Skip to content

Commit 2a2ff60

Browse files
sgngitster
authored andcommitted
mailinfo.c: avoid strlen on strings that can contains NUL
We're passing buffer from strbuf to reencode_string, which will call strlen(3) on that buffer, and discard the length of newly created buffer. Then, we compute the length of the return buffer to attach to strbuf. During this process, we introduce a discrimination between mail originally written in utf-8 and other encoding. * if the email was written in utf-8, we leave it as is. If there is a NUL character in that line, we complains loudly: error: a NUL byte in commit log message not allowed. * if the email was written in other encoding, we truncate the data as the NUL character in that line, then we used the truncated line for the metadata. We can do better by reusing all the available information, and call the underlying lower level function that will be called indirectly by reencode_string. By doing this, we will also postpone the NUL character processing to the commit step, which will complains about the faulty metadata. Signed-off-by: Đoàn Trần Công Danh <[email protected]> Signed-off-by: Junio C Hamano <[email protected]>
1 parent 2ed282c commit 2a2ff60

File tree

2 files changed

+48
-2
lines changed

2 files changed

+48
-2
lines changed

mailinfo.c

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -447,19 +447,21 @@ static int convert_to_utf8(struct mailinfo *mi,
447447
struct strbuf *line, const char *charset)
448448
{
449449
char *out;
450+
size_t out_len;
450451

451452
if (!mi->metainfo_charset || !charset || !*charset)
452453
return 0;
453454

454455
if (same_encoding(mi->metainfo_charset, charset))
455456
return 0;
456-
out = reencode_string(line->buf, mi->metainfo_charset, charset);
457+
out = reencode_string_len(line->buf, line->len,
458+
mi->metainfo_charset, charset, &out_len);
457459
if (!out) {
458460
mi->input_error = -1;
459461
return error("cannot convert from %s to %s",
460462
charset, mi->metainfo_charset);
461463
}
462-
strbuf_attach(line, out, strlen(out), strlen(out));
464+
strbuf_attach(line, out, out_len, out_len);
463465
return 0;
464466
}
465467

t/t4254-am-corrupt.sh

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,37 @@
33
test_description='git am with corrupt input'
44
. ./test-lib.sh
55

6+
make_mbox_with_nul () {
7+
space=' '
8+
q_nul_in_subject=
9+
q_nul_in_body=
10+
while test $# -ne 0
11+
do
12+
case "$1" in
13+
subject) q_nul_in_subject='=00' ;;
14+
body) q_nul_in_body='=00' ;;
15+
esac &&
16+
shift
17+
done &&
18+
cat <<-EOF
19+
From ec7364544f690c560304f5a5de9428ea3b978b26 Mon Sep 17 00:00:00 2001
20+
From: A U Thor <[email protected]>
21+
Date: Sun, 19 Apr 2020 13:42:07 +0700
22+
Subject: [PATCH] =?ISO-8859-1?q?=C4=CB${q_nul_in_subject}=D1=CF=D6?=
23+
MIME-Version: 1.0
24+
Content-Type: text/plain; charset=ISO-8859-1
25+
Content-Transfer-Encoding: quoted-printable
26+
27+
abc${q_nul_in_body}def
28+
---
29+
diff --git a/afile b/afile
30+
new file mode 100644
31+
index 0000000000..e69de29bb2
32+
--$space
33+
2.26.1
34+
EOF
35+
}
36+
637
test_expect_success setup '
738
# Note the missing "+++" line:
839
cat >bad-patch.diff <<-\EOF &&
@@ -32,4 +63,17 @@ test_expect_success 'try to apply corrupted patch' '
3263
test_i18ncmp expected actual
3364
'
3465

66+
test_expect_success "NUL in commit message's body" '
67+
test_when_finished "git am --abort" &&
68+
make_mbox_with_nul body >body.patch &&
69+
test_must_fail git am body.patch 2>err &&
70+
grep "a NUL byte in commit log message not allowed" err
71+
'
72+
73+
test_expect_failure "NUL in commit message's header" "
74+
test_when_finished 'git am --abort' &&
75+
make_mbox_with_nul subject >subject.patch &&
76+
test_must_fail git am subject.patch
77+
"
78+
3579
test_done

0 commit comments

Comments
 (0)