fast-import: fix buffer overflow in dump_tags

When creating a new annotated tag, we sprintf the refname into a static-sized buffer. If we have an absurdly long tagname, like: git init repo && cd repo && git commit --allow-empty -m foo && git tag -m message mytag && git fast-export mytag | perl -lpe '/^tag/ and s/mytag/"a" x 8192/e' | git fast-import <input we'll overflow the buffer. We can fix it by using a strbuf. Signed-off-by: Jeff King <peff@peff.net> Reviewed-by: Michael Haggerty <mhagger@alum.mit.edu> Reviewed-by: Ronnie Sahlberg <sahlberg@google.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Aug 23, 2014 at 01:32 UTC c252785982c268e5c969900c677322744d09f52e
1 file changed +6 -4
fast-import.c
+6 -4
@@ -1730,14 +1730,16 @@ static void dump_tags(void)
1730 static const char *msg = "fast-import";
1731 struct tag *t;
1732 struct ref_lock *lock;
1733 - char ref_name[PATH_MAX];
1733 + struct strbuf ref_name = STRBUF_INIT;
1734
1735 for (t = first_tag; t; t = t->next_tag) {
1736 - sprintf(ref_name, "tags/%s", t->name);
1737 - lock = lock_ref_sha1(ref_name, NULL);
1736 + strbuf_reset(&ref_name);
1737 + strbuf_addf(&ref_name, "tags/%s", t->name);
1738 + lock = lock_ref_sha1(ref_name.buf, NULL);
1739 if (!lock || write_ref_sha1(lock, t->sha1, msg) < 0)
1739 - failure |= error("Unable to update %s", ref_name);
1740 + failure |= error("Unable to update %s", ref_name.buf);
1741 }
1742 + strbuf_release(&ref_name);
1743 }
1744
1745 static void dump_marks_helper(FILE *f,