On macOS, git status may abort while reading a directory entry whose UTF-8 name grows past NAME_MAX bytes:
__chk_fail_overflow __strlcpy_chk precompose_utf8_readdir read_directory_recursive wt_status_collect cmd_status
The precompose wrapper already reallocates dirent_prec_psx for long names, but d_name is declared as char[NAME_MAX + 1]. A fortified libc can still see that declared object size and reject a larger strlcpy bound, even though the allocation was grown.
Make d_name a FLEX_ARRAY and size allocations from offsetof(). That matches the actual object layout with the dynamic allocation, so the fortified copy sees a destination whose size can grow with max_name_len.
Add a regression test that creates a 261-byte non-ASCII basename and runs status with core.precomposeunicode enabled.
Signed-off-by: Ihar Hrachyshka <ihar.hrachyshka@gmail.com> --- compat/precompose_utf8.c | 12 ++++++++---- compat/precompose_utf8.h | 9 +++++---- t/t3910-mac-os-precompose.sh | 15 +++++++++++++++ 3 files changed, 28 insertions(+), 8 deletions(-)
Show changes to 3 files +28 −8
compat/precompose_utf8.c, compat/precompose_utf8.h, t/t3910-mac-os-precompose.sh
diff --git a/compat/precompose_utf8.c b/compat/precompose_utf8.c index 1711794..8077f62 100644 --- a/compat/precompose_utf8.c +++ b/compat/precompose_utf8.c @@ -19,6 +19,11 @@ typedef char *iconv_ibp; static const char *repo_encoding = "UTF-8"; static const char *path_encoding = "UTF-8-MAC"; +static size_t dirent_prec_psx_size(size_t max_name_len) +{ + return st_add(offsetof(dirent_prec_psx, d_name), max_name_len); +} + static size_t has_non_ascii(const char *s, size_t maxlen, size_t *strlen_c) { const uint8_t *ptr = (const uint8_t *)s; @@ -114,8 +119,8 @@ const char *precompose_argv_prefix(int argc, const char **argv, const char *pref PREC_DIR *precompose_utf8_opendir(const char *dirname) { PREC_DIR *prec_dir = xmalloc(sizeof(PREC_DIR)); - prec_dir->dirent_nfc = xmalloc(sizeof(dirent_prec_psx)); - prec_dir->dirent_nfc->max_name_len = sizeof(prec_dir->dirent_nfc->d_name); + prec_dir->dirent_nfc = xmalloc(dirent_prec_psx_size(NAME_MAX + 1)); + prec_dir->dirent_nfc->max_name_len = NAME_MAX + 1; prec_dir->dirp = opendir(dirname); if (!prec_dir->dirp) { @@ -145,8 +150,7 @@ struct dirent_prec_psx *precompose_utf8_readdir(PREC_DIR *prec_dir) int ret_errno = errno; if (new_maxlen > prec_dir->dirent_nfc->max_name_len) { - size_t new_len = sizeof(dirent_prec_psx) + new_maxlen - - sizeof(prec_dir->dirent_nfc->d_name); + size_t new_len = dirent_prec_psx_size(new_maxlen); prec_dir->dirent_nfc = xrealloc(prec_dir->dirent_nfc, new_len); prec_dir->dirent_nfc->max_name_len = new_maxlen; diff --git a/compat/precompose_utf8.h b/compat/precompose_utf8.h index fea06cf..c7c3cc2 100644 --- a/compat/precompose_utf8.h +++ b/compat/precompose_utf8.h @@ -14,11 +14,12 @@ typedef struct dirent_prec_psx { /* * See http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/dirent.h.html - * NAME_MAX + 1 should be enough, but some systems have - * NAME_MAX=255 and strlen(d_name) may return 508 or 510 - * Solution: allocate more when needed, see precompose_utf8_readdir() + * Start with room for NAME_MAX + 1 bytes, but keep d_name as a + * flexible array. Some systems have NAME_MAX=255 while strlen(d_name) + * from readdir() may return 508 or 510 bytes. Grow the allocation as + * needed in precompose_utf8_readdir(). */ - char d_name[NAME_MAX+1]; + char d_name[FLEX_ARRAY]; } dirent_prec_psx; diff --git a/t/t3910-mac-os-precompose.sh b/t/t3910-mac-os-precompose.sh index 6d5918c..fda4a76 100755 --- a/t/t3910-mac-os-precompose.sh +++ b/t/t3910-mac-os-precompose.sh @@ -207,6 +207,21 @@ test_expect_success "Add long precomposed filename" ' git commit -m "Long filename" ' +test_expect_success "status with long non-ASCII filename" ' + test_when_finished "rm -rf long-utf8-status" && + git init long-utf8-status && + ( + cd long-utf8-status && + test "$(git config --bool core.precomposeunicode)" = true && + long_utf8_name=$( + perl -e "print q(a) x 249, qq(\342\200\224) x 3, q(.md)" + ) && + test "$(printf "%s" "$long_utf8_name" | wc -c | tr -d " ")" = 261 && + printf "content\n" >"$long_utf8_name" && + git status --porcelain=v1 >actual + ) +' + test_expect_failure 'handle existing decomposed filenames' ' echo content >"verbatim.$Adiarnfd" && git -c core.precomposeunicode=false add "verbatim.$Adiarnfd" && base-commit: e9019fcafe0040228b8631c30f97ae1adb61bcdc
-- 2.54.0