t5303: test some corrupt deltas

We don't have any tests that specifically check boundary cases in patch_delta(). It obviously gets exercised by tests which read from packfiles, but it's hard to create packfiles with bogus deltas. So let's cover some obvious boundary cases: 1. commands that overflow the result buffer a. literal content from the delta b. copies from a base 2. commands where the source isn't large enough a. literal content from a truncated delta b. copies that need more bytes than the base has 3. copy commands who parameters are truncated And indeed, we have problems with both 2a and 3. I've marked these both as expect_failure, though note that because they involve reading past the end of a buffer, they will typically only be caught when run under valgrind or ASan. There's one more test here, too, which just applies a basic delta. Since all of the other tests expect failure and we don't otherwise use "test-tool delta" in the test suite, this gives a sanity check that the tool works at all. These are based on an earlier patch by Jann Horn <jannh@google.com>. Signed-off-by: Jeff King <peff@peff.net> Reviewed-by: Nicolas Pitre <nico@fluxnic.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Aug 30, 2018 at 03:09 UTC 9caf0107a86d11f059554e55c461f8e7657d89bf
1 file changed +59
t/t5303-pack-corruption-resilience.sh
+59
@@ -311,4 +311,63 @@ test_expect_success \
311 test_must_fail git cat-file blob $blob_2 > /dev/null &&
312 test_must_fail git cat-file blob $blob_3 > /dev/null'
313
314 +# \0 - empty base
315 +# \1 - one byte in result
316 +# \1 - one literal byte (X)
317 +test_expect_success \
318 + 'apply good minimal delta' \
319 + 'printf "\0\1\1X" > minimal_delta &&
320 + test-tool delta -p /dev/null minimal_delta /dev/null'
321 +
322 +# \0 - empty base
323 +# \1 - 1 byte in result
324 +# \2 - two literal bytes (one too many)
325 +test_expect_success \
326 + 'apply delta with too many literal bytes' \
327 + 'printf "\0\1\2XX" > too_big_literal &&
328 + test_must_fail test-tool delta -p /dev/null too_big_literal /dev/null'
329 +
330 +# \5 - five bytes in base
331 +# \1 - one byte in result
332 +# \221 - copy, one byte offset, one byte size
333 +# \0 - copy from offset 0
334 +# \2 - copy two bytes (one too many)
335 +test_expect_success \
336 + 'apply delta with too many copied bytes' \
337 + 'printf "\5\1\221\0\2" > too_big_copy &&
338 + echo base >base &&
339 + test_must_fail test-tool delta -p base too_big_copy /dev/null'
340 +
341 +# \0 - empty base
342 +# \2 - two bytes in result
343 +# \2 - two literal bytes (we are short one)
344 +test_expect_failure \
345 + 'apply delta with too few literal bytes' \
346 + 'printf "\0\2\2X" > truncated_delta &&
347 + test_must_fail test-tool delta -p /dev/null truncated_delta /dev/null'
348 +
349 +# \0 - empty base
350 +# \1 - one byte in result
351 +# \221 - copy, one byte offset, one byte size
352 +# \0 - copy from offset 0
353 +# \1 - copy one byte (we are short one)
354 +test_expect_success \
355 + 'apply delta with too few bytes in base' \
356 + 'printf "\0\1\221\0\1" > truncated_base &&
357 + test_must_fail test-tool delta -p /dev/null truncated_base /dev/null'
358 +
359 +# \5 - five bytes in base
360 +# \5 - five bytes in result
361 +# \1 - one literal byte (X)
362 +# \221 - copy, one byte offset, one byte size
363 +# (offset/size missing)
364 +#
365 +# Note that the literal byte is necessary to get past the uninteresting minimum
366 +# delta size check.
367 +test_expect_failure \
368 + 'apply delta with truncated copy parameters' \
369 + 'printf "\5\5\1X\221" > truncated_copy_delta &&
370 + echo base >base &&
371 + test_must_fail test-tool delta -p base truncated_copy_delta /dev/null'
372 +
373 test_done