]> git.ipfire.org Git - thirdparty/git.git/blame_incremental - fsck.c
Merge branch 'sg/osx-force-gcc-9'
[thirdparty/git.git] / fsck.c
... / ...
CommitLineData
1#include "cache.h"
2#include "object-store.h"
3#include "repository.h"
4#include "object.h"
5#include "blob.h"
6#include "tree.h"
7#include "tree-walk.h"
8#include "commit.h"
9#include "tag.h"
10#include "fsck.h"
11#include "refs.h"
12#include "utf8.h"
13#include "decorate.h"
14#include "oidset.h"
15#include "packfile.h"
16#include "submodule-config.h"
17#include "config.h"
18#include "help.h"
19
20static struct oidset gitmodules_found = OIDSET_INIT;
21static struct oidset gitmodules_done = OIDSET_INIT;
22
23#define FSCK_FATAL -1
24#define FSCK_INFO -2
25
26#define FOREACH_MSG_ID(FUNC) \
27 /* fatal errors */ \
28 FUNC(NUL_IN_HEADER, FATAL) \
29 FUNC(UNTERMINATED_HEADER, FATAL) \
30 /* errors */ \
31 FUNC(BAD_DATE, ERROR) \
32 FUNC(BAD_DATE_OVERFLOW, ERROR) \
33 FUNC(BAD_EMAIL, ERROR) \
34 FUNC(BAD_NAME, ERROR) \
35 FUNC(BAD_OBJECT_SHA1, ERROR) \
36 FUNC(BAD_PARENT_SHA1, ERROR) \
37 FUNC(BAD_TAG_OBJECT, ERROR) \
38 FUNC(BAD_TIMEZONE, ERROR) \
39 FUNC(BAD_TREE, ERROR) \
40 FUNC(BAD_TREE_SHA1, ERROR) \
41 FUNC(BAD_TYPE, ERROR) \
42 FUNC(DUPLICATE_ENTRIES, ERROR) \
43 FUNC(MISSING_AUTHOR, ERROR) \
44 FUNC(MISSING_COMMITTER, ERROR) \
45 FUNC(MISSING_EMAIL, ERROR) \
46 FUNC(MISSING_NAME_BEFORE_EMAIL, ERROR) \
47 FUNC(MISSING_OBJECT, ERROR) \
48 FUNC(MISSING_SPACE_BEFORE_DATE, ERROR) \
49 FUNC(MISSING_SPACE_BEFORE_EMAIL, ERROR) \
50 FUNC(MISSING_TAG, ERROR) \
51 FUNC(MISSING_TAG_ENTRY, ERROR) \
52 FUNC(MISSING_TREE, ERROR) \
53 FUNC(MISSING_TREE_OBJECT, ERROR) \
54 FUNC(MISSING_TYPE, ERROR) \
55 FUNC(MISSING_TYPE_ENTRY, ERROR) \
56 FUNC(MULTIPLE_AUTHORS, ERROR) \
57 FUNC(TREE_NOT_SORTED, ERROR) \
58 FUNC(UNKNOWN_TYPE, ERROR) \
59 FUNC(ZERO_PADDED_DATE, ERROR) \
60 FUNC(GITMODULES_MISSING, ERROR) \
61 FUNC(GITMODULES_BLOB, ERROR) \
62 FUNC(GITMODULES_LARGE, ERROR) \
63 FUNC(GITMODULES_NAME, ERROR) \
64 FUNC(GITMODULES_SYMLINK, ERROR) \
65 FUNC(GITMODULES_URL, ERROR) \
66 FUNC(GITMODULES_PATH, ERROR) \
67 /* warnings */ \
68 FUNC(BAD_FILEMODE, WARN) \
69 FUNC(EMPTY_NAME, WARN) \
70 FUNC(FULL_PATHNAME, WARN) \
71 FUNC(HAS_DOT, WARN) \
72 FUNC(HAS_DOTDOT, WARN) \
73 FUNC(HAS_DOTGIT, WARN) \
74 FUNC(NULL_SHA1, WARN) \
75 FUNC(ZERO_PADDED_FILEMODE, WARN) \
76 FUNC(NUL_IN_COMMIT, WARN) \
77 /* infos (reported as warnings, but ignored by default) */ \
78 FUNC(GITMODULES_PARSE, INFO) \
79 FUNC(BAD_TAG_NAME, INFO) \
80 FUNC(MISSING_TAGGER_ENTRY, INFO)
81
82#define MSG_ID(id, msg_type) FSCK_MSG_##id,
83enum fsck_msg_id {
84 FOREACH_MSG_ID(MSG_ID)
85 FSCK_MSG_MAX
86};
87#undef MSG_ID
88
89#define STR(x) #x
90#define MSG_ID(id, msg_type) { STR(id), NULL, NULL, FSCK_##msg_type },
91static struct {
92 const char *id_string;
93 const char *downcased;
94 const char *camelcased;
95 int msg_type;
96} msg_id_info[FSCK_MSG_MAX + 1] = {
97 FOREACH_MSG_ID(MSG_ID)
98 { NULL, NULL, NULL, -1 }
99};
100#undef MSG_ID
101
102static void prepare_msg_ids(void)
103{
104 int i;
105
106 if (msg_id_info[0].downcased)
107 return;
108
109 /* convert id_string to lower case, without underscores. */
110 for (i = 0; i < FSCK_MSG_MAX; i++) {
111 const char *p = msg_id_info[i].id_string;
112 int len = strlen(p);
113 char *q = xmalloc(len);
114
115 msg_id_info[i].downcased = q;
116 while (*p)
117 if (*p == '_')
118 p++;
119 else
120 *(q)++ = tolower(*(p)++);
121 *q = '\0';
122
123 p = msg_id_info[i].id_string;
124 q = xmalloc(len);
125 msg_id_info[i].camelcased = q;
126 while (*p) {
127 if (*p == '_') {
128 p++;
129 if (*p)
130 *q++ = *p++;
131 } else {
132 *q++ = tolower(*p++);
133 }
134 }
135 *q = '\0';
136 }
137}
138
139static int parse_msg_id(const char *text)
140{
141 int i;
142
143 prepare_msg_ids();
144
145 for (i = 0; i < FSCK_MSG_MAX; i++)
146 if (!strcmp(text, msg_id_info[i].downcased))
147 return i;
148
149 return -1;
150}
151
152void list_config_fsck_msg_ids(struct string_list *list, const char *prefix)
153{
154 int i;
155
156 prepare_msg_ids();
157
158 for (i = 0; i < FSCK_MSG_MAX; i++)
159 list_config_item(list, prefix, msg_id_info[i].camelcased);
160}
161
162static int fsck_msg_type(enum fsck_msg_id msg_id,
163 struct fsck_options *options)
164{
165 int msg_type;
166
167 assert(msg_id >= 0 && msg_id < FSCK_MSG_MAX);
168
169 if (options->msg_type)
170 msg_type = options->msg_type[msg_id];
171 else {
172 msg_type = msg_id_info[msg_id].msg_type;
173 if (options->strict && msg_type == FSCK_WARN)
174 msg_type = FSCK_ERROR;
175 }
176
177 return msg_type;
178}
179
180static int parse_msg_type(const char *str)
181{
182 if (!strcmp(str, "error"))
183 return FSCK_ERROR;
184 else if (!strcmp(str, "warn"))
185 return FSCK_WARN;
186 else if (!strcmp(str, "ignore"))
187 return FSCK_IGNORE;
188 else
189 die("Unknown fsck message type: '%s'", str);
190}
191
192int is_valid_msg_type(const char *msg_id, const char *msg_type)
193{
194 if (parse_msg_id(msg_id) < 0)
195 return 0;
196 parse_msg_type(msg_type);
197 return 1;
198}
199
200void fsck_set_msg_type(struct fsck_options *options,
201 const char *msg_id, const char *msg_type)
202{
203 int id = parse_msg_id(msg_id), type;
204
205 if (id < 0)
206 die("Unhandled message id: %s", msg_id);
207 type = parse_msg_type(msg_type);
208
209 if (type != FSCK_ERROR && msg_id_info[id].msg_type == FSCK_FATAL)
210 die("Cannot demote %s to %s", msg_id, msg_type);
211
212 if (!options->msg_type) {
213 int i;
214 int *msg_type;
215 ALLOC_ARRAY(msg_type, FSCK_MSG_MAX);
216 for (i = 0; i < FSCK_MSG_MAX; i++)
217 msg_type[i] = fsck_msg_type(i, options);
218 options->msg_type = msg_type;
219 }
220
221 options->msg_type[id] = type;
222}
223
224void fsck_set_msg_types(struct fsck_options *options, const char *values)
225{
226 char *buf = xstrdup(values), *to_free = buf;
227 int done = 0;
228
229 while (!done) {
230 int len = strcspn(buf, " ,|"), equal;
231
232 done = !buf[len];
233 if (!len) {
234 buf++;
235 continue;
236 }
237 buf[len] = '\0';
238
239 for (equal = 0;
240 equal < len && buf[equal] != '=' && buf[equal] != ':';
241 equal++)
242 buf[equal] = tolower(buf[equal]);
243 buf[equal] = '\0';
244
245 if (!strcmp(buf, "skiplist")) {
246 if (equal == len)
247 die("skiplist requires a path");
248 oidset_parse_file(&options->skiplist, buf + equal + 1);
249 buf += len + 1;
250 continue;
251 }
252
253 if (equal == len)
254 die("Missing '=': '%s'", buf);
255
256 fsck_set_msg_type(options, buf, buf + equal + 1);
257 buf += len + 1;
258 }
259 free(to_free);
260}
261
262static void append_msg_id(struct strbuf *sb, const char *msg_id)
263{
264 for (;;) {
265 char c = *(msg_id)++;
266
267 if (!c)
268 break;
269 if (c != '_')
270 strbuf_addch(sb, tolower(c));
271 else {
272 assert(*msg_id);
273 strbuf_addch(sb, *(msg_id)++);
274 }
275 }
276
277 strbuf_addstr(sb, ": ");
278}
279
280static int object_on_skiplist(struct fsck_options *opts,
281 const struct object_id *oid)
282{
283 return opts && oid && oidset_contains(&opts->skiplist, oid);
284}
285
286__attribute__((format (printf, 5, 6)))
287static int report(struct fsck_options *options,
288 const struct object_id *oid, enum object_type object_type,
289 enum fsck_msg_id id, const char *fmt, ...)
290{
291 va_list ap;
292 struct strbuf sb = STRBUF_INIT;
293 int msg_type = fsck_msg_type(id, options), result;
294
295 if (msg_type == FSCK_IGNORE)
296 return 0;
297
298 if (object_on_skiplist(options, oid))
299 return 0;
300
301 if (msg_type == FSCK_FATAL)
302 msg_type = FSCK_ERROR;
303 else if (msg_type == FSCK_INFO)
304 msg_type = FSCK_WARN;
305
306 append_msg_id(&sb, msg_id_info[id].id_string);
307
308 va_start(ap, fmt);
309 strbuf_vaddf(&sb, fmt, ap);
310 result = options->error_func(options, oid, object_type,
311 msg_type, sb.buf);
312 strbuf_release(&sb);
313 va_end(ap);
314
315 return result;
316}
317
318void fsck_enable_object_names(struct fsck_options *options)
319{
320 if (!options->object_names)
321 options->object_names = kh_init_oid_map();
322}
323
324const char *fsck_get_object_name(struct fsck_options *options,
325 const struct object_id *oid)
326{
327 khiter_t pos;
328 if (!options->object_names)
329 return NULL;
330 pos = kh_get_oid_map(options->object_names, *oid);
331 if (pos >= kh_end(options->object_names))
332 return NULL;
333 return kh_value(options->object_names, pos);
334}
335
336void fsck_put_object_name(struct fsck_options *options,
337 const struct object_id *oid,
338 const char *fmt, ...)
339{
340 va_list ap;
341 struct strbuf buf = STRBUF_INIT;
342 khiter_t pos;
343 int hashret;
344
345 if (!options->object_names)
346 return;
347
348 pos = kh_put_oid_map(options->object_names, *oid, &hashret);
349 if (!hashret)
350 return;
351 va_start(ap, fmt);
352 strbuf_vaddf(&buf, fmt, ap);
353 kh_value(options->object_names, pos) = strbuf_detach(&buf, NULL);
354 va_end(ap);
355}
356
357const char *fsck_describe_object(struct fsck_options *options,
358 const struct object_id *oid)
359{
360 static struct strbuf bufs[] = {
361 STRBUF_INIT, STRBUF_INIT, STRBUF_INIT, STRBUF_INIT
362 };
363 static int b = 0;
364 struct strbuf *buf;
365 const char *name = fsck_get_object_name(options, oid);
366
367 buf = bufs + b;
368 b = (b + 1) % ARRAY_SIZE(bufs);
369 strbuf_reset(buf);
370 strbuf_addstr(buf, oid_to_hex(oid));
371 if (name)
372 strbuf_addf(buf, " (%s)", name);
373
374 return buf->buf;
375}
376
377static int fsck_walk_tree(struct tree *tree, void *data, struct fsck_options *options)
378{
379 struct tree_desc desc;
380 struct name_entry entry;
381 int res = 0;
382 const char *name;
383
384 if (parse_tree(tree))
385 return -1;
386
387 name = fsck_get_object_name(options, &tree->object.oid);
388 if (init_tree_desc_gently(&desc, tree->buffer, tree->size))
389 return -1;
390 while (tree_entry_gently(&desc, &entry)) {
391 struct object *obj;
392 int result;
393
394 if (S_ISGITLINK(entry.mode))
395 continue;
396
397 if (S_ISDIR(entry.mode)) {
398 obj = (struct object *)lookup_tree(the_repository, &entry.oid);
399 if (name && obj)
400 fsck_put_object_name(options, &entry.oid, "%s%s/",
401 name, entry.path);
402 result = options->walk(obj, OBJ_TREE, data, options);
403 }
404 else if (S_ISREG(entry.mode) || S_ISLNK(entry.mode)) {
405 obj = (struct object *)lookup_blob(the_repository, &entry.oid);
406 if (name && obj)
407 fsck_put_object_name(options, &entry.oid, "%s%s",
408 name, entry.path);
409 result = options->walk(obj, OBJ_BLOB, data, options);
410 }
411 else {
412 result = error("in tree %s: entry %s has bad mode %.6o",
413 fsck_describe_object(options, &tree->object.oid),
414 entry.path, entry.mode);
415 }
416 if (result < 0)
417 return result;
418 if (!res)
419 res = result;
420 }
421 return res;
422}
423
424static int fsck_walk_commit(struct commit *commit, void *data, struct fsck_options *options)
425{
426 int counter = 0, generation = 0, name_prefix_len = 0;
427 struct commit_list *parents;
428 int res;
429 int result;
430 const char *name;
431
432 if (parse_commit(commit))
433 return -1;
434
435 name = fsck_get_object_name(options, &commit->object.oid);
436 if (name)
437 fsck_put_object_name(options, get_commit_tree_oid(commit),
438 "%s:", name);
439
440 result = options->walk((struct object *)get_commit_tree(commit),
441 OBJ_TREE, data, options);
442 if (result < 0)
443 return result;
444 res = result;
445
446 parents = commit->parents;
447 if (name && parents) {
448 int len = strlen(name), power;
449
450 if (len && name[len - 1] == '^') {
451 generation = 1;
452 name_prefix_len = len - 1;
453 }
454 else { /* parse ~<generation> suffix */
455 for (generation = 0, power = 1;
456 len && isdigit(name[len - 1]);
457 power *= 10)
458 generation += power * (name[--len] - '0');
459 if (power > 1 && len && name[len - 1] == '~')
460 name_prefix_len = len - 1;
461 }
462 }
463
464 while (parents) {
465 if (name) {
466 struct object_id *oid = &parents->item->object.oid;
467
468 if (counter++)
469 fsck_put_object_name(options, oid, "%s^%d",
470 name, counter);
471 else if (generation > 0)
472 fsck_put_object_name(options, oid, "%.*s~%d",
473 name_prefix_len, name,
474 generation + 1);
475 else
476 fsck_put_object_name(options, oid, "%s^", name);
477 }
478 result = options->walk((struct object *)parents->item, OBJ_COMMIT, data, options);
479 if (result < 0)
480 return result;
481 if (!res)
482 res = result;
483 parents = parents->next;
484 }
485 return res;
486}
487
488static int fsck_walk_tag(struct tag *tag, void *data, struct fsck_options *options)
489{
490 const char *name = fsck_get_object_name(options, &tag->object.oid);
491
492 if (parse_tag(tag))
493 return -1;
494 if (name)
495 fsck_put_object_name(options, &tag->tagged->oid, "%s", name);
496 return options->walk(tag->tagged, OBJ_ANY, data, options);
497}
498
499int fsck_walk(struct object *obj, void *data, struct fsck_options *options)
500{
501 if (!obj)
502 return -1;
503
504 if (obj->type == OBJ_NONE)
505 parse_object(the_repository, &obj->oid);
506
507 switch (obj->type) {
508 case OBJ_BLOB:
509 return 0;
510 case OBJ_TREE:
511 return fsck_walk_tree((struct tree *)obj, data, options);
512 case OBJ_COMMIT:
513 return fsck_walk_commit((struct commit *)obj, data, options);
514 case OBJ_TAG:
515 return fsck_walk_tag((struct tag *)obj, data, options);
516 default:
517 error("Unknown object type for %s",
518 fsck_describe_object(options, &obj->oid));
519 return -1;
520 }
521}
522
523/*
524 * The entries in a tree are ordered in the _path_ order,
525 * which means that a directory entry is ordered by adding
526 * a slash to the end of it.
527 *
528 * So a directory called "a" is ordered _after_ a file
529 * called "a.c", because "a/" sorts after "a.c".
530 */
531#define TREE_UNORDERED (-1)
532#define TREE_HAS_DUPS (-2)
533
534static int verify_ordered(unsigned mode1, const char *name1, unsigned mode2, const char *name2)
535{
536 int len1 = strlen(name1);
537 int len2 = strlen(name2);
538 int len = len1 < len2 ? len1 : len2;
539 unsigned char c1, c2;
540 int cmp;
541
542 cmp = memcmp(name1, name2, len);
543 if (cmp < 0)
544 return 0;
545 if (cmp > 0)
546 return TREE_UNORDERED;
547
548 /*
549 * Ok, the first <len> characters are the same.
550 * Now we need to order the next one, but turn
551 * a '\0' into a '/' for a directory entry.
552 */
553 c1 = name1[len];
554 c2 = name2[len];
555 if (!c1 && !c2)
556 /*
557 * git-write-tree used to write out a nonsense tree that has
558 * entries with the same name, one blob and one tree. Make
559 * sure we do not have duplicate entries.
560 */
561 return TREE_HAS_DUPS;
562 if (!c1 && S_ISDIR(mode1))
563 c1 = '/';
564 if (!c2 && S_ISDIR(mode2))
565 c2 = '/';
566 return c1 < c2 ? 0 : TREE_UNORDERED;
567}
568
569static int fsck_tree(const struct object_id *oid,
570 const char *buffer, unsigned long size,
571 struct fsck_options *options)
572{
573 int retval = 0;
574 int has_null_sha1 = 0;
575 int has_full_path = 0;
576 int has_empty_name = 0;
577 int has_dot = 0;
578 int has_dotdot = 0;
579 int has_dotgit = 0;
580 int has_zero_pad = 0;
581 int has_bad_modes = 0;
582 int has_dup_entries = 0;
583 int not_properly_sorted = 0;
584 struct tree_desc desc;
585 unsigned o_mode;
586 const char *o_name;
587
588 if (init_tree_desc_gently(&desc, buffer, size)) {
589 retval += report(options, oid, OBJ_TREE, FSCK_MSG_BAD_TREE, "cannot be parsed as a tree");
590 return retval;
591 }
592
593 o_mode = 0;
594 o_name = NULL;
595
596 while (desc.size) {
597 unsigned short mode;
598 const char *name;
599 const struct object_id *oid;
600
601 oid = tree_entry_extract(&desc, &name, &mode);
602
603 has_null_sha1 |= is_null_oid(oid);
604 has_full_path |= !!strchr(name, '/');
605 has_empty_name |= !*name;
606 has_dot |= !strcmp(name, ".");
607 has_dotdot |= !strcmp(name, "..");
608 has_dotgit |= is_hfs_dotgit(name) || is_ntfs_dotgit(name);
609 has_zero_pad |= *(char *)desc.buffer == '0';
610
611 if (is_hfs_dotgitmodules(name) || is_ntfs_dotgitmodules(name)) {
612 if (!S_ISLNK(mode))
613 oidset_insert(&gitmodules_found, oid);
614 else
615 retval += report(options,
616 oid, OBJ_TREE,
617 FSCK_MSG_GITMODULES_SYMLINK,
618 ".gitmodules is a symbolic link");
619 }
620
621 if (update_tree_entry_gently(&desc)) {
622 retval += report(options, oid, OBJ_TREE, FSCK_MSG_BAD_TREE, "cannot be parsed as a tree");
623 break;
624 }
625
626 switch (mode) {
627 /*
628 * Standard modes..
629 */
630 case S_IFREG | 0755:
631 case S_IFREG | 0644:
632 case S_IFLNK:
633 case S_IFDIR:
634 case S_IFGITLINK:
635 break;
636 /*
637 * This is nonstandard, but we had a few of these
638 * early on when we honored the full set of mode
639 * bits..
640 */
641 case S_IFREG | 0664:
642 if (!options->strict)
643 break;
644 /* fallthrough */
645 default:
646 has_bad_modes = 1;
647 }
648
649 if (o_name) {
650 switch (verify_ordered(o_mode, o_name, mode, name)) {
651 case TREE_UNORDERED:
652 not_properly_sorted = 1;
653 break;
654 case TREE_HAS_DUPS:
655 has_dup_entries = 1;
656 break;
657 default:
658 break;
659 }
660 }
661
662 o_mode = mode;
663 o_name = name;
664 }
665
666 if (has_null_sha1)
667 retval += report(options, oid, OBJ_TREE, FSCK_MSG_NULL_SHA1, "contains entries pointing to null sha1");
668 if (has_full_path)
669 retval += report(options, oid, OBJ_TREE, FSCK_MSG_FULL_PATHNAME, "contains full pathnames");
670 if (has_empty_name)
671 retval += report(options, oid, OBJ_TREE, FSCK_MSG_EMPTY_NAME, "contains empty pathname");
672 if (has_dot)
673 retval += report(options, oid, OBJ_TREE, FSCK_MSG_HAS_DOT, "contains '.'");
674 if (has_dotdot)
675 retval += report(options, oid, OBJ_TREE, FSCK_MSG_HAS_DOTDOT, "contains '..'");
676 if (has_dotgit)
677 retval += report(options, oid, OBJ_TREE, FSCK_MSG_HAS_DOTGIT, "contains '.git'");
678 if (has_zero_pad)
679 retval += report(options, oid, OBJ_TREE, FSCK_MSG_ZERO_PADDED_FILEMODE, "contains zero-padded file modes");
680 if (has_bad_modes)
681 retval += report(options, oid, OBJ_TREE, FSCK_MSG_BAD_FILEMODE, "contains bad file modes");
682 if (has_dup_entries)
683 retval += report(options, oid, OBJ_TREE, FSCK_MSG_DUPLICATE_ENTRIES, "contains duplicate file entries");
684 if (not_properly_sorted)
685 retval += report(options, oid, OBJ_TREE, FSCK_MSG_TREE_NOT_SORTED, "not properly sorted");
686 return retval;
687}
688
689static int verify_headers(const void *data, unsigned long size,
690 const struct object_id *oid, enum object_type type,
691 struct fsck_options *options)
692{
693 const char *buffer = (const char *)data;
694 unsigned long i;
695
696 for (i = 0; i < size; i++) {
697 switch (buffer[i]) {
698 case '\0':
699 return report(options, oid, type,
700 FSCK_MSG_NUL_IN_HEADER,
701 "unterminated header: NUL at offset %ld", i);
702 case '\n':
703 if (i + 1 < size && buffer[i + 1] == '\n')
704 return 0;
705 }
706 }
707
708 /*
709 * We did not find double-LF that separates the header
710 * and the body. Not having a body is not a crime but
711 * we do want to see the terminating LF for the last header
712 * line.
713 */
714 if (size && buffer[size - 1] == '\n')
715 return 0;
716
717 return report(options, oid, type,
718 FSCK_MSG_UNTERMINATED_HEADER, "unterminated header");
719}
720
721static int fsck_ident(const char **ident,
722 const struct object_id *oid, enum object_type type,
723 struct fsck_options *options)
724{
725 const char *p = *ident;
726 char *end;
727
728 *ident = strchrnul(*ident, '\n');
729 if (**ident == '\n')
730 (*ident)++;
731
732 if (*p == '<')
733 return report(options, oid, type, FSCK_MSG_MISSING_NAME_BEFORE_EMAIL, "invalid author/committer line - missing space before email");
734 p += strcspn(p, "<>\n");
735 if (*p == '>')
736 return report(options, oid, type, FSCK_MSG_BAD_NAME, "invalid author/committer line - bad name");
737 if (*p != '<')
738 return report(options, oid, type, FSCK_MSG_MISSING_EMAIL, "invalid author/committer line - missing email");
739 if (p[-1] != ' ')
740 return report(options, oid, type, FSCK_MSG_MISSING_SPACE_BEFORE_EMAIL, "invalid author/committer line - missing space before email");
741 p++;
742 p += strcspn(p, "<>\n");
743 if (*p != '>')
744 return report(options, oid, type, FSCK_MSG_BAD_EMAIL, "invalid author/committer line - bad email");
745 p++;
746 if (*p != ' ')
747 return report(options, oid, type, FSCK_MSG_MISSING_SPACE_BEFORE_DATE, "invalid author/committer line - missing space before date");
748 p++;
749 if (*p == '0' && p[1] != ' ')
750 return report(options, oid, type, FSCK_MSG_ZERO_PADDED_DATE, "invalid author/committer line - zero-padded date");
751 if (date_overflows(parse_timestamp(p, &end, 10)))
752 return report(options, oid, type, FSCK_MSG_BAD_DATE_OVERFLOW, "invalid author/committer line - date causes integer overflow");
753 if ((end == p || *end != ' '))
754 return report(options, oid, type, FSCK_MSG_BAD_DATE, "invalid author/committer line - bad date");
755 p = end + 1;
756 if ((*p != '+' && *p != '-') ||
757 !isdigit(p[1]) ||
758 !isdigit(p[2]) ||
759 !isdigit(p[3]) ||
760 !isdigit(p[4]) ||
761 (p[5] != '\n'))
762 return report(options, oid, type, FSCK_MSG_BAD_TIMEZONE, "invalid author/committer line - bad time zone");
763 p += 6;
764 return 0;
765}
766
767static int fsck_commit(const struct object_id *oid,
768 const char *buffer, unsigned long size,
769 struct fsck_options *options)
770{
771 struct object_id tree_oid, parent_oid;
772 unsigned author_count;
773 int err;
774 const char *buffer_begin = buffer;
775 const char *p;
776
777 if (verify_headers(buffer, size, oid, OBJ_COMMIT, options))
778 return -1;
779
780 if (!skip_prefix(buffer, "tree ", &buffer))
781 return report(options, oid, OBJ_COMMIT, FSCK_MSG_MISSING_TREE, "invalid format - expected 'tree' line");
782 if (parse_oid_hex(buffer, &tree_oid, &p) || *p != '\n') {
783 err = report(options, oid, OBJ_COMMIT, FSCK_MSG_BAD_TREE_SHA1, "invalid 'tree' line format - bad sha1");
784 if (err)
785 return err;
786 }
787 buffer = p + 1;
788 while (skip_prefix(buffer, "parent ", &buffer)) {
789 if (parse_oid_hex(buffer, &parent_oid, &p) || *p != '\n') {
790 err = report(options, oid, OBJ_COMMIT, FSCK_MSG_BAD_PARENT_SHA1, "invalid 'parent' line format - bad sha1");
791 if (err)
792 return err;
793 }
794 buffer = p + 1;
795 }
796 author_count = 0;
797 while (skip_prefix(buffer, "author ", &buffer)) {
798 author_count++;
799 err = fsck_ident(&buffer, oid, OBJ_COMMIT, options);
800 if (err)
801 return err;
802 }
803 if (author_count < 1)
804 err = report(options, oid, OBJ_COMMIT, FSCK_MSG_MISSING_AUTHOR, "invalid format - expected 'author' line");
805 else if (author_count > 1)
806 err = report(options, oid, OBJ_COMMIT, FSCK_MSG_MULTIPLE_AUTHORS, "invalid format - multiple 'author' lines");
807 if (err)
808 return err;
809 if (!skip_prefix(buffer, "committer ", &buffer))
810 return report(options, oid, OBJ_COMMIT, FSCK_MSG_MISSING_COMMITTER, "invalid format - expected 'committer' line");
811 err = fsck_ident(&buffer, oid, OBJ_COMMIT, options);
812 if (err)
813 return err;
814 if (memchr(buffer_begin, '\0', size)) {
815 err = report(options, oid, OBJ_COMMIT, FSCK_MSG_NUL_IN_COMMIT,
816 "NUL byte in the commit object body");
817 if (err)
818 return err;
819 }
820 return 0;
821}
822
823static int fsck_tag(const struct object_id *oid, const char *buffer,
824 unsigned long size, struct fsck_options *options)
825{
826 struct object_id tagged_oid;
827 int ret = 0;
828 char *eol;
829 struct strbuf sb = STRBUF_INIT;
830 const char *p;
831
832 ret = verify_headers(buffer, size, oid, OBJ_TAG, options);
833 if (ret)
834 goto done;
835
836 if (!skip_prefix(buffer, "object ", &buffer)) {
837 ret = report(options, oid, OBJ_TAG, FSCK_MSG_MISSING_OBJECT, "invalid format - expected 'object' line");
838 goto done;
839 }
840 if (parse_oid_hex(buffer, &tagged_oid, &p) || *p != '\n') {
841 ret = report(options, oid, OBJ_TAG, FSCK_MSG_BAD_OBJECT_SHA1, "invalid 'object' line format - bad sha1");
842 if (ret)
843 goto done;
844 }
845 buffer = p + 1;
846
847 if (!skip_prefix(buffer, "type ", &buffer)) {
848 ret = report(options, oid, OBJ_TAG, FSCK_MSG_MISSING_TYPE_ENTRY, "invalid format - expected 'type' line");
849 goto done;
850 }
851 eol = strchr(buffer, '\n');
852 if (!eol) {
853 ret = report(options, oid, OBJ_TAG, FSCK_MSG_MISSING_TYPE, "invalid format - unexpected end after 'type' line");
854 goto done;
855 }
856 if (type_from_string_gently(buffer, eol - buffer, 1) < 0)
857 ret = report(options, oid, OBJ_TAG, FSCK_MSG_BAD_TYPE, "invalid 'type' value");
858 if (ret)
859 goto done;
860 buffer = eol + 1;
861
862 if (!skip_prefix(buffer, "tag ", &buffer)) {
863 ret = report(options, oid, OBJ_TAG, FSCK_MSG_MISSING_TAG_ENTRY, "invalid format - expected 'tag' line");
864 goto done;
865 }
866 eol = strchr(buffer, '\n');
867 if (!eol) {
868 ret = report(options, oid, OBJ_TAG, FSCK_MSG_MISSING_TAG, "invalid format - unexpected end after 'type' line");
869 goto done;
870 }
871 strbuf_addf(&sb, "refs/tags/%.*s", (int)(eol - buffer), buffer);
872 if (check_refname_format(sb.buf, 0)) {
873 ret = report(options, oid, OBJ_TAG,
874 FSCK_MSG_BAD_TAG_NAME,
875 "invalid 'tag' name: %.*s",
876 (int)(eol - buffer), buffer);
877 if (ret)
878 goto done;
879 }
880 buffer = eol + 1;
881
882 if (!skip_prefix(buffer, "tagger ", &buffer)) {
883 /* early tags do not contain 'tagger' lines; warn only */
884 ret = report(options, oid, OBJ_TAG, FSCK_MSG_MISSING_TAGGER_ENTRY, "invalid format - expected 'tagger' line");
885 if (ret)
886 goto done;
887 }
888 else
889 ret = fsck_ident(&buffer, oid, OBJ_TAG, options);
890
891done:
892 strbuf_release(&sb);
893 return ret;
894}
895
896struct fsck_gitmodules_data {
897 const struct object_id *oid;
898 struct fsck_options *options;
899 int ret;
900};
901
902static int fsck_gitmodules_fn(const char *var, const char *value, void *vdata)
903{
904 struct fsck_gitmodules_data *data = vdata;
905 const char *subsection, *key;
906 int subsection_len;
907 char *name;
908
909 if (parse_config_key(var, "submodule", &subsection, &subsection_len, &key) < 0 ||
910 !subsection)
911 return 0;
912
913 name = xmemdupz(subsection, subsection_len);
914 if (check_submodule_name(name) < 0)
915 data->ret |= report(data->options,
916 data->oid, OBJ_BLOB,
917 FSCK_MSG_GITMODULES_NAME,
918 "disallowed submodule name: %s",
919 name);
920 if (!strcmp(key, "url") && value &&
921 looks_like_command_line_option(value))
922 data->ret |= report(data->options,
923 data->oid, OBJ_BLOB,
924 FSCK_MSG_GITMODULES_URL,
925 "disallowed submodule url: %s",
926 value);
927 if (!strcmp(key, "path") && value &&
928 looks_like_command_line_option(value))
929 data->ret |= report(data->options,
930 data->oid, OBJ_BLOB,
931 FSCK_MSG_GITMODULES_PATH,
932 "disallowed submodule path: %s",
933 value);
934 free(name);
935
936 return 0;
937}
938
939static int fsck_blob(const struct object_id *oid, const char *buf,
940 unsigned long size, struct fsck_options *options)
941{
942 struct fsck_gitmodules_data data;
943 struct config_options config_opts = { 0 };
944
945 if (!oidset_contains(&gitmodules_found, oid))
946 return 0;
947 oidset_insert(&gitmodules_done, oid);
948
949 if (object_on_skiplist(options, oid))
950 return 0;
951
952 if (!buf) {
953 /*
954 * A missing buffer here is a sign that the caller found the
955 * blob too gigantic to load into memory. Let's just consider
956 * that an error.
957 */
958 return report(options, oid, OBJ_BLOB,
959 FSCK_MSG_GITMODULES_LARGE,
960 ".gitmodules too large to parse");
961 }
962
963 data.oid = oid;
964 data.options = options;
965 data.ret = 0;
966 config_opts.error_action = CONFIG_ERROR_SILENT;
967 if (git_config_from_mem(fsck_gitmodules_fn, CONFIG_ORIGIN_BLOB,
968 ".gitmodules", buf, size, &data, &config_opts))
969 data.ret |= report(options, oid, OBJ_BLOB,
970 FSCK_MSG_GITMODULES_PARSE,
971 "could not parse gitmodules blob");
972
973 return data.ret;
974}
975
976int fsck_object(struct object *obj, void *data, unsigned long size,
977 struct fsck_options *options)
978{
979 if (!obj)
980 return report(options, NULL, OBJ_NONE, FSCK_MSG_BAD_OBJECT_SHA1, "no valid object to fsck");
981
982 if (obj->type == OBJ_BLOB)
983 return fsck_blob(&obj->oid, data, size, options);
984 if (obj->type == OBJ_TREE)
985 return fsck_tree(&obj->oid, data, size, options);
986 if (obj->type == OBJ_COMMIT)
987 return fsck_commit(&obj->oid, data, size, options);
988 if (obj->type == OBJ_TAG)
989 return fsck_tag(&obj->oid, data, size, options);
990
991 return report(options, &obj->oid, obj->type,
992 FSCK_MSG_UNKNOWN_TYPE,
993 "unknown type '%d' (internal fsck error)",
994 obj->type);
995}
996
997int fsck_error_function(struct fsck_options *o,
998 const struct object_id *oid,
999 enum object_type object_type,
1000 int msg_type, const char *message)
1001{
1002 if (msg_type == FSCK_WARN) {
1003 warning("object %s: %s", fsck_describe_object(o, oid), message);
1004 return 0;
1005 }
1006 error("object %s: %s", fsck_describe_object(o, oid), message);
1007 return 1;
1008}
1009
1010int fsck_finish(struct fsck_options *options)
1011{
1012 int ret = 0;
1013 struct oidset_iter iter;
1014 const struct object_id *oid;
1015
1016 oidset_iter_init(&gitmodules_found, &iter);
1017 while ((oid = oidset_iter_next(&iter))) {
1018 enum object_type type;
1019 unsigned long size;
1020 char *buf;
1021
1022 if (oidset_contains(&gitmodules_done, oid))
1023 continue;
1024
1025 buf = read_object_file(oid, &type, &size);
1026 if (!buf) {
1027 if (is_promisor_object(oid))
1028 continue;
1029 ret |= report(options,
1030 oid, OBJ_BLOB,
1031 FSCK_MSG_GITMODULES_MISSING,
1032 "unable to read .gitmodules blob");
1033 continue;
1034 }
1035
1036 if (type == OBJ_BLOB)
1037 ret |= fsck_blob(oid, buf, size, options);
1038 else
1039 ret |= report(options,
1040 oid, type,
1041 FSCK_MSG_GITMODULES_BLOB,
1042 "non-blob found at .gitmodules");
1043 free(buf);
1044 }
1045
1046
1047 oidset_clear(&gitmodules_found);
1048 oidset_clear(&gitmodules_done);
1049 return ret;
1050}