ref-filter: drop sprintf and strcpy calls

The ref-filter code comes from for-each-ref, and inherited a number of raw sprintf and strcpy calls. These are generally all safe, as we custom-size the buffers, or are formatting numbers into sufficiently large buffers. But we can make the resulting code even simpler and more obviously correct by using some of our helper functions. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Sep 24, 2015 at 17:07 UTC a5e03bf5c686e9f2da5e94e091e0ea531d40c6b8
1 file changed +22 -48
ref-filter.c
+22 -48
@@ -192,9 +192,7 @@ static int grab_objectname(const char *name, const unsigned char *sha1,
192 struct atom_value *v)
193 {
194 if (!strcmp(name, "objectname")) {
195 - char *s = xmalloc(41);
196 - strcpy(s, sha1_to_hex(sha1));
197 - v->s = s;
195 + v->s = xstrdup(sha1_to_hex(sha1));
196 return 1;
197 }
198 if (!strcmp(name, "objectname:short")) {
@@ -219,10 +217,8 @@ static void grab_common_values(struct atom_value *val, int deref, struct object
217 if (!strcmp(name, "objecttype"))
218 v->s = typename(obj->type);
219 else if (!strcmp(name, "objectsize")) {
222 - char *s = xmalloc(40);
223 - sprintf(s, "%lu", sz);
220 v->ul = sz;
225 - v->s = s;
221 + v->s = xstrfmt("%lu", sz);
222 }
223 else if (deref)
224 grab_objectname(name, obj->sha1, v);
@@ -246,11 +242,8 @@ static void grab_tag_values(struct atom_value *val, int deref, struct object *ob
242 v->s = tag->tag;
243 else if (!strcmp(name, "type") && tag->tagged)
244 v->s = typename(tag->tagged->type);
249 - else if (!strcmp(name, "object") && tag->tagged) {
250 - char *s = xmalloc(41);
251 - strcpy(s, sha1_to_hex(tag->tagged->sha1));
252 - v->s = s;
253 - }
245 + else if (!strcmp(name, "object") && tag->tagged)
246 + v->s = xstrdup(sha1_to_hex(tag->tagged->sha1));
247 }
248 }
249
@@ -268,32 +261,22 @@ static void grab_commit_values(struct atom_value *val, int deref, struct object
261 if (deref)
262 name++;
263 if (!strcmp(name, "tree")) {
271 - char *s = xmalloc(41);
272 - strcpy(s, sha1_to_hex(commit->tree->object.sha1));
273 - v->s = s;
264 + v->s = xstrdup(sha1_to_hex(commit->tree->object.sha1));
265 }
275 - if (!strcmp(name, "numparent")) {
276 - char *s = xmalloc(40);
266 + else if (!strcmp(name, "numparent")) {
267 v->ul = commit_list_count(commit->parents);
278 - sprintf(s, "%lu", v->ul);
279 - v->s = s;
268 + v->s = xstrfmt("%lu", v->ul);
269 }
270 else if (!strcmp(name, "parent")) {
282 - int num = commit_list_count(commit->parents);
283 - int i;
271 struct commit_list *parents;
285 - char *s = xmalloc(41 * num + 1);
286 - v->s = s;
287 - for (i = 0, parents = commit->parents;
288 - parents;
289 - parents = parents->next, i = i + 41) {
272 + struct strbuf s = STRBUF_INIT;
273 + for (parents = commit->parents; parents; parents = parents->next) {
274 struct commit *parent = parents->item;
291 - strcpy(s+i, sha1_to_hex(parent->object.sha1));
292 - if (parents->next)
293 - s[i+40] = ' ';
275 + if (parents != commit->parents)
276 + strbuf_addch(&s, ' ');
277 + strbuf_addstr(&s, sha1_to_hex(parent->object.sha1));
278 }
295 - if (!i)
296 - *s = '\0';
279 + v->s = strbuf_detach(&s, NULL);
280 }
281 }
282 }
@@ -700,7 +683,6 @@ static void populate_value(struct ref_array_item *ref)
683 else if (!strcmp(formatp, "track") &&
684 (starts_with(name, "upstream") ||
685 starts_with(name, "push"))) {
703 - char buf[40];
686
687 if (stat_tracking_info(branch, &num_ours,
688 &num_theirs, NULL))
@@ -708,17 +690,13 @@ static void populate_value(struct ref_array_item *ref)
690
691 if (!num_ours && !num_theirs)
692 v->s = "";
711 - else if (!num_ours) {
712 - sprintf(buf, "[behind %d]", num_theirs);
713 - v->s = xstrdup(buf);
714 - } else if (!num_theirs) {
715 - sprintf(buf, "[ahead %d]", num_ours);
716 - v->s = xstrdup(buf);
717 - } else {
718 - sprintf(buf, "[ahead %d, behind %d]",
719 - num_ours, num_theirs);
720 - v->s = xstrdup(buf);
721 - }
693 + else if (!num_ours)
694 + v->s = xstrfmt("[behind %d]", num_theirs);
695 + else if (!num_theirs)
696 + v->s = xstrfmt("[ahead %d]", num_ours);
697 + else
698 + v->s = xstrfmt("[ahead %d, behind %d]",
699 + num_ours, num_theirs);
700 continue;
701 } else if (!strcmp(formatp, "trackshort") &&
702 (starts_with(name, "upstream") ||
@@ -745,12 +723,8 @@ static void populate_value(struct ref_array_item *ref)
723
724 if (!deref)
725 v->s = refname;
748 - else {
749 - int len = strlen(refname);
750 - char *s = xmalloc(len + 4);
751 - sprintf(s, "%s^{}", refname);
752 - v->s = s;
753 - }
726 + else
727 + v->s = xstrfmt("%s^{}", refname);
728 }
729
730 for (i = 0; i < used_atom_cnt; i++) {