builtin/commit.c: switch to strbuf, instead of snprintf()

Switch to dynamic allocation with strbuf, so we can avoid dealing with magic numbers in the code and reduce the cognitive burden from the programmers. The original code is correct, but programmers no longer have to count bytes needed for static allocation to know that. As a side effect of this change, we also reduce the snprintf() calls, that may silently truncate results if the programmer is not careful. Helped-by: René Scharfe <l.s.r@web.de> Helped-by: Junio C Hamano <gitster@pobox.com> Helped-by: Jeff King <peff@peff.net> Signed-off-by: Elia Pinto <gitter.spiros@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Elia Pinto committed Jan 31, 2017 at 13:45 UTC 4a5281917b2b84affa9942c991419115088aec0e
1 file changed +4 -6
builtin/commit.c
+4 -6
@@ -1525,12 +1525,10 @@ static int git_commit_config(const char *k, const char *v, void *cb)
1525 static int run_rewrite_hook(const unsigned char *oldsha1,
1526 const unsigned char *newsha1)
1527 {
1528 - /* oldsha1 SP newsha1 LF NUL */
1529 - static char buf[2*40 + 3];
1528 struct child_process proc = CHILD_PROCESS_INIT;
1529 const char *argv[3];
1530 int code;
1533 - size_t n;
1531 + struct strbuf sb = STRBUF_INIT;
1532
1533 argv[0] = find_hook("post-rewrite");
1534 if (!argv[0])
@@ -1546,11 +1544,11 @@ static int run_rewrite_hook(const unsigned char *oldsha1,
1544 code = start_command(&proc);
1545 if (code)
1546 return code;
1549 - n = snprintf(buf, sizeof(buf), "%s %s\n",
1550 - sha1_to_hex(oldsha1), sha1_to_hex(newsha1));
1547 + strbuf_addf(&sb, "%s %s\n", sha1_to_hex(oldsha1), sha1_to_hex(newsha1));
1548 sigchain_push(SIGPIPE, SIG_IGN);
1552 - write_in_full(proc.in, buf, n);
1549 + write_in_full(proc.in, sb.buf, sb.len);
1550 close(proc.in);
1551 + strbuf_release(&sb);
1552 sigchain_pop(SIGPIPE);
1553 return finish_command(&proc);
1554 }