use strip_suffix and xstrfmt to replace suffix

When we want to convert "foo.pack" to "foo.idx", we do it by duplicating the original string and then munging the bytes in place. Let's use strip_suffix and xstrfmt instead, which has several advantages: 1. It's more clear what the intent is. 2. It does not implicitly rely on the fact that strlen(".idx") <= strlen(".pack") to avoid an overflow. 3. We communicate the assumption that the input file ends with ".pack" (and get a run-time check that this is so). 4. We drop calls to strcpy, which makes auditing the code base easier. Likewise, we can do this to convert ".pack" to ".bitmap", avoiding some manual memory computation. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Sep 24, 2015 at 17:07 UTC 9ae97018fb2e7f30ab92fdc2965d1dcff2c5c296
3 files changed +12 -14
http.c
+4 -3
@@ -1511,6 +1511,7 @@ int finish_http_pack_request(struct http_pack_request *preq)
1511 struct packed_git **lst;
1512 struct packed_git *p = preq->target;
1513 char *tmp_idx;
1514 + size_t len;
1515 struct child_process ip = CHILD_PROCESS_INIT;
1516 const char *ip_argv[8];
1517
@@ -1524,9 +1525,9 @@ int finish_http_pack_request(struct http_pack_request *preq)
1525 lst = &((*lst)->next);
1526 *lst = (*lst)->next;
1527
1527 - tmp_idx = xstrdup(preq->tmpfile);
1528 - strcpy(tmp_idx + strlen(tmp_idx) - strlen(".pack.temp"),
1529 - ".idx.temp");
1528 + if (!strip_suffix(preq->tmpfile, ".pack.temp", &len))
1529 + die("BUG: pack tmpfile does not end in .pack.temp?");
1530 + tmp_idx = xstrfmt("%.*s.idx.temp", (int)len, preq->tmpfile);
1531
1532 ip_argv[0] = "index-pack";
1533 ip_argv[1] = "-o";
pack-bitmap.c
+4 -9
@@ -252,16 +252,11 @@ static int load_bitmap_entries_v1(struct bitmap_index *index)
252
253 static char *pack_bitmap_filename(struct packed_git *p)
254 {
255 - char *idx_name;
256 - int len;
257 -
258 - len = strlen(p->pack_name) - strlen(".pack");
259 - idx_name = xmalloc(len + strlen(".bitmap") + 1);
260 -
261 - memcpy(idx_name, p->pack_name, len);
262 - memcpy(idx_name + len, ".bitmap", strlen(".bitmap") + 1);
255 + size_t len;
256
264 - return idx_name;
257 + if (!strip_suffix(p->pack_name, ".pack", &len))
258 + die("BUG: pack_name does not end in .pack");
259 + return xstrfmt("%.*s.bitmap", (int)len, p->pack_name);
260 }
261
262 static int open_pack_bitmap_1(struct packed_git *packfile)
sha1_file.c
+4 -2
@@ -671,13 +671,15 @@ static int check_packed_git_idx(const char *path, struct packed_git *p)
671 int open_pack_index(struct packed_git *p)
672 {
673 char *idx_name;
674 + size_t len;
675 int ret;
676
677 if (p->index_data)
678 return 0;
679
679 - idx_name = xstrdup(p->pack_name);
680 - strcpy(idx_name + strlen(idx_name) - strlen(".pack"), ".idx");
680 + if (!strip_suffix(p->pack_name, ".pack", &len))
681 + die("BUG: pack_name does not end in .pack");
682 + idx_name = xstrfmt("%.*s.idx", (int)len, p->pack_name);
683 ret = check_packed_git_idx(idx_name, p);
684 free(idx_name);
685 return ret;