git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 2/3] path: use size_t for dir_prefix length

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 4, 2026, 17:15 UTC
Message-ID
<xmqqwlzr8qjs.fsf@gitster.g>
In-Reply-To
<20260304130502.8475-3-jayatheerthkulkarni2005@gmail.com>
K Jayatheerth <jayatheerthkulkarni2005@gmail.com> writes:
> The strlen() function returns a size_t. Storing this in a standard
> signed int is a bad practice that invites overflow vulnerabilities if
> paths get absurdly long.

"a standard signed int" -> "an int variable". There is no "nonstandard signed int" anyway ;-)

If we were doing malloc(len) using length truncated due to integer wraparound and then strcpy() the whole string, it would make us write beyond the end of the allocation, but in this case, the worst thing that can happen is that we stop comparing prematurely, which may make us declare that buf is a path inside the directory dir when it isn't. The two callers of this function do not use this miscalculated len to carry out what they do, so there is no other damage. It indeed would be computing a wrong result, but "overflow vulnerabilities" is a slight exaggeration in the context of this patch, I think.

"overflow vulnerabilities" -> "bugs due to integer wraparound".
Show 23 quoted lines
> Switch the variable to size_t. This is safe to do because 'len' is
> strictly used as an argument to strncmp() (which expects size_t) and
> as a positive array index, involving no signed arithmetic that could
> rely on negative values.
>
> Signed-off-by: K Jayatheerth <jayatheerthkulkarni2005@gmail.com>
> ---
>  path.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/path.c b/path.c
> index f613d8bbd1..56be5e1726 100644
> --- a/path.c
> +++ b/path.c
> @@ -58,7 +58,7 @@ static void strbuf_cleanup_path(struct strbuf *sb)
>  
>  static int dir_prefix(const char *buf, const char *dir)
>  {
> -	int len = strlen(dir);
> +	size_t len = strlen(dir);
>  	return !strncmp(buf, dir, len) &&
>  		(is_dir_sep(buf[len]) || buf[len] == '\0');
>  }
Previous: K JayatheerthNext: K Jayatheerth
Message 12 of 21 in “path: clean up few things”
  1. 0/3 path: clean up few thingsK Jayatheerth, Mar 2, 2026
  2. 1/3 path: remove unused headerK Jayatheerth, Mar 2, 2026
  3. 2/3 path: use the right datatypeK Jayatheerth, Mar 2, 2026
  4. Patrick SteinhardtMar 3, 2026
  5. Junio C HamanoMar 3, 2026
  6. 3/3 path: remove redundant function callsK Jayatheerth, Mar 2, 2026
  7. Patrick SteinhardtMar 3, 2026
  8. Junio C HamanoMar 3, 2026
  9. 0/3 clean up a few thingsK Jayatheerth, Mar 4, 2026
  10. 1/3 path: remove unused headerK Jayatheerth, Mar 4, 2026
  11. 2/3 path: use size_t for dir_prefix lengthK Jayatheerth, Mar 4, 2026
  12. Junio C HamanoMar 4, 2026
  13. 3/3 path: remove redundant function callsK Jayatheerth, Mar 4, 2026
  14. 0/3 clean up a few thingsK Jayatheerth, Mar 5, 2026
  15. 1/3 path: remove unused headerK Jayatheerth, Mar 5, 2026
  16. 2/3 path: use size_t for dir_prefix lengthK Jayatheerth, Mar 5, 2026
  17. 3/3 path: remove redundant function callsK Jayatheerth, Mar 5, 2026
  18. Junio C HamanoMar 5, 2026
  19. K JayatheerthMar 6, 2026
  20. K JayatheerthMar 6, 2026
  21. Junio C HamanoMar 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.