threads / patch / 8230

patch, 3 partsUse stringbuf to clean up some string handling code.

Subject: [PATCH 3/3] Use stringbuf to clean up some string handling code.

## tl;dr

4 messages between May 20, 2007 and May 20, 2007. Diffs are folded; open one to read it.

replies: 3people: 3as markdown or json

Timo Sirainen· May 20, 2007, 02:25 UTC · lore
---
 commit.c      |   30 +++++++++++++-----------------
 local-fetch.c |   34 ++++++++++++++++------------------
 2 files changed, 29 insertions(+), 35 deletions(-)
Show changes to 2 files +29 −35

commit.c, local-fetch.c

diff --git a/commit.c b/commit.c
index bee066f..58f1718 100644
--- a/commit.c
+++ b/commit.c
@@ -6,6 +6,7 @@
 #include "interpolate.h"
 #include "diff.h"
 #include "revision.h"
+#include "str.h"
 
 int save_commit_buffer = 1;
 
@@ -821,7 +822,7 @@ static long format_commit_message(const struct
commit *commit,
 		ILEFT_RIGHT,
 	};
 	struct commit_list *p;
-	char parents[1024];
+	stringbuf(parents, 1024);
 	int i;
 	enum { HEADER, SUBJECT, BODY } state;
 
@@ -853,22 +854,17 @@ static long format_commit_message(const struct
commit *commit,
 			 ? "<"
 			 : ">");
 
-	parents[1] = 0;
-	for (i = 0, p = commit->parents;
-			p && i < sizeof(parents) - 1;
-			p = p->next)
-		i += snprintf(parents + i, sizeof(parents) - i - 1, " %s",
-			sha1_to_hex(p->item->object.sha1));
-	interp_set_entry(table, IPARENTS, parents + 1);
-
-	parents[1] = 0;
-	for (i = 0, p = commit->parents;
-			p && i < sizeof(parents) - 1;
-			p = p->next)
-		i += snprintf(parents + i, sizeof(parents) - i - 1, " %s",
-			find_unique_abbrev(p->item->object.sha1,
-				DEFAULT_ABBREV));
-	interp_set_entry(table, IPARENTS_ABBREV, parents + 1);
+	str_c(parents)[1] = 0;
+	for (p = commit->parents; p; p = p->next)
+		str_printfa(parents, " %s", sha1_to_hex(p->item->object.sha1));
+	interp_set_entry(table, IPARENTS, str_c(parents) + 1);
+
+	str_c(parents)[1] = 0;
+	for (p = commit->parents; p; p = p->next)
+		str_printfa(parents, " %s",
+			    find_unique_abbrev(p->item->object.sha1,
+					       DEFAULT_ABBREV));
+	interp_set_entry(table, IPARENTS_ABBREV, str_c(parents) + 1);
 
 	for (i = 0, state = HEADER; msg[i] && state < BODY; i++) {
 		int eol;
diff --git a/local-fetch.c b/local-fetch.c
index 4b650ef..6d0599f 100644
--- a/local-fetch.c
+++ b/local-fetch.c
@@ -4,6 +4,7 @@
 #include "cache.h"
 #include "commit.h"
 #include "fetch.h"
+#include "str.h"
 
 static int use_link;
 static int use_symlink;
@@ -21,12 +22,11 @@ static struct packed_git *packs;
 static void setup_index(unsigned char *sha1)
 {
 	struct packed_git *new_pack;
-	char filename[PATH_MAX];
-	strcpy(filename, path);
-	strcat(filename, "/objects/pack/pack-");
-	strcat(filename, sha1_to_hex(sha1));
-	strcat(filename, ".idx");
-	new_pack = parse_pack_index_file(sha1, filename);
+	stringbuf(filename, PATH_MAX);
+
+	str_printfa(filename, "%s/objects/pack/pack-%s.idx",
+		    path, sha1_to_hex(sha1));
+	new_pack = parse_pack_index_file(sha1, str_c(filename));
 	new_pack->next = packs;
 	packs = new_pack;
 }
@@ -35,10 +35,11 @@ static int setup_indices(void)
 {
 	DIR *dir;
 	struct dirent *de;
-	char filename[PATH_MAX];
+	stringbuf(filename, PATH_MAX);
 	unsigned char sha1[20];
-	sprintf(filename, "%s/objects/pack/", path);
-	dir = opendir(filename);
+
+	str_printfa(filename, "%s/objects/pack/", path);
+	dir = opendir(str_c(filename));
 	if (!dir)
 		return -1;
 	while ((de = readdir(dir)) != NULL) {
@@ -137,20 +138,17 @@ static int fetch_pack(const unsigned char *sha1)
 static int fetch_file(const unsigned char *sha1)
 {
 	static int object_name_start = -1;
-	static char filename[PATH_MAX];
+	static stringbuf(filename, PATH_MAX);
 	char *hex = sha1_to_hex(sha1);
 	char *dest_filename = sha1_file_name(sha1);
 
  	if (object_name_start < 0) {
-		strcpy(filename, path); /* e.g. git.git */
-		strcat(filename, "/objects/");
-		object_name_start = strlen(filename);
+		str_printfa(filename, "%s/objects/", path); /* e.g. git.git */
+		object_name_start = str_len(filename);
 	}
-	filename[object_name_start+0] = hex[0];
-	filename[object_name_start+1] = hex[1];
-	filename[object_name_start+2] = '/';
-	strcpy(filename + object_name_start + 3, hex + 2);
-	return copy_file(filename, dest_filename, hex, 0);
+	str_truncate(filename, object_name_start);
+	str_printfa(filename, "%c%c/%s", hex[0], hex[1], hex + 2);
+	return copy_file(str_c(filename), dest_filename, hex, 0);
 }
 
 int fetch(unsigned char *sha1)
-- 
1.5.1.4
Alex Riesen· May 20, 2007, 09:56 UTC · re: Timo Sirainen · lore

Re: [PATCH 3/3] Use stringbuf to clean up some string handling code.

Timo Sirainen, Sun, May 20, 2007 04:25:42 +0200:
> ---
>  commit.c      |   30 +++++++++++++-----------------
>  local-fetch.c |   34 ++++++++++++++++------------------
>  2 files changed, 29 insertions(+), 35 deletions(-)
I find it hard to believe that it actually was a cleanup.

It is a nicer code, but... it is bigger, heavier on stack, and it does not actually fix anything.

In my experience, such changes are seldom worth the effort. It may be a nice code (and I actually like str.[hc]), but its use _must_ be justified. I.e. it must simplify a complex formatting routine, or fix a bug, which otherwise would be too hard or ugly to fix. It is definitely not the case in this patch.

Junio C Hamano· May 20, 2007, 10:04 UTC · re: Alex Riesen · lore

Re: [PATCH 3/3] Use stringbuf to clean up some string handling code.

Alex Riesen <raa.lkml@gmail.com> writes:
Show 16 quoted lines
> Timo Sirainen, Sun, May 20, 2007 04:25:42 +0200:
>> ---
>>  commit.c      |   30 +++++++++++++-----------------
>>  local-fetch.c |   34 ++++++++++++++++------------------
>>  2 files changed, 29 insertions(+), 35 deletions(-)
>
> I find it hard to believe that it actually was a cleanup.
>
> It is a nicer code, but... it is bigger, heavier on stack, and it does
> not actually fix anything.
>
> In my experience, such changes are seldom worth the effort. It may be
> a nice code (and I actually like str.[hc]), but its use _must_ be
> justified. I.e. it must simplify a complex formatting routine, or fix
> a bug, which otherwise would be too hard or ugly to fix. It is
> definitely not the case in this patch.

Thanks. I was kind of waiting for somebody to say that for me ;-)

Timo Sirainen· May 20, 2007, 11:19 UTC · re: Alex Riesen · lore

Re: [PATCH 3/3] Use stringbuf to clean up some string handling code.

On Sun, 2007-05-20 at 11:56 +0200, Alex Riesen wrote:
Show 16 quoted lines
> Timo Sirainen, Sun, May 20, 2007 04:25:42 +0200:
> > ---
> >  commit.c      |   30 +++++++++++++-----------------
> >  local-fetch.c |   34 ++++++++++++++++------------------
> >  2 files changed, 29 insertions(+), 35 deletions(-)
> 
> I find it hard to believe that it actually was a cleanup.
> 
> It is a nicer code, but... it is bigger, heavier on stack, and it does
> not actually fix anything.
> 
> In my experience, such changes are seldom worth the effort. It may be
> a nice code (and I actually like str.[hc]), but its use _must_ be
> justified. I.e. it must simplify a complex formatting routine, or fix
> a bug, which otherwise would be too hard or ugly to fix. It is
> definitely not the case in this patch.

In my own projects security is the highest priority and it justifies pretty much all changes. I've done several large changes that change thousands of lines of code just because it makes it a bit easier to verify the code's safety/correctness.

I realize that other projects may not want to use all of the tricks that I'm using in my C code (type safe dynamic arrays, type safe context pointer in callback functions, etc.), but I was hoping that at least the libc string handling functions would never be used in a large project anymore. Using them makes it extremely time consuming to verify the code's safety, and at least I try to avoid software if I can't do that.

← back to recent threads