bundle-uri: avoid using undefined output of `sscanf()`

In c429bed102 (bundle-uri: store fetch.bundleCreationToken, 2023-01-31) code was introduced that assumes that an `sscanf()` call leaves its output variables unchanged unless the return value indicates success. However, the POSIX documentation makes no such guarantee: https://pubs.opengroup.org/onlinepubs/9699919799/functions/sscanf.html So let's make sure that the output variable `maxCreationToken` is always well-defined. Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Johannes Schindelin committed May 15, 2025 at 13:11 UTC d7cfbd4351bb304eefc09a8b1ba24fd40a9f36a0
1 file changed +7 -5
bundle-uri.c
+7 -5
@@ -532,11 +532,13 @@ static int fetch_bundles_by_token(struct repository *r,
532 */
533 if (!repo_config_get_value(r,
534 "fetch.bundlecreationtoken",
535 - &creationTokenStr) &&
536 - sscanf(creationTokenStr, "%"PRIu64, &maxCreationToken) == 1 &&
537 - bundles.items[0]->creationToken <= maxCreationToken) {
538 - free(bundles.items);
539 - return 0;
535 + &creationTokenStr)) {
536 + if (sscanf(creationTokenStr, "%"PRIu64, &maxCreationToken) != 1)
537 + maxCreationToken = 0;
538 + if (bundles.items[0]->creationToken <= maxCreationToken) {
539 + free(bundles.items);
540 + return 0;
541 + }
542 }
543
544 /*