fsck: use strbuf to generate alternate directories

When fsck-ing alternates, we make a copy of the alternate directory in a fixed PATH_MAX buffer. We memcpy directly, without any check whether we are overflowing the buffer. This is OK if PATH_MAX is a true representation of the maximum path on the system, because any path here will have already been vetted by the alternates subsystem. But that is not true on every system, so we should be more careful. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Sep 24, 2015 at 17:05 UTC c1fd0809174a31edd17e97c1161e01907f41a4fc
1 file changed +6 -5
builtin/fsck.c
+6 -5
@@ -683,11 +683,12 @@ int cmd_fsck(int argc, const char **argv, const char *prefix)
683
684 prepare_alt_odb();
685 for (alt = alt_odb_list; alt; alt = alt->next) {
686 - char namebuf[PATH_MAX];
687 - int namelen = alt->name - alt->base;
688 - memcpy(namebuf, alt->base, namelen);
689 - namebuf[namelen - 1] = 0;
690 - fsck_object_dir(namebuf);
686 + /* directory name, minus trailing slash */
687 + size_t namelen = alt->name - alt->base - 1;
688 + struct strbuf name = STRBUF_INIT;
689 + strbuf_add(&name, alt->base, namelen);
690 + fsck_object_dir(name.buf);
691 + strbuf_release(&name);
692 }
693 }
694