receive-pack: do not overallocate command structure
An "update" command in the protocol exchange consists of 40-hex old object name, SP, 40-hex new object name, SP, and a refname, but the first instance is further followed by a NUL with feature requests. The command structure, which has a flex-array member that stores the refname at the end, was allocated based on the whole length of the update command, without excluding the trailing feature requests. Signed-off-by: Junio C Hamano <gitster@pobox.com>
Junio C Hamano committed
Aug 15, 2014 at 13:53 UTC
3bfcb95fa84d8bacb01a990c5bdb16df13462279
1 file changed
+3
-2
builtin/receive-pack.c
+3
-2
@@ -872,10 +872,11 @@ static struct command *read_head_info(struct sha1_array *shallow)
872
if (parse_feature_request(feature_list, "quiet"))
873
quiet = 1;
874
}
875
- cmd = xcalloc(1, sizeof(struct command) + len - 80);
875
+ cmd = xcalloc(1, sizeof(struct command) + reflen + 1);
876
hashcpy(cmd->old_sha1, old_sha1);
877
hashcpy(cmd->new_sha1, new_sha1);
878
- memcpy(cmd->ref_name, line + 82, len - 81);
878
+ memcpy(cmd->ref_name, refname, reflen);
879
+ cmd->ref_name[reflen] = '\0';
880
*p = cmd;
881
p = &cmd->next;
882
}