Unfortunately, prefix_path() sometimes returns a newly xmalloc()ed buffer,
and in other cases it returns a substring!
For example, when calling
git update-index ./hello.txt
prefix_path() returns "hello.txt", but does not allocate a new buffer. The
original code only checked if the result of prefix_path() was different from
what was passed in, and thusly trigger a segmentation fault.
Signed-off-by: Johannes Schindelin <Johannes.Schindelin@gmx.de>
Signed-off-by: Junio C Hamano <junkio@cox.net>
die("git-checkout-index: don't mix '--stdin' and explicit filenames");
p = prefix_path(prefix, prefix_length, arg);
checkout_file(p);
die("git-checkout-index: don't mix '--stdin' and explicit filenames");
p = prefix_path(prefix, prefix_length, arg);
checkout_file(p);
+ if (p < arg || p > arg + strlen(arg))
path_name = buf.buf;
p = prefix_path(prefix, prefix_length, path_name);
checkout_file(p);
path_name = buf.buf;
p = prefix_path(prefix, prefix_length, path_name);
checkout_file(p);
+ if (p < path_name || p > path_name + strlen(path_name))
free((char *)p);
if (path_name != buf.buf)
free(path_name);
free((char *)p);
if (path_name != buf.buf)
free(path_name);
die("Unable to process file %s", path);
report("add '%s'", path);
free_return:
die("Unable to process file %s", path);
report("add '%s'", path);
free_return:
+ if (p < path || p > path + strlen(path))
const char *arg = av[i];
const char *p = prefix_path(prefix, prefix_length, arg);
err |= unresolve_one(p);
const char *arg = av[i];
const char *p = prefix_path(prefix, prefix_length, arg);
err |= unresolve_one(p);
+ if (p < arg || p > arg + strlen(arg))
free((char*)p);
}
return err;
free((char*)p);
}
return err;
*/
int pos;
int has_head = 1;
*/
int pos;
int has_head = 1;
- char **pathspec = get_pathspec(prefix, av + 1);
+ const char **pathspec = get_pathspec(prefix, av + 1);
if (read_ref(git_path("HEAD"), head_sha1))
/* If there is no HEAD, that means it is an initial
if (read_ref(git_path("HEAD"), head_sha1))
/* If there is no HEAD, that means it is an initial
update_one(p, NULL, 0);
if (set_executable_bit)
chmod_path(set_executable_bit, p);
update_one(p, NULL, 0);
if (set_executable_bit)
chmod_path(set_executable_bit, p);
+ if (p < path_name || p > path_name + strlen(path_name))
free((char*) p);
if (path_name != buf.buf)
free(path_name);
free((char*) p);
if (path_name != buf.buf)
free(path_name);