Skip to content

Commit acb5334

Browse files
hanwengitster
authored andcommitted
reftable: implement refname validation
The packed/loose format has restrictions on refnames: a and a/b cannot coexist. This limitation does not apply to reftable per se, but must be maintained for interoperability. This code adds validation routines to abort transactions that are trying to add invalid names. Signed-off-by: Han-Wen Nienhuys <[email protected]> Signed-off-by: Junio C Hamano <[email protected]>
1 parent 1ae2b8c commit acb5334

File tree

5 files changed

+342
-0
lines changed

5 files changed

+342
-0
lines changed

Makefile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2478,6 +2478,7 @@ REFTABLE_TEST_OBJS += reftable/merged_test.o
24782478
REFTABLE_TEST_OBJS += reftable/pq_test.o
24792479
REFTABLE_TEST_OBJS += reftable/record_test.o
24802480
REFTABLE_TEST_OBJS += reftable/readwrite_test.o
2481+
REFTABLE_TEST_OBJS += reftable/refname_test.o
24812482
REFTABLE_TEST_OBJS += reftable/test_framework.o
24822483
REFTABLE_TEST_OBJS += reftable/tree_test.o
24832484

reftable/refname.c

Lines changed: 209 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,209 @@
1+
/*
2+
Copyright 2020 Google LLC
3+
4+
Use of this source code is governed by a BSD-style
5+
license that can be found in the LICENSE file or at
6+
https://developers.google.com/open-source/licenses/bsd
7+
*/
8+
9+
#include "system.h"
10+
#include "reftable-error.h"
11+
#include "basics.h"
12+
#include "refname.h"
13+
#include "reftable-iterator.h"
14+
15+
struct find_arg {
16+
char **names;
17+
const char *want;
18+
};
19+
20+
static int find_name(size_t k, void *arg)
21+
{
22+
struct find_arg *f_arg = arg;
23+
return strcmp(f_arg->names[k], f_arg->want) >= 0;
24+
}
25+
26+
static int modification_has_ref(struct modification *mod, const char *name)
27+
{
28+
struct reftable_ref_record ref = { NULL };
29+
int err = 0;
30+
31+
if (mod->add_len > 0) {
32+
struct find_arg arg = {
33+
.names = mod->add,
34+
.want = name,
35+
};
36+
int idx = binsearch(mod->add_len, find_name, &arg);
37+
if (idx < mod->add_len && !strcmp(mod->add[idx], name)) {
38+
return 0;
39+
}
40+
}
41+
42+
if (mod->del_len > 0) {
43+
struct find_arg arg = {
44+
.names = mod->del,
45+
.want = name,
46+
};
47+
int idx = binsearch(mod->del_len, find_name, &arg);
48+
if (idx < mod->del_len && !strcmp(mod->del[idx], name)) {
49+
return 1;
50+
}
51+
}
52+
53+
err = reftable_table_read_ref(&mod->tab, name, &ref);
54+
reftable_ref_record_release(&ref);
55+
return err;
56+
}
57+
58+
static void modification_release(struct modification *mod)
59+
{
60+
/* don't delete the strings themselves; they're owned by ref records.
61+
*/
62+
FREE_AND_NULL(mod->add);
63+
FREE_AND_NULL(mod->del);
64+
mod->add_len = 0;
65+
mod->del_len = 0;
66+
}
67+
68+
static int modification_has_ref_with_prefix(struct modification *mod,
69+
const char *prefix)
70+
{
71+
struct reftable_iterator it = { NULL };
72+
struct reftable_ref_record ref = { NULL };
73+
int err = 0;
74+
75+
if (mod->add_len > 0) {
76+
struct find_arg arg = {
77+
.names = mod->add,
78+
.want = prefix,
79+
};
80+
int idx = binsearch(mod->add_len, find_name, &arg);
81+
if (idx < mod->add_len &&
82+
!strncmp(prefix, mod->add[idx], strlen(prefix)))
83+
goto done;
84+
}
85+
err = reftable_table_seek_ref(&mod->tab, &it, prefix);
86+
if (err)
87+
goto done;
88+
89+
while (1) {
90+
err = reftable_iterator_next_ref(&it, &ref);
91+
if (err)
92+
goto done;
93+
94+
if (mod->del_len > 0) {
95+
struct find_arg arg = {
96+
.names = mod->del,
97+
.want = ref.refname,
98+
};
99+
int idx = binsearch(mod->del_len, find_name, &arg);
100+
if (idx < mod->del_len &&
101+
!strcmp(ref.refname, mod->del[idx])) {
102+
continue;
103+
}
104+
}
105+
106+
if (strncmp(ref.refname, prefix, strlen(prefix))) {
107+
err = 1;
108+
goto done;
109+
}
110+
err = 0;
111+
goto done;
112+
}
113+
114+
done:
115+
reftable_ref_record_release(&ref);
116+
reftable_iterator_destroy(&it);
117+
return err;
118+
}
119+
120+
static int validate_refname(const char *name)
121+
{
122+
while (1) {
123+
char *next = strchr(name, '/');
124+
if (!*name) {
125+
return REFTABLE_REFNAME_ERROR;
126+
}
127+
if (!next) {
128+
return 0;
129+
}
130+
if (next - name == 0 || (next - name == 1 && *name == '.') ||
131+
(next - name == 2 && name[0] == '.' && name[1] == '.'))
132+
return REFTABLE_REFNAME_ERROR;
133+
name = next + 1;
134+
}
135+
return 0;
136+
}
137+
138+
int validate_ref_record_addition(struct reftable_table tab,
139+
struct reftable_ref_record *recs, size_t sz)
140+
{
141+
struct modification mod = {
142+
.tab = tab,
143+
.add = reftable_calloc(sizeof(char *) * sz),
144+
.del = reftable_calloc(sizeof(char *) * sz),
145+
};
146+
int i = 0;
147+
int err = 0;
148+
for (; i < sz; i++) {
149+
if (reftable_ref_record_is_deletion(&recs[i])) {
150+
mod.del[mod.del_len++] = recs[i].refname;
151+
} else {
152+
mod.add[mod.add_len++] = recs[i].refname;
153+
}
154+
}
155+
156+
err = modification_validate(&mod);
157+
modification_release(&mod);
158+
return err;
159+
}
160+
161+
static void strbuf_trim_component(struct strbuf *sl)
162+
{
163+
while (sl->len > 0) {
164+
int is_slash = (sl->buf[sl->len - 1] == '/');
165+
strbuf_setlen(sl, sl->len - 1);
166+
if (is_slash)
167+
break;
168+
}
169+
}
170+
171+
int modification_validate(struct modification *mod)
172+
{
173+
struct strbuf slashed = STRBUF_INIT;
174+
int err = 0;
175+
int i = 0;
176+
for (; i < mod->add_len; i++) {
177+
err = validate_refname(mod->add[i]);
178+
if (err)
179+
goto done;
180+
strbuf_reset(&slashed);
181+
strbuf_addstr(&slashed, mod->add[i]);
182+
strbuf_addstr(&slashed, "/");
183+
184+
err = modification_has_ref_with_prefix(mod, slashed.buf);
185+
if (err == 0) {
186+
err = REFTABLE_NAME_CONFLICT;
187+
goto done;
188+
}
189+
if (err < 0)
190+
goto done;
191+
192+
strbuf_reset(&slashed);
193+
strbuf_addstr(&slashed, mod->add[i]);
194+
while (slashed.len) {
195+
strbuf_trim_component(&slashed);
196+
err = modification_has_ref(mod, slashed.buf);
197+
if (err == 0) {
198+
err = REFTABLE_NAME_CONFLICT;
199+
goto done;
200+
}
201+
if (err < 0)
202+
goto done;
203+
}
204+
}
205+
err = 0;
206+
done:
207+
strbuf_release(&slashed);
208+
return err;
209+
}

reftable/refname.h

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
/*
2+
Copyright 2020 Google LLC
3+
4+
Use of this source code is governed by a BSD-style
5+
license that can be found in the LICENSE file or at
6+
https://developers.google.com/open-source/licenses/bsd
7+
*/
8+
#ifndef REFNAME_H
9+
#define REFNAME_H
10+
11+
#include "reftable-record.h"
12+
#include "reftable-generic.h"
13+
14+
struct modification {
15+
struct reftable_table tab;
16+
17+
char **add;
18+
size_t add_len;
19+
20+
char **del;
21+
size_t del_len;
22+
};
23+
24+
int validate_ref_record_addition(struct reftable_table tab,
25+
struct reftable_ref_record *recs, size_t sz);
26+
27+
int modification_validate(struct modification *mod);
28+
29+
#endif

reftable/refname_test.c

Lines changed: 102 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,102 @@
1+
/*
2+
Copyright 2020 Google LLC
3+
4+
Use of this source code is governed by a BSD-style
5+
license that can be found in the LICENSE file or at
6+
https://developers.google.com/open-source/licenses/bsd
7+
*/
8+
9+
#include "basics.h"
10+
#include "block.h"
11+
#include "blocksource.h"
12+
#include "constants.h"
13+
#include "reader.h"
14+
#include "record.h"
15+
#include "refname.h"
16+
#include "reftable-error.h"
17+
#include "reftable-writer.h"
18+
#include "system.h"
19+
20+
#include "test_framework.h"
21+
#include "reftable-tests.h"
22+
23+
struct testcase {
24+
char *add;
25+
char *del;
26+
int error_code;
27+
};
28+
29+
static void test_conflict(void)
30+
{
31+
struct reftable_write_options opts = { 0 };
32+
struct strbuf buf = STRBUF_INIT;
33+
struct reftable_writer *w =
34+
reftable_new_writer(&strbuf_add_void, &buf, &opts);
35+
struct reftable_ref_record rec = {
36+
.refname = "a/b",
37+
.value_type = REFTABLE_REF_SYMREF,
38+
.value.symref = "destination", /* make sure it's not a symref.
39+
*/
40+
.update_index = 1,
41+
};
42+
int err;
43+
int i;
44+
struct reftable_block_source source = { NULL };
45+
struct reftable_reader *rd = NULL;
46+
struct reftable_table tab = { NULL };
47+
struct testcase cases[] = {
48+
{ "a/b/c", NULL, REFTABLE_NAME_CONFLICT },
49+
{ "b", NULL, 0 },
50+
{ "a", NULL, REFTABLE_NAME_CONFLICT },
51+
{ "a", "a/b", 0 },
52+
53+
{ "p/", NULL, REFTABLE_REFNAME_ERROR },
54+
{ "p//q", NULL, REFTABLE_REFNAME_ERROR },
55+
{ "p/./q", NULL, REFTABLE_REFNAME_ERROR },
56+
{ "p/../q", NULL, REFTABLE_REFNAME_ERROR },
57+
58+
{ "a/b/c", "a/b", 0 },
59+
{ NULL, "a//b", 0 },
60+
};
61+
reftable_writer_set_limits(w, 1, 1);
62+
63+
err = reftable_writer_add_ref(w, &rec);
64+
EXPECT_ERR(err);
65+
66+
err = reftable_writer_close(w);
67+
EXPECT_ERR(err);
68+
reftable_writer_free(w);
69+
70+
block_source_from_strbuf(&source, &buf);
71+
err = reftable_new_reader(&rd, &source, "filename");
72+
EXPECT_ERR(err);
73+
74+
reftable_table_from_reader(&tab, rd);
75+
76+
for (i = 0; i < ARRAY_SIZE(cases); i++) {
77+
struct modification mod = {
78+
.tab = tab,
79+
};
80+
81+
if (cases[i].add) {
82+
mod.add = &cases[i].add;
83+
mod.add_len = 1;
84+
}
85+
if (cases[i].del) {
86+
mod.del = &cases[i].del;
87+
mod.del_len = 1;
88+
}
89+
90+
err = modification_validate(&mod);
91+
EXPECT(err == cases[i].error_code);
92+
}
93+
94+
reftable_reader_free(rd);
95+
strbuf_release(&buf);
96+
}
97+
98+
int refname_test_main(int argc, const char *argv[])
99+
{
100+
RUN_TEST(test_conflict);
101+
return 0;
102+
}

t/helper/test-reftable.c

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ int cmd__reftable(int argc, const char **argv)
88
merged_test_main(argc, argv);
99
pq_test_main(argc, argv);
1010
record_test_main(argc, argv);
11+
refname_test_main(argc, argv);
1112
readwrite_test_main(argc, argv);
1213
tree_test_main(argc, argv);
1314
return 0;

0 commit comments

Comments
 (0)