]> git.ipfire.org Git - thirdparty/git.git/blame - quote.c
double free in builtin-update-index.c
[thirdparty/git.git] / quote.c
CommitLineData
6fb737be
JH
1#include "cache.h"
2#include "quote.h"
3
4/* Help to copy the thing properly quoted for the shell safety.
77d604c3
PA
5 * any single quote is replaced with '\'', any exclamation point
6 * is replaced with '\!', and the whole thing is enclosed in a
6fb737be
JH
7 *
8 * E.g.
9 * original sq_quote result
10 * name ==> name ==> 'name'
11 * a b ==> a b ==> 'a b'
12 * a'b ==> a'\''b ==> 'a'\''b'
77d604c3 13 * a!b ==> a'\!'b ==> 'a'\!'b'
6fb737be 14 */
35eb2d36
LT
15static inline int need_bs_quote(char c)
16{
17 return (c == '\'' || c == '!');
18}
19
7a33bcbe 20void sq_quote_buf(struct strbuf *dst, const char *src)
77d604c3 21{
7a33bcbe
PH
22 char *to_free = NULL;
23
24 if (dst->buf == src)
25 to_free = strbuf_detach(dst);
26
27 strbuf_addch(dst, '\'');
28 while (*src) {
29 size_t len = strcspn(src, "'\\");
30 strbuf_add(dst, src, len);
31 src += len;
32 while (need_bs_quote(*src)) {
33 strbuf_addstr(dst, "'\\");
34 strbuf_addch(dst, *src++);
35 strbuf_addch(dst, '\'');
6fb737be
JH
36 }
37 }
7a33bcbe
PH
38 strbuf_addch(dst, '\'');
39 free(to_free);
77d604c3
PA
40}
41
575ba9d6
ML
42void sq_quote_print(FILE *stream, const char *src)
43{
44 char c;
45
46 fputc('\'', stream);
47 while ((c = *src++)) {
48 if (need_bs_quote(c)) {
49 fputs("'\\", stream);
50 fputc(c, stream);
51 fputc('\'', stream);
52 } else {
53 fputc(c, stream);
54 }
55 }
56 fputc('\'', stream);
57}
58
7a33bcbe
PH
59void sq_quote_argv(struct strbuf *dst, const char** argv, int count,
60 size_t maxlen)
7cf67205 61{
7cf67205 62 int i;
7cf67205
CC
63
64 /* Count argv if needed. */
65 if (count < 0) {
66 for (count = 0; argv[count]; count++)
67 ; /* just counting */
68 }
69
7cf67205 70 /* Copy into destination buffer. */
7a33bcbe 71 strbuf_grow(dst, 32 * count);
7cf67205 72 for (i = 0; i < count; ++i) {
7a33bcbe
PH
73 strbuf_addch(dst, ' ');
74 sq_quote_buf(dst, argv[i]);
75 if (maxlen && dst->len > maxlen)
76 die("Too many or long arguments");
7cf67205 77 }
86257aa3
CC
78}
79
35eb2d36
LT
80char *sq_dequote(char *arg)
81{
82 char *dst = arg;
83 char *src = arg;
84 char c;
85
86 if (*src != '\'')
87 return NULL;
88 for (;;) {
89 c = *++src;
90 if (!c)
91 return NULL;
92 if (c != '\'') {
93 *dst++ = c;
94 continue;
95 }
96 /* We stepped out of sq */
97 switch (*++src) {
98 case '\0':
99 *dst = 0;
100 return arg;
101 case '\\':
102 c = *++src;
103 if (need_bs_quote(c) && *++src == '\'') {
104 *dst++ = c;
105 continue;
106 }
107 /* Fallthrough */
108 default:
109 return NULL;
110 }
111 }
112}
113
663af342
PH
114/* 1 means: quote as octal
115 * 0 means: quote as octal if (quote_path_fully)
116 * -1 means: never quote
117 * c: quote as "\\c"
118 */
119#define X8(x) x, x, x, x, x, x, x, x
120#define X16(x) X8(x), X8(x)
121static signed char const sq_lookup[256] = {
122 /* 0 1 2 3 4 5 6 7 */
123 /* 0x00 */ 1, 1, 1, 1, 1, 1, 1, 'a',
124 /* 0x08 */ 'b', 't', 'n', 'v', 'f', 'r', 1, 1,
125 /* 0x10 */ X16(1),
126 /* 0x20 */ -1, -1, '"', -1, -1, -1, -1, -1,
127 /* 0x28 */ X16(-1), X16(-1), X16(-1),
128 /* 0x58 */ -1, -1, -1, -1,'\\', -1, -1, -1,
129 /* 0x60 */ X16(-1), X8(-1),
130 /* 0x78 */ -1, -1, -1, -1, -1, -1, -1, 1,
131 /* 0x80 */ /* set to 0 */
132};
133
134static inline int sq_must_quote(char c) {
135 return sq_lookup[(unsigned char)c] + quote_path_fully > 0;
136}
137
138/* returns the longest prefix not needing a quote up to maxlen if positive.
139 This stops at the first \0 because it's marked as a character needing an
140 escape */
141static size_t next_quote_pos(const char *s, ssize_t maxlen)
142{
143 size_t len;
144 if (maxlen < 0) {
145 for (len = 0; !sq_must_quote(s[len]); len++);
146 } else {
147 for (len = 0; len < maxlen && !sq_must_quote(s[len]); len++);
148 }
149 return len;
150}
151
4f6fbcdc
JH
152/*
153 * C-style name quoting.
154 *
663af342
PH
155 * (1) if sb and fp are both NULL, inspect the input name and counts the
156 * number of bytes that are needed to hold c_style quoted version of name,
157 * counting the double quotes around it but not terminating NUL, and
158 * returns it.
159 * However, if name does not need c_style quoting, it returns 0.
4f6fbcdc 160 *
663af342
PH
161 * (2) if sb or fp are not NULL, it emits the c_style quoted version
162 * of name, enclosed with double quotes if asked and needed only.
163 * Return value is the same as in (1).
4f6fbcdc 164 */
663af342
PH
165static size_t quote_c_style_counted(const char *name, ssize_t maxlen,
166 struct strbuf *sb, FILE *fp, int no_dq)
4f6fbcdc
JH
167{
168#undef EMIT
663af342
PH
169#define EMIT(c) \
170 do { \
171 if (sb) strbuf_addch(sb, (c)); \
172 if (fp) fputc((c), fp); \
173 count++; \
174 } while (0)
175#define EMITBUF(s, l) \
176 do { \
177 if (sb) strbuf_add(sb, (s), (l)); \
178 if (fp) fwrite((s), (l), 1, fp); \
179 count += (l); \
180 } while (0)
181
182 size_t len, count = 0;
183 const char *p = name;
4f6fbcdc 184
663af342
PH
185 for (;;) {
186 int ch;
4f6fbcdc 187
663af342
PH
188 len = next_quote_pos(p, maxlen);
189 if (len == maxlen || !p[len])
50e7b067 190 break;
663af342
PH
191
192 if (!no_dq && p == name)
193 EMIT('"');
194
195 EMITBUF(p, len);
196 EMIT('\\');
197 p += len;
198 ch = (unsigned char)*p++;
199 if (sq_lookup[ch] >= ' ') {
200 EMIT(sq_lookup[ch]);
201 } else {
202 EMIT(((ch >> 6) & 03) + '0');
203 EMIT(((ch >> 3) & 07) + '0');
204 EMIT(((ch >> 0) & 07) + '0');
4f6fbcdc 205 }
4f6fbcdc 206 }
663af342
PH
207
208 EMITBUF(p, len);
209 if (p == name) /* no ending quote needed */
210 return 0;
211
4f6fbcdc
JH
212 if (!no_dq)
213 EMIT('"');
663af342
PH
214 return count;
215}
4f6fbcdc 216
663af342
PH
217size_t quote_c_style(const char *name, struct strbuf *sb, FILE *fp, int nodq)
218{
219 return quote_c_style_counted(name, -1, sb, fp, nodq);
4f6fbcdc
JH
220}
221
663af342 222void write_name_quoted(const char *name, FILE *fp, int terminator)
9ef2b3cb 223{
663af342
PH
224 if (terminator) {
225 quote_c_style(name, NULL, fp, 0);
226 } else {
227 fputs(name, fp);
228 }
229 fputc(terminator, fp);
230}
231
232extern void write_name_quotedpfx(const char *pfx, size_t pfxlen,
233 const char *name, FILE *fp, int terminator)
234{
235 int needquote = 0;
236
237 if (terminator) {
238 needquote = next_quote_pos(pfx, pfxlen) < pfxlen
239 || name[next_quote_pos(name, -1)];
240 }
241 if (needquote) {
242 fputc('"', fp);
243 quote_c_style_counted(pfx, pfxlen, NULL, fp, 1);
244 quote_c_style(name, NULL, fp, 1);
245 fputc('"', fp);
246 } else {
247 fwrite(pfx, pfxlen, 1, fp);
248 fputs(name, fp);
249 }
250 fputc(terminator, fp);
9ef2b3cb
JH
251}
252
4f6fbcdc
JH
253/*
254 * C-style name unquoting.
255 *
7fb1011e
PH
256 * Quoted should point at the opening double quote.
257 * + Returns 0 if it was able to unquote the string properly, and appends the
258 * result in the strbuf `sb'.
259 * + Returns -1 in case of error, and doesn't touch the strbuf. Though note
260 * that this function will allocate memory in the strbuf, so calling
261 * strbuf_release is mandatory whichever result unquote_c_style returns.
262 *
263 * Updates endp pointer to point at one past the ending double quote if given.
4f6fbcdc 264 */
7fb1011e 265int unquote_c_style(struct strbuf *sb, const char *quoted, const char **endp)
4f6fbcdc 266{
7fb1011e
PH
267 size_t oldlen = sb->len, len;
268 int ch, ac;
4f6fbcdc
JH
269
270 if (*quoted++ != '"')
7fb1011e
PH
271 return -1;
272
273 for (;;) {
274 len = strcspn(quoted, "\"\\");
275 strbuf_add(sb, quoted, len);
276 quoted += len;
4f6fbcdc 277
7fb1011e
PH
278 switch (*quoted++) {
279 case '"':
280 if (endp)
281 *endp = quoted + 1;
282 return 0;
283 case '\\':
284 break;
285 default:
286 goto error;
287 }
288
289 switch ((ch = *quoted++)) {
290 case 'a': ch = '\a'; break;
291 case 'b': ch = '\b'; break;
292 case 'f': ch = '\f'; break;
293 case 'n': ch = '\n'; break;
294 case 'r': ch = '\r'; break;
295 case 't': ch = '\t'; break;
296 case 'v': ch = '\v'; break;
297
298 case '\\': case '"':
299 break; /* verbatim */
300
301 /* octal values with first digit over 4 overflow */
302 case '0': case '1': case '2': case '3':
4f6fbcdc 303 ac = ((ch - '0') << 6);
7fb1011e
PH
304 if ((ch = *quoted++) < '0' || '7' < ch)
305 goto error;
4f6fbcdc 306 ac |= ((ch - '0') << 3);
7fb1011e
PH
307 if ((ch = *quoted++) < '0' || '7' < ch)
308 goto error;
4f6fbcdc
JH
309 ac |= (ch - '0');
310 ch = ac;
311 break;
312 default:
7fb1011e 313 goto error;
4f6fbcdc 314 }
7fb1011e 315 strbuf_addch(sb, ch);
4f6fbcdc
JH
316 }
317
7fb1011e
PH
318 error:
319 strbuf_setlen(sb, oldlen);
320 return -1;
4f6fbcdc
JH
321}
322
9f613ddd
JH
323/* quoting as a string literal for other languages */
324
325void perl_quote_print(FILE *stream, const char *src)
326{
327 const char sq = '\'';
328 const char bq = '\\';
329 char c;
330
331 fputc(sq, stream);
332 while ((c = *src++)) {
333 if (c == sq || c == bq)
334 fputc(bq, stream);
335 fputc(c, stream);
336 }
337 fputc(sq, stream);
338}
339
340void python_quote_print(FILE *stream, const char *src)
341{
342 const char sq = '\'';
343 const char bq = '\\';
344 const char nl = '\n';
345 char c;
346
347 fputc(sq, stream);
348 while ((c = *src++)) {
349 if (c == nl) {
350 fputc(bq, stream);
351 fputc('n', stream);
352 continue;
353 }
354 if (c == sq || c == bq)
355 fputc(bq, stream);
356 fputc(c, stream);
357 }
358 fputc(sq, stream);
359}
5558e55c
SP
360
361void tcl_quote_print(FILE *stream, const char *src)
362{
363 char c;
364
365 fputc('"', stream);
366 while ((c = *src++)) {
367 switch (c) {
368 case '[': case ']':
369 case '{': case '}':
370 case '$': case '\\': case '"':
371 fputc('\\', stream);
372 default:
373 fputc(c, stream);
374 break;
375 case '\f':
376 fputs("\\f", stream);
377 break;
378 case '\r':
379 fputs("\\r", stream);
380 break;
381 case '\n':
382 fputs("\\n", stream);
383 break;
384 case '\t':
385 fputs("\\t", stream);
386 break;
387 case '\v':
388 fputs("\\v", stream);
389 break;
390 }
391 }
392 fputc('"', stream);
393}