]> git.99rst.org Git - git.git/commit
packed-backend: check whether the refname contains NUL characters
authorshejialuo <redacted>
Thu, 27 Feb 2025 16:07:00 +0000 (00:07 +0800)
committerJunio C Hamano <redacted>
Thu, 27 Feb 2025 22:03:08 +0000 (14:03 -0800)
commit5637d5542021294e81cf0d8344fe140368117296
tree5a7220372947d809cd175661b2cc47234bc0c700
parentc92e7e156e6b406e7555fb5df058d18758a0b3f0
packed-backend: check whether the refname contains NUL characters

"packed-backend.c::next_record" will use "check_refname_format" to check
the consistency of the refname. If it is not OK, the program will die.
However, it is reported in [1], we cannot catch some corruption. But we
already have the code path and we must miss out something.

We use the following code to get the refname:

    strbuf_add(&iter->refname_buf, p, eol - p);
    iter->base.refname = iter->refname_buf.buf

In the above code, `p` is the start pointer of the refname and `eol` is
the next newline pointer. We calculate the length of the refname by
subtracting the two pointers. Then we add the memory range between `p`
and `eol` to get the refname.

However, if there are some NUL characters in the memory range between `p`
and `eol`, we will see the refname as a valid ref name as long as the
memory range between `p` and first occurred NUL character is valid.

In order to catch above corruption, create a new function
"refname_contains_nul" by searching the first NUL character. If it is
not at the end of the string, there must be some NUL characters in the
refname.

Use this function in "next_record" function to die the program if
"refname_contains_nul" returns true.

[1] https://lore.kernel.org/git/6cfee0e4-3285-4f18-91ff-d097da9de737@rd10.de/

Reported-by: R. Diez <redacted>
Mentored-by: Patrick Steinhardt <redacted>
Mentored-by: Karthik Nayak <redacted>
Signed-off-by: shejialuo <redacted>
Signed-off-by: Junio C Hamano <redacted>
refs/packed-backend.c
git clone https://git.99rst.org/PROJECT