pretty: avoid reading past end-of-string with "%G"

If the user asks for --format=%G with nothing else, we correctly realize that "%G" is not a valid placeholder (it should be "%G?", "%GK", etc). But we still tell the strbuf_expand code that we consumed 2 characters, causing it to jump over the trailing NUL and output garbage. This also fixes the case where "%GX" would be consumed (and produce no output). In other cases, we pass unrecognized placeholders through to the final string. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Jun 16, 2014 at 20:07 UTC aa4b78d483a918ebee810993e420b4697b0de4d3
2 files changed +8
pretty.c
+2
@@ -1267,6 +1267,8 @@ static size_t format_commit_one(struct strbuf *sb, /* in UTF-8 */
1267 if (c->signature_check.key)
1268 strbuf_addstr(sb, c->signature_check.key);
1269 break;
1270 + default:
1271 + return 0;
1272 }
1273 return 2;
1274 }
t/t7510-signed-commit.sh
+6
@@ -147,4 +147,10 @@ test_expect_success GPG 'show lack of signature with custom format' '
147 test_cmp expect actual
148 '
149
150 +test_expect_success 'unused %G placeholders are passed through' '
151 + echo "%GX %G" >expect &&
152 + git log -1 --format="%GX %G" >actual &&
153 + test_cmp expect actual
154 +'
155 +
156 test_done