2018
  55. Eric SunshineAug 8, 2018
  56. Phillip WoodAug 9, 2018
  57. Eric SunshineAug 8, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.