index-pack: terminate object buffers with NUL

We have some tricky checks in fsck that rely on a side effect of require_end_of_header(), and would otherwise easily run outside non-NUL-terminated buffers. This is a bit brittle, so let's make sure that only NUL-terminated buffers are passed around to begin with. Jeff "Peff" King contributed the detailed analysis which call paths are involved and pointed out that we also have to patch the get_data() function in unpack-objects.c, which is what Johannes "Dscho" Schindelin implemented. Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com> Analyzed-by: Jeff King <peff@peff.net> Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Duy Nguyen committed Dec 8, 2014 at 15:17 UTC a1e920a0a7747f0820e62b22b67fd36fb1d74607
2 files changed +3 -3
builtin/index-pack.c
+2 -2
@@ -438,7 +438,7 @@ static void *unpack_entry_data(unsigned long offset, unsigned long size,
438 if (type == OBJ_BLOB && size > big_file_threshold)
439 buf = fixed_buf;
440 else
441 - buf = xmalloc(size);
441 + buf = xmallocz(size);
442
443 memset(&stream, 0, sizeof(stream));
444 git_inflate_init(&stream);
@@ -543,7 +543,7 @@ static void *unpack_data(struct object_entry *obj,
543 git_zstream stream;
544 int status;
545
546 - data = xmalloc(consume ? 64*1024 : obj->size);
546 + data = xmallocz(consume ? 64*1024 : obj->size);
547 inbuf = xmalloc((len < 64*1024) ? len : 64*1024);
548
549 memset(&stream, 0, sizeof(stream));
builtin/unpack-objects.c
+1 -1
@@ -91,7 +91,7 @@ static void use(int bytes)
91 static void *get_data(unsigned long size)
92 {
93 git_zstream stream;
94 - void *buf = xmalloc(size);
94 + void *buf = xmallocz(size);
95
96 memset(&stream, 0, sizeof(stream));
97