load_subtree(): check that `prefix_len` is in the expected range

This value, which is stashed in the last byte of an object_id hash, gets handed around a lot. So add a sanity check before using it in `load_subtree()`. Signed-off-by: Michael Haggerty <mhagger@alum.mit.edu> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Michael Haggerty committed Sep 8, 2017 at 18:10 UTC 396428152413f431cac18f68a7190827b4acb3b6
1 file changed +4 -1
notes.c
+4 -1
@@ -417,7 +417,10 @@ static void load_subtree(struct notes_tree *t, struct leaf_node *subtree,
417 oid_to_hex(&subtree->val_oid));
418
419 prefix_len = subtree->key_oid.hash[KEY_INDEX];
420 - assert(prefix_len * 2 >= n);
420 + if (prefix_len >= GIT_SHA1_RAWSZ)
421 + BUG("prefix_len (%"PRIuMAX") is out of range", (uintmax_t)prefix_len);
422 + if (prefix_len * 2 < n)
423 + BUG("prefix_len (%"PRIuMAX") is too small", (uintmax_t)prefix_len);
424 memcpy(object_oid.hash, subtree->key_oid.hash, prefix_len);
425 while (tree_entry(&desc, &entry)) {
426 unsigned char type;