git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v5 1/1] worktree add: sanitize worktree names

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 12, 2019, 06:45 UTC
Message-ID
<xmqqzhq0h9pk.fsf@gitster-ct.c.googlers.com>
In-Reply-To
<nycvar.QRO.7.76.6.1903111401220.41@tvgsbejvaqbjf.bet>
Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:
Show 23 quoted lines
>> +static int check_refname_component(const char *refname, int *flags,
>> +				   struct strbuf *sanitized)
>>  {
>>  	const char *cp;
>>  	char last = '\0';
>> +	size_t component_start;
>
> This variable is uninitialized. It is then...
>
>> +
>> +	if (sanitized)
>> +		component_start = sanitized->len;
>
> ... initialized only when `sanitized` is not `NULL`, and subsequently...
> ...
>> +	if (refname[0] == '.') { /* Component starts with '.'. */
>> +		if (sanitized)
>> +			sanitized->buf[component_start] = '-';
> ...
> ... used a loooooooong time after that, also only if `sanitized` is not
> `NULL`.
>
> Apparently for some GCC versions, this is too cute, and it complains that

It does require humans (well, at least it did to this one) to be careful when reading the code to know that component_start is valid when it is used.

There unfortunately is no good "default" value to initialize the variable to. When checking a later component in a series of components, it would be looking at non-zero position, so even initializing it to 0 in this function is *not* a more sensible fallback default value than any other random garbage value (which would squelch the compiler, but it would mislead the humans nevertheless).

And that (i.e. the lack of any sensible default value when sanitized is NULL) is the reason why the variable is left uninitialized by the patch, I think. I do not think the code is trying to be cute at all.

I wonder if we make the caller pass a pointer to
	struct {
		struct strbuf result;
		size_t component_start;
	} sanitized;
	sanitized.component_start = sanitized.result.len
	check_refname_component(refname, flags, &sanitized);

and get rid of the assignment to component_start done by the callee, it would appease compilers and makes the code easier to vet. It does introduce one more ad-hoc type, which is a certain downside.

I dunno.
Previous: Johannes Schindelin
Message 41 of 41 in “git gc fails with "unable to resolve reference" for worktree”
  1. hi-angel@yandex.ruFeb 18, 2019
  2. Duy NguyenFeb 18, 2019
  3. hi-angel@yandex.ruFeb 18, 2019
  4. Duy NguyenFeb 18, 2019
  5. hi-angel@yandex.ruFeb 20, 2019
  6. worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Feb 21, 2019
  7. Konstantin KharlamovFeb 21, 2019
  8. Duy NguyenFeb 21, 2019
  9. Konstantin KharlamovFeb 21, 2019
  10. Duy NguyenFeb 21, 2019
  11. Jeff KingFeb 21, 2019
  12. 0/1 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Feb 21, 2019
  13. 1/1 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Feb 21, 2019
  14. Jeff KingFeb 21, 2019
  15. Ramsay JonesFeb 21, 2019
  16. Duy NguyenFeb 22, 2019
  17. 0/1 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Feb 26, 2019
  18. 1/1 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Feb 26, 2019
  19. Jeff KingFeb 27, 2019
  20. Eric SunshineFeb 27, 2019
  21. Jeff KingFeb 27, 2019
  22. Junio C HamanoMar 3, 2019
  23. Duy NguyenMar 4, 2019
  24. Duy NguyenMar 4, 2019
  25. Johannes SchindelinMar 4, 2019
  26. 0/2 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Mar 5, 2019
  27. 1/2 refs.c: refactor check_refname_component()Nguyễn Thái Ngọc Duy, Mar 5, 2019
  28. Jeff KingMar 6, 2019
  29. Eric SunshineMar 7, 2019
  30. 2/2 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Mar 5, 2019
  31. 0/1 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Mar 8, 2019
  32. 1/1 worktree add: sanitize worktree namesNguyễn Thái Ngọc Duy, Mar 8, 2019
  33. Eric SunshineMar 10, 2019
  34. Junio C HamanoMar 11, 2019
  35. Duy NguyenMar 11, 2019
  36. Jeff KingMar 11, 2019
  37. Junio C HamanoMar 12, 2019
  38. Junio C HamanoMar 11, 2019
  39. Duy NguyenMar 11, 2019
  40. Johannes SchindelinMar 11, 2019
  41. Junio C HamanoMar 12, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.