Re: [PATCH v2 2/4] string-list: replace negative index encoding with "exact_match" parameter
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Sep 24, 2025, 13:20 UTC
- Message-ID
- <xmqqwm5om1gy.fsf@gitster.g>
- In-Reply-To
- <20250924053601.GC1173044@coredump.intra.peff.net>
Jeff King <peff@peff.net> writes:
> I agree that size_t is much more than one needs for counting most > things. But the problem is that "int" is much too small, if you are > worried about malicious input causing integer overflows that could cause > memory access errors.
Well, a malicious input can cause overflow/wraparound size_t while parsing, so I do not think that is really an argument.
The code need to be protected against such overflows either way.