hash-object --literally: fix buffer overrun with extra-long object type
"hash-object" learned in 5ba9a93 (hash-object: add --literally option, 2014-09-11) to allow crafting a corrupt/broken object of unknown type. When the user-provided type is particularly long, however, it can overflow the relatively small stack-based character array handed to write_sha1_file_prepare() by hash_sha1_file() and write_sha1_file(), leading to stack corruption (and crash). Introduce a custom helper to allow arbitrarily long typenames just for "hash-object --literally". [jc: Eric's original used a strbuf in the more common codepaths, and I rewrote it to avoid penalizing the non-literally code. Bugs are mine] Signed-off-by: Eric Sunshine <sunshine@sunshineco.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Eric Sunshine committed
May 4, 2015 at 03:25 UTC
0c3db67cc8137cebea5b1a9c3c7fc379ef8ffda6
3 files changed
+23
-3
builtin/hash-object.c
+1
-3
@@ -22,10 +22,8 @@ static int hash_literally(unsigned char *sha1, int fd, const char *type, unsigne
22
23
if (strbuf_read(&buf, fd, 4096) < 0)
24
ret = -1;
25
- else if (flags & HASH_WRITE_OBJECT)
26
- ret = write_sha1_file(buf.buf, buf.len, type, sha1);
25
else
28
- ret = hash_sha1_file(buf.buf, buf.len, type, sha1);
26
+ ret = hash_sha1_file_literally(buf.buf, buf.len, type, sha1, flags);
27
strbuf_release(&buf);
28
return ret;
29
}
cache.h
+1
@@ -888,6 +888,7 @@ static inline const unsigned char *lookup_replace_object_extended(const unsigned
888
extern int sha1_object_info(const unsigned char *, unsigned long *);
889
extern int hash_sha1_file(const void *buf, unsigned long len, const char *type, unsigned char *sha1);
890
extern int write_sha1_file(const void *buf, unsigned long len, const char *type, unsigned char *return_sha1);
891
+extern int hash_sha1_file_literally(const void *buf, unsigned long len, const char *type, unsigned char *sha1, unsigned flags);
892
extern int pretend_sha1_file(void *, unsigned long, enum object_type, unsigned char *);
893
extern int force_object_loose(const unsigned char *sha1, time_t mtime);
894
extern int git_open_noatime(const char *name);
sha1_file.c
+21
@@ -2962,6 +2962,27 @@ int write_sha1_file(const void *buf, unsigned long len, const char *type, unsign
2962
return write_loose_object(sha1, hdr, hdrlen, buf, len, 0);
2963
}
2964
2965
+int hash_sha1_file_literally(const void *buf, unsigned long len, const char *type,
2966
+ unsigned char *sha1, unsigned flags)
2967
+{
2968
+ char *header;
2969
+ int hdrlen, status = 0;
2970
+
2971
+ /* type string, SP, %lu of the length plus NUL must fit this */
2972
+ header = xmalloc(strlen(type) + 32);
2973
+ write_sha1_file_prepare(buf, len, type, sha1, header, &hdrlen);
2974
+
2975
+ if (!(flags & HASH_WRITE_OBJECT))
2976
+ goto cleanup;
2977
+ if (has_sha1_file(sha1))
2978
+ goto cleanup;
2979
+ status = write_loose_object(sha1, header, hdrlen, buf, len, 0);
2980
+
2981
+cleanup:
2982
+ free(header);
2983
+ return status;
2984
+}
2985
+
2986
int force_object_loose(const unsigned char *sha1, time_t mtime)
2987
{
2988
void *buf;