pretty: avoid reading past end-of-string with "%G"
If the user asks for --format=%G with nothing else, we correctly realize that "%G" is not a valid placeholder (it should be "%G?", "%GK", etc). But we still tell the strbuf_expand code that we consumed 2 characters, causing it to jump over the trailing NUL and output garbage. This also fixes the case where "%GX" would be consumed (and produce no output). In other cases, we pass unrecognized placeholders through to the final string. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Jun 16, 2014 at 20:07 UTC
aa4b78d483a918ebee810993e420b4697b0de4d3
2 files changed
+8
pretty.c
+2
@@ -1267,6 +1267,8 @@ static size_t format_commit_one(struct strbuf *sb, /* in UTF-8 */
1267
if (c->signature_check.key)
1268
strbuf_addstr(sb, c->signature_check.key);
1269
break;
1270
+ default:
1271
+ return 0;
1272
}
1273
return 2;
1274
}
t/t7510-signed-commit.sh
+6
@@ -147,4 +147,10 @@ test_expect_success GPG 'show lack of signature with custom format' '
147
test_cmp expect actual
148
'
149
150
+test_expect_success 'unused %G placeholders are passed through' '
151
+ echo "%GX %G" >expect &&
152
+ git log -1 --format="%GX %G" >actual &&
153
+ test_cmp expect actual
154
+'
155
+
156
test_done