]> git.ipfire.org Git - thirdparty/git.git/commitdiff
precompose_utf8: use a flex array for d_name
authorIhar Hrachyshka <ihar.hrachyshka@gmail.com>
Sat, 4 Jul 2026 23:37:24 +0000 (19:37 -0400)
committerJunio C Hamano <gitster@pobox.com>
Sun, 5 Jul 2026 00:59:36 +0000 (17:59 -0700)
On macOS, git status may abort while reading a directory entry
whose UTF-8 name grows past NAME_MAX bytes:

  __chk_fail_overflow
  __strlcpy_chk
  precompose_utf8_readdir
  read_directory_recursive
  wt_status_collect
  cmd_status

The precompose wrapper already reallocates dirent_prec_psx for
long names, but d_name is declared as char[NAME_MAX + 1]. A
fortified libc can still see that declared object size and reject a
larger strlcpy bound, even though the allocation was grown.

Make d_name a FLEX_ARRAY and size allocations from offsetof(). That
matches the actual object layout with the dynamic allocation, so the
fortified copy sees a destination whose size can grow with max_name_len.

Add a regression test that creates an over-NAME_MAX non-ASCII basename
and runs status with core.precomposeunicode enabled.

Signed-off-by: Ihar Hrachyshka <ihar.hrachyshka@gmail.com>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
compat/precompose_utf8.c
compat/precompose_utf8.h
t/t3910-mac-os-precompose.sh

index 43b3be011439ef9921b5c6a353526ff43116164f..69740c2ad7f2a67f443418c888791b671e025b5b 100644 (file)
@@ -19,6 +19,11 @@ typedef char *iconv_ibp;
 static const char *repo_encoding = "UTF-8";
 static const char *path_encoding = "UTF-8-MAC";
 
+static size_t dirent_prec_psx_size(size_t max_name_len)
+{
+       return st_add(offsetof(dirent_prec_psx, d_name), max_name_len);
+}
+
 static size_t has_non_ascii(const char *s, size_t maxlen, size_t *strlen_c)
 {
        const uint8_t *ptr = (const uint8_t *)s;
@@ -110,8 +115,8 @@ const char *precompose_argv_prefix(int argc, const char **argv, const char *pref
 PREC_DIR *precompose_utf8_opendir(const char *dirname)
 {
        PREC_DIR *prec_dir = xmalloc(sizeof(PREC_DIR));
-       prec_dir->dirent_nfc = xmalloc(sizeof(dirent_prec_psx));
-       prec_dir->dirent_nfc->max_name_len = sizeof(prec_dir->dirent_nfc->d_name);
+       prec_dir->dirent_nfc = xmalloc(dirent_prec_psx_size(NAME_MAX + 1));
+       prec_dir->dirent_nfc->max_name_len = NAME_MAX + 1;
 
        prec_dir->dirp = opendir(dirname);
        if (!prec_dir->dirp) {
@@ -139,8 +144,7 @@ struct dirent_prec_psx *precompose_utf8_readdir(PREC_DIR *prec_dir)
                int ret_errno = errno;
 
                if (new_maxlen > prec_dir->dirent_nfc->max_name_len) {
-                       size_t new_len = sizeof(dirent_prec_psx) + new_maxlen -
-                               sizeof(prec_dir->dirent_nfc->d_name);
+                       size_t new_len = dirent_prec_psx_size(new_maxlen);
 
                        prec_dir->dirent_nfc = xrealloc(prec_dir->dirent_nfc, new_len);
                        prec_dir->dirent_nfc->max_name_len = new_maxlen;
index fea06cf28a52dffacf1839d99b364d71f16b6461..c7c3cc211e503115c4496ea7da6bf93042bd6d20 100644 (file)
@@ -14,11 +14,12 @@ typedef struct dirent_prec_psx {
 
        /*
         * See http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/dirent.h.html
-        * NAME_MAX + 1 should be enough, but some systems have
-        * NAME_MAX=255 and strlen(d_name) may return 508 or 510
-        * Solution: allocate more when needed, see precompose_utf8_readdir()
+        * Start with room for NAME_MAX + 1 bytes, but keep d_name as a
+        * flexible array. Some systems have NAME_MAX=255 while strlen(d_name)
+        * from readdir() may return 508 or 510 bytes. Grow the allocation as
+        * needed in precompose_utf8_readdir().
         */
-       char   d_name[NAME_MAX+1];
+       char   d_name[FLEX_ARRAY];
 } dirent_prec_psx;
 
 
index 6d5918c8feaf9535da63ff801ca28da48d0a18d2..ea75fb490d1a2f247d2b1fcccdd59e4e8bad6d28 100755 (executable)
@@ -207,6 +207,22 @@ test_expect_success "Add long precomposed filename" '
        git commit -m "Long filename"
 '
 
+test_expect_success "status with long non-ASCII filename" '
+       test_when_finished "rm -rf long-utf8-status" &&
+       git init long-utf8-status &&
+       (
+               cd long-utf8-status &&
+               test "$(git config --bool core.precomposeunicode)" = true &&
+               long_utf8_name=$(
+                       printf "%253s\342\200\224" "" |
+                       tr " " a
+               ) &&
+               test "$(printf "%s" "$long_utf8_name" | wc -c | tr -d " ")" = 256 &&
+               printf "content\n" >"$long_utf8_name" &&
+               git status --porcelain=v1 >actual
+       )
+'
+
 test_expect_failure 'handle existing decomposed filenames' '
        echo content >"verbatim.$Adiarnfd" &&
        git -c core.precomposeunicode=false add "verbatim.$Adiarnfd" &&