use_pack: handle signed off_t overflow
A v2 pack index file can specify an offset within a packfile of up to 2^64-1 bytes. On a system with a signed 64-bit off_t, we can represent only up to 2^63-1. This means that a corrupted .idx file can end up with a negative offset in the pack code. Our bounds-checking use_pack function looks for too-large offsets, but not for ones that have wrapped around to negative. Let's do so, which fixes an out-of-bounds access demonstrated in t5313. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Feb 25, 2016 at 09:23 UTC
13e0b0d3dc76353632dcb0bc63cdf03426154317
2 files changed
+3
-1
sha1_file.c
+2
@@ -1041,6 +1041,8 @@ unsigned char *use_pack(struct packed_git *p,
1041
die("packfile %s cannot be accessed", p->pack_name);
1042
if (offset > (p->pack_size - 20))
1043
die("offset beyond end of packfile (truncated pack?)");
1044
+ if (offset < 0)
1045
+ die("offset before end of packfile (broken .idx?)");
1046
1047
if (!win || !in_window(win, offset)) {
1048
if (win)
t/t5313-pack-bounds-checks.sh
+1
-1
@@ -136,7 +136,7 @@ test_expect_success 'bogus offset into v2 extended table' '
136
test_must_fail git index-pack --verify $pack
137
'
138
139
-test_expect_failure 'bogus offset inside v2 extended table' '
139
+test_expect_success 'bogus offset inside v2 extended table' '
140
# We need two objects here, so we can plausibly require
141
# an extended table (if the first object were larger than 2^31).
142
do_pack "$object $(git rev-parse HEAD)" --index-version=2 &&