Git with broken hash generation to generate collisions between object IDs. Don't use this! https://undefinedbehavior.de/posts/commit-vandalism/
Go to file
Jeff King 8e1c5fcf28 ref-filter: fix parsing of signatures with CRLF and no body
This commit fixes a bug when parsing tags that have CRLF line endings, a
signature, and no body, like this (the "^M" are marking the CRs):

  this is the subject^M
  -----BEGIN PGP SIGNATURE-----^M
  ^M
  ...some stuff...^M
  -----END PGP SIGNATURE-----^M

When trying to find the start of the body, we look for a blank line
separating the subject and body. In this case, there isn't one. But we
search for it using strstr(), which will find the blank line in the
signature.

In the non-CRLF code path, we check whether the line we found is past
the start of the signature, and if so, put the body pointer at the start
of the signature (effectively making the body empty). But the CRLF code
path doesn't catch the same case, and we end up with the body pointer in
the middle of the signature field. This has two visible problems:

  - printing %(contents:subject) will show part of the signature, too,
    since the subject length is computed as (body - subject)

  - the length of the body is (sig - body), which makes it negative.
    Asking for %(contents:body) causes us to cast this to a very large
    size_t when we feed it to xmemdupz(), which then complains about
    trying to allocate too much memory.

These are essentially the same bugs fixed in the previous commit, except
that they happen when there is a CRLF blank line in the signature,
rather than no blank line at all. Both are caused by the refactoring in
9f75ce3d8f (ref-filter: handle CRLF at end-of-line more gracefully,
2020-10-29).

We can fix this by doing the same "sigstart" check that we do in the
non-CRLF case. And rather than repeat ourselves, we can just use
short-circuiting OR to collapse both cases into a single conditional.
I.e., rather than:

  if (strstr("\n\n"))
    ...found blank, check if it's in signature...
  else if (strstr("\r\n\r\n"))
    ...found blank, check if it's in signature...
  else
    ...no blank line found...

we can collapse this to:

  if (strstr("\n\n")) ||
      strstr("\r\n\r\n")))
    ...found blank, check if it's in signature...
  else
    ...no blank line found...

The tests show the problem and the fix. Though it wasn't broken, I
included contents:signature here to make sure it still behaves as
expected, but note the shell hackery needed to make it work. A
less-clever option would be to skip using test_atom and just "append_cr
>expected" ourselves.

Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Taylor Blau <me@ttaylorr.com>
2022-11-02 21:36:04 -04:00
.github ci: add address and undefined sanitizer tasks 2022-10-20 09:20:59 -07:00
block-sha1
builtin Merge branch 'en/merge-tree-sequence' 2022-10-30 21:04:44 -04:00
ci Merge branch 'jc/more-sanitizer-at-ci' 2022-10-25 17:11:44 -07:00
compat Merge branch 'jk/unused-anno-more' 2022-10-27 14:51:52 -07:00
contrib Merge branch 'pb/subtree-split-and-merge-after-squashing-tag-fix' 2022-10-30 21:04:43 -04:00
Documentation The ninth batch 2022-10-30 21:14:28 -04:00
ewah
git-gui
gitk-git
gitweb
mergetools mergetools: vimdiff: simplify tabfirst 2022-08-10 12:39:39 -07:00
negotiator negotiator/skipping: avoid stack overflow 2022-10-25 17:14:40 -07:00
oss-fuzz Merge branch 'ac/fuzzers' 2022-10-07 17:19:59 -07:00
perl Git.pm: trust rev-parse to find bare repositories 2022-10-22 16:39:48 -07:00
po l10n: zh_TW.po: Git 2.38.0, round 3 2022-10-01 19:10:41 +08:00
refs refs: unify parse_worktree_ref() and ref_type() 2022-09-19 11:11:11 -07:00
reftable reftable: use a pointer for pq_entry param 2022-09-15 11:32:37 -07:00
sha1collisiondetection@855827c583
sha1dc
sha256
t ref-filter: fix parsing of signatures with CRLF and no body 2022-11-02 21:36:04 -04:00
templates
trace2 trace2: add global counter mechanism 2022-10-24 12:45:26 -07:00
xdiff
.cirrus.yml
.clang-format
.editorconfig
.gitattributes
.gitignore Merge branch 'js/cmake-updates' 2022-10-27 14:51:53 -07:00
.gitmodules
.mailmap
.tsan-suppressions
abspath.c
aclocal.m4
add-interactive.c
add-interactive.h
add-patch.c add -p: avoid ambiguous signed/unsigned comparison 2022-10-19 11:55:28 -07:00
advice.c
advice.h
alias.c alias.c: reject too-long cmdline strings in split_cmdline() 2022-10-01 00:23:38 -04:00
alias.h
alloc.c
alloc.h
apply.c Merge branch 'tb/cap-patch-at-1gb' 2022-10-30 21:04:43 -04:00
apply.h
archive-tar.c
archive-zip.c
archive.c Merge branch 'rs/archive-dedup-printf' into maint-2.38 2022-10-27 15:24:14 -07:00
archive.h
attr.c attr: drop DEBUG_ATTR code 2022-10-06 09:59:17 -07:00
attr.h
banned.h
base85.c
bisect.c
bisect.h
blame.c Merge branch 'rs/mergesort' 2022-08-03 13:36:09 -07:00
blame.h
blob.c
blob.h
bloom.c
bloom.h
branch.c
branch.h
builtin.h
bulk-checkin.c
bulk-checkin.h
bundle-uri.c bundle-uri: suppress stderr from remote-https 2022-10-12 09:13:25 -07:00
bundle-uri.h bundle-uri: fetch a list of bundles 2022-10-12 09:13:25 -07:00
bundle.c bundle-uri: quiet failed unbundlings 2022-10-12 09:13:25 -07:00
bundle.h Merge branch 'ds/bundle-uri-3' 2022-10-30 21:04:44 -04:00
cache-tree.c
cache-tree.h
cache.h
cbtree.c
cbtree.h
chdir-notify.c
chdir-notify.h
check-builtins.sh
checkout.c
checkout.h
chunk-format.c
chunk-format.h
CODE_OF_CONDUCT.md
color.c
color.h
column.c
column.h
combine-diff.c
command-list.txt version: fix builtin linking & documentation 2022-09-19 17:28:25 -07:00
commit-graph.c Merge branch 'ml/commit-graph-expire-dir-leak-fix' 2022-09-21 14:23:14 -07:00
commit-graph.h
commit-reach.c
commit-reach.h
commit-slab-decl.h
commit-slab-impl.h
commit-slab.h
commit.c Merge branch 'pw/rebase-keep-base-fixes' 2022-10-30 21:04:42 -04:00
commit.h rebase: be stricter when reading state files containing oids 2022-10-17 11:53:00 -07:00
common-main.c grep: fix multibyte regex handling under macOS 2022-08-26 11:45:52 -07:00
config.c Merge branch 'ds/bundle-uri-3' 2022-10-30 21:04:44 -04:00
config.h bundle-uri: create base key-value pair parsing 2022-10-12 09:13:24 -07:00
config.mak.dev config.mak.dev: disable suggest braces error on old clang versions 2022-10-10 11:15:31 -07:00
config.mak.in
config.mak.uname
configure.ac
connect.c
connect.h
connected.c
connected.h
convert.c convert: mark unused parameter in null stream filter 2022-10-17 21:24:04 -07:00
convert.h
copy.c
COPYING
credential.c
credential.h
csum-file.c
csum-file.h
ctype.c
daemon.c
date.c date: mark unused parameters in handler functions 2022-10-17 21:24:04 -07:00
date.h
decorate.c
decorate.h
delta-islands.c
delta-islands.h
delta.h
detect-compiler
diagnose.c diagnose.c: refactor to safely use 'd_type' 2022-09-19 10:25:01 -07:00
diagnose.h
diff-delta.c
diff-lib.c
diff-merges.c diff-merges: cleanup set_diff_merges() 2022-09-16 09:21:43 -07:00
diff-merges.h
diff-no-index.c diff-no-index: simplify argv index calculation 2022-09-07 12:36:43 -07:00
diff.c Merge branch 'jz/patch-id' 2022-10-30 21:04:41 -04:00
diff.h patch-id: use stable patch-id for rebases 2022-10-24 15:44:19 -07:00
diffcore-break.c
diffcore-delta.c diffcore-delta.c: LLP64 compatibility, upcast unity for left shift 2021-12-01 14:48:10 -08:00
diffcore-order.c
diffcore-pickaxe.c diffcore-pickaxe: mark unused parameters in pickaxe functions 2022-10-17 21:24:04 -07:00
diffcore-rename.c
diffcore-rotate.c
diffcore.h
dir-iterator.c
dir-iterator.h
dir.c Merge branch 'rs/use-fspathncmp' into maint-2.38 2022-10-27 15:24:13 -07:00
dir.h
editor.c
entry.c
entry.h
environment.c Merge branch 'ab/unused-annotation' 2022-09-14 12:56:39 -07:00
environment.h
exec-cmd.c mark unused parameters in trivial compat functions 2022-10-17 21:24:03 -07:00
exec-cmd.h
fetch-negotiator.c
fetch-negotiator.h
fetch-pack.c Merge branch 'ab/unused-annotation' 2022-09-14 12:56:39 -07:00
fetch-pack.h
fmt-merge-msg.c revisions API users: add straightforward release_revisions() 2022-04-13 23:56:08 -07:00
fmt-merge-msg.h
fsck.c
fsck.h fsck: document msg-id 2022-10-25 15:44:18 -07:00
fsmonitor--daemon.h fsmonitor: deal with synthetic firmlinks on macOS 2022-10-05 11:05:23 -07:00
fsmonitor-ipc.c fsmonitor: relocate socket file if .git directory is remote 2022-10-05 11:05:22 -07:00
fsmonitor-ipc.h fsmonitor: relocate socket file if .git directory is remote 2022-10-05 11:05:22 -07:00
fsmonitor-path-utils.h fsmonitor: deal with synthetic firmlinks on macOS 2022-10-05 11:05:23 -07:00
fsmonitor-settings.c fsmonitor: check for compatability before communicating with fsmonitor 2022-10-05 11:05:23 -07:00
fsmonitor-settings.h fsmonitor: check for compatability before communicating with fsmonitor 2022-10-05 11:05:23 -07:00
fsmonitor.c fsmonitor: fix leak of warning message 2022-10-10 22:16:56 -07:00
fsmonitor.h
generate-cmdlist.sh
generate-configlist.sh
generate-hooklist.sh
gettext.c
gettext.h
git-add--interactive.perl
git-archimport.perl
git-bisect.sh
git-compat-util.h Merge branch 'ab/unused-annotation' into maint-2.38 2022-10-27 15:24:12 -07:00
git-curl-compat.h
git-cvsexportcommit.perl
git-cvsimport.perl
git-cvsserver.perl
git-difftool--helper.sh
git-filter-branch.sh
git-instaweb.sh
git-merge-octopus.sh
git-merge-one-file.sh
git-merge-resolve.sh
git-mergetool--lib.sh
git-mergetool.sh
git-p4.py
git-quiltimport.sh
git-request-pull.sh
git-send-email.perl
git-sh-i18n.sh
git-sh-setup.sh
git-submodule.sh
git-svn.perl
GIT-VERSION-GEN Start 2.39 cycle 2022-10-07 17:19:59 -07:00
git-web--browse.sh
git.c Merge branch 'ds/cmd-main-reorder' 2022-10-21 11:37:29 -07:00
git.rc
gpg-interface.c Merge branch 'pw/ssh-sign-report-errors' into maint-2.38 2022-10-25 17:11:35 -07:00
gpg-interface.h
graph.c
graph.h
grep.c Merge branch 'ab/grep-simplify-extended-expression' 2022-10-21 11:37:28 -07:00
grep.h Merge branch 'ab/grep-simplify-extended-expression' 2022-10-21 11:37:28 -07:00
hash-lookup.c
hash-lookup.h
hash.h
hashmap.c
hashmap.h
help.c Merge branch 'ab/doc-synopsis-and-cmd-usage' 2022-10-28 11:26:54 -07:00
help.h
hex.c
hook.c run-command API: have run_process_parallel() take an "opts" struct 2022-10-12 14:12:41 -07:00
hook.h
http-backend.c
http-fetch.c
http-push.c
http-walker.c
http.c
http.h
ident.c
imap-send.c
INSTALL
iterator.h
json-writer.c
json-writer.h
khash.h
kwset.c
kwset.h kset.h, tar.h: add missing header guard to prevent multiple inclusion 2019-11-07 20:12:04 +09:00
levenshtein.c
levenshtein.h
LGPL-2.1
line-log.c
line-log.h
line-range.c
line-range.h
linear-assignment.c
linear-assignment.h
list-objects-filter-options.c list-objects-filter: initialize sub-filter structs 2022-09-22 12:43:04 -07:00
list-objects-filter-options.h list-objects-filter: convert filter_spec to a strbuf 2022-09-12 08:38:59 -07:00
list-objects-filter.c
list-objects-filter.h
list-objects.c
list-objects.h
list.h
ll-merge.c ll-merge: mark unused parameters in callbacks 2022-10-17 21:24:04 -07:00
ll-merge.h
lockfile.c
lockfile.h
log-tree.c Merge branch 'ab/unused-annotation' 2022-09-14 12:56:39 -07:00
log-tree.h
ls-refs.c
ls-refs.h
mailinfo.c mailinfo -b: fix an out of bounds access 2022-10-03 09:05:07 -07:00
mailinfo.h am: learn to process quoted lines that ends with CRLF 2021-05-10 15:06:22 +09:00
mailmap.c
mailmap.h
Makefile Merge branch 'ds/bundle-uri-3' 2022-10-30 21:04:44 -04:00
match-trees.c
mem-pool.c
mem-pool.h
merge-blobs.c
merge-blobs.h
merge-ort-wrappers.c
merge-ort-wrappers.h
merge-ort.c Merge branch 'en/ort-dir-rename-and-symlink-fix' 2022-10-30 21:04:43 -04:00
merge-ort.h
merge-recursive.c
merge-recursive.h
merge.c unpack-trees: introduce preserve_ignored to unpack_trees_options 2021-09-27 13:38:37 -07:00
mergesort.h
midx.c Merge branch 'tb/midx-bitmap-selection-fix' 2022-10-27 14:51:52 -07:00
midx.h
name-hash.c
notes-cache.c
notes-cache.h
notes-merge.c
notes-merge.h
notes-utils.c
notes-utils.h
notes.c Merge branch 'ab/unused-annotation' 2022-09-14 12:56:39 -07:00
notes.h
object-file.c Merge branch 'jk/unused-anno-more' 2022-10-27 14:51:52 -07:00
object-name.c
object-store.h
object.c Merge branch 'jk/fsck-on-diet' into maint-2.38 2022-10-25 17:11:33 -07:00
object.h parse_object(): allow skipping hash check 2022-09-07 12:18:57 -07:00
oid-array.c
oid-array.h
oidmap.c
oidmap.h
oidset.c
oidset.h
oidtree.c
oidtree.h
pack-bitmap-write.c pack-bitmap-write.c: instrument number of reused bitmaps 2022-10-13 13:35:08 -07:00
pack-bitmap.c Merge branch 'ds/bitmap-lookup-remove-tracing' 2022-09-26 21:46:51 -07:00
pack-bitmap.h
pack-check.c
pack-mtimes.c
pack-mtimes.h
pack-objects.c
pack-objects.h
pack-revindex.c
pack-revindex.h
pack-write.c
pack.h
packfile.c Merge branch 'ab/unused-annotation' 2022-09-14 12:56:39 -07:00
packfile.h
pager.c
parallel-checkout.c
parallel-checkout.h
parse-options-cb.c
parse-options.c
parse-options.h
patch-delta.c
patch-ids.c Merge branch 'jz/patch-id' 2022-10-30 21:04:41 -04:00
patch-ids.h patch-id: use stable patch-id for rebases 2022-10-24 15:44:19 -07:00
path.c
path.h
pathspec.c
pathspec.h
pkt-line.c
pkt-line.h
preload-index.c
pretty.c Merge branch 'ab/unused-annotation' 2022-09-14 12:56:39 -07:00
pretty.h
prio-queue.c
prio-queue.h
progress.c
progress.h
promisor-remote.c promisor-remote: die upon failing fetch 2022-10-05 11:06:53 -07:00
promisor-remote.h promisor-remote: remove a return value 2022-10-05 11:06:52 -07:00
prompt.c
prompt.h
protocol-caps.c
protocol-caps.h
protocol.c
protocol.h
prune-packed.c
prune-packed.h
quote.c
quote.h
range-diff.c Merge branch 'ab/unused-annotation' 2022-09-14 12:56:39 -07:00
range-diff.h
reachable.c
reachable.h
read-cache.c read-cache: avoid misaligned reads in index v4 2022-09-28 10:32:18 -07:00
README.md
rebase-interactive.c
rebase-interactive.h
rebase.c
rebase.h
ref-filter.c ref-filter: fix parsing of signatures with CRLF and no body 2022-11-02 21:36:04 -04:00
ref-filter.h
reflog-walk.c string-list: mark unused callback parameters 2022-10-17 21:24:04 -07:00
reflog-walk.h
reflog.c refs: unify parse_worktree_ref() and ref_type() 2022-09-19 11:11:11 -07:00
reflog.h
refs.c refs: unify parse_worktree_ref() and ref_type() 2022-09-19 11:11:11 -07:00
refs.h refs: unify parse_worktree_ref() and ref_type() 2022-09-19 11:11:11 -07:00
refspec.c
refspec.h
RelNotes Downmerge a handful of topics for 2.38.2 2022-10-25 17:11:39 -07:00
remote-curl.c
remote.c
remote.h
replace-object.c
replace-object.h
repo-settings.c Merge branch 'jk/plug-list-object-filter-leaks' 2022-09-14 12:56:40 -07:00
repository.c
repository.h Merge branch 'ab/submodule-helper-prep' 2022-09-13 11:38:23 -07:00
rerere.c
rerere.h
reset.c
reset.h
resolve-undo.c
resolve-undo.h
revision.c Merge branch 'rs/diff-caret-bang-with-parents' 2022-10-25 17:11:43 -07:00
revision.h Merge branch 'jc/format-patch-force-in-body-from' 2022-09-09 12:02:25 -07:00
run-command.c run-command.c: remove "max_processes", add "const" to signal() handler 2022-10-12 14:12:42 -07:00
run-command.h run-command API: move *_tr2() users to "run_processes_parallel()" 2022-10-12 14:12:41 -07:00
scalar.c scalar: make 'unregister' idempotent 2022-09-27 09:32:26 -07:00
SECURITY.md
send-pack.c
send-pack.h
sequencer.c Merge branch 'pw/rebase-reflog-fixes' 2022-10-30 21:04:43 -04:00
sequencer.h
serve.c
serve.h
server-info.c
setup.c
sh-i18n--envsubst.c
sha1dc_git.c
sha1dc_git.h
shallow.c
shallow.h
shared.mak
shell.c Sync with 2.32.4 2022-10-06 17:42:02 -04:00
shortlog.h shortlog: extract shortlog_finish_setup() 2022-10-24 14:48:05 -07:00
sideband.c
sideband.h
sigchain.c
sigchain.h
simple-ipc.h
sparse-index.c
sparse-index.h
split-index.c
split-index.h
stable-qsort.c
strbuf.c
strbuf.h
streaming.c
streaming.h
string-list.c string-list: mark unused callback parameters 2022-10-17 21:24:04 -07:00
string-list.h string-list: document iterator behavior on NULL input 2022-09-27 09:32:26 -07:00
strmap.c
strmap.h
strvec.c
strvec.h
sub-process.c
sub-process.h
submodule-config.c run-command API: don't fall back on online_cpus() 2022-10-12 14:12:41 -07:00
submodule-config.h
submodule.c Merge branch 'rs/absorb-git-dir-simplify' 2022-10-30 21:04:42 -04:00
submodule.h
symlinks.c
tag.c
tag.h
tar.h
tempfile.c
tempfile.h
thread-utils.c
thread-utils.h
tmp-objdir.c tmp-objdir: skip clean up when handling a signal 2022-09-30 21:26:58 -07:00
tmp-objdir.h
trace2.c trace2: add global counter mechanism 2022-10-24 12:45:26 -07:00
trace2.h trace2: add global counter mechanism 2022-10-24 12:45:26 -07:00
trace.c
trace.h
trailer.c
trailer.h
transport-helper.c list-objects-filter: add and use initializers 2022-09-12 08:38:59 -07:00
transport-internal.h
transport.c Merge branch 'ds/bundle-uri-3' 2022-10-30 21:04:44 -04:00
transport.h
tree-diff.c
tree-walk.c
tree-walk.h
tree.c tree.h API: simplify read_tree_recursive() signature 2021-03-20 16:09:26 -07:00
tree.h
unicode-width.h unicode: update the width tables to Unicode 14 2021-09-17 17:26:21 -07:00
unimplemented.sh
unix-socket.c
unix-socket.h
unix-stream-server.c
unix-stream-server.h
unpack-trees.c Merge branch 'vd/sparse-reset-checkout-fixes' 2022-09-09 12:02:26 -07:00
unpack-trees.h
upload-pack.c Merge branch 'jk/list-objects-filter-cleanup' 2022-09-19 14:35:24 -07:00
upload-pack.h
url.c
url.h
urlmatch.c
urlmatch.h
usage.c
userdiff.c
userdiff.h
utf8.c
utf8.h
varint.c
varint.h
version.c version --build-options: report commit, too, if possible 2017-12-14 22:53:04 -08:00
version.h
versioncmp.c config: don't include config.h by default 2017-06-15 12:56:22 -07:00
walker.c
walker.h
wildmatch.c
wildmatch.h
worktree.c refs: unify parse_worktree_ref() and ref_type() 2022-09-19 11:11:11 -07:00
worktree.h refs: unify parse_worktree_ref() and ref_type() 2022-09-19 11:11:11 -07:00
wrap-for-bin.sh
wrapper.c
write-or-die.c environ: GIT_FLUSH should be made a usual Boolean 2022-09-15 11:34:51 -07:00
ws.c
wt-status.c
wt-status.h
xdiff-interface.c
xdiff-interface.h
zlib.c

Build status

Git - fast, scalable, distributed revision control system

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals.

Git is an Open Source project covered by the GNU General Public License version 2 (some parts of it are under different licenses, compatible with the GPLv2). It was originally written by Linus Torvalds with help of a group of hackers around the net.

Please read the file INSTALL for installation instructions.

Many Git online resources are accessible from https://git-scm.com/ including full documentation and Git related tools.

See Documentation/gittutorial.txt to get started, then see Documentation/giteveryday.txt for a useful minimum set of commands, and Documentation/git-<commandname>.txt for documentation of each command. If git has been correctly installed, then the tutorial can also be read with man gittutorial or git help tutorial, and the documentation of each command with man git-<commandname> or git help <commandname>.

CVS users may also want to read Documentation/gitcvs-migration.txt (man gitcvs-migration or git help cvs-migration if git is installed).

The user discussion and development of Git take place on the Git mailing list -- everyone is welcome to post bug reports, feature requests, comments and patches to git@vger.kernel.org (read Documentation/SubmittingPatches for instructions on patch submission and Documentation/CodingGuidelines).

Those wishing to help with error message, usage and informational message string translations (localization l10) should see po/README.md (a po file is a Portable Object file that holds the translations).

To subscribe to the list, send an email with just "subscribe git" in the body to majordomo@vger.kernel.org (not the Git list). The mailing list archives are available at https://lore.kernel.org/git/, http://marc.info/?l=git and other archival sites.

Issues which are security relevant should be disclosed privately to the Git Security mailing list git-security@googlegroups.com.

The maintainer frequently sends the "What's cooking" reports that list the current status of various development topics to the mailing list. The discussion following them give a good reference for project status, development direction and remaining tasks.

The name "git" was given by Linus Torvalds when he wrote the very first version. He described the tool as "the stupid content tracker" and the name as (depending on your mood):

  • random three-letter combination that is pronounceable, and not actually used by any common UNIX command. The fact that it is a mispronunciation of "get" may or may not be relevant.
  • stupid. contemptible and despicable. simple. Take your pick from the dictionary of slang.
  • "global information tracker": you're in a good mood, and it actually works for you. Angels sing, and a light suddenly fills the room.
  • "goddamn idiotic truckload of sh*t": when it breaks