path.c: make get_pathname() call sites return const char *

Before the previous commit, get_pathname returns an array of PATH_MAX length. Even if git_path() and similar functions does not use the whole array, git_path() caller can, in theory. After the commit, get_pathname() may return a buffer that has just enough room for the returned string and git_path() caller should never write beyond that. Make git_path(), mkpath() and git_path_submodule() return a const buffer to make sure callers do not write in it at all. This could have been part of the previous commit, but the "const" conversion is too much distraction from the core changes in path.c. Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Nguyễn Thái Ngọc Duy committed Nov 30, 2014 at 15:24 UTC dcf692625ac569fefbe52269061230f4fde10e47
15 files changed +36 -32
builtin/checkout.c
+1 -1
@@ -589,7 +589,7 @@ static void update_refs_for_switch(const struct checkout_opts *opts,
589 if (opts->new_branch_log && !log_all_ref_updates) {
590 int temp;
591 char log_file[PATH_MAX];
592 - char *ref_name = mkpath("refs/heads/%s", opts->new_orphan_branch);
592 + const char *ref_name = mkpath("refs/heads/%s", opts->new_orphan_branch);
593
594 temp = log_all_ref_updates;
595 log_all_ref_updates = 1;
builtin/clone.c
+5 -4
@@ -290,16 +290,17 @@ static void copy_alternates(struct strbuf *src, struct strbuf *dst,
290 struct strbuf line = STRBUF_INIT;
291
292 while (strbuf_getline(&line, in, '\n') != EOF) {
293 - char *abs_path, abs_buf[PATH_MAX];
293 + char *abs_path;
294 if (!line.len || line.buf[0] == '#')
295 continue;
296 if (is_absolute_path(line.buf)) {
297 add_to_alternates_file(line.buf);
298 continue;
299 }
300 - abs_path = mkpath("%s/objects/%s", src_repo, line.buf);
301 - normalize_path_copy(abs_buf, abs_path);
302 - add_to_alternates_file(abs_buf);
300 + abs_path = mkpathdup("%s/objects/%s", src_repo, line.buf);
301 + normalize_path_copy(abs_path, abs_path);
302 + add_to_alternates_file(abs_path);
303 + free(abs_path);
304 }
305 strbuf_release(&line);
306 fclose(in);
builtin/fetch.c
+3 -2
@@ -587,7 +587,8 @@ static int store_updated_refs(const char *raw_url, const char *remote_name,
587 struct strbuf note = STRBUF_INIT;
588 const char *what, *kind;
589 struct ref *rm;
590 - char *url, *filename = dry_run ? "/dev/null" : git_path("FETCH_HEAD");
590 + char *url;
591 + const char *filename = dry_run ? "/dev/null" : git_path("FETCH_HEAD");
592 int want_status;
593
594 fp = fopen(filename, "a");
@@ -821,7 +822,7 @@ static void check_not_current_branch(struct ref *ref_map)
822
823 static int truncate_fetch_head(void)
824 {
824 - char *filename = git_path("FETCH_HEAD");
825 + const char *filename = git_path("FETCH_HEAD");
826 FILE *fp = fopen(filename, "w");
827
828 if (!fp)
builtin/fsck.c
+2 -2
@@ -225,12 +225,12 @@ static void check_unreachable_object(struct object *obj)
225 printf("dangling %s %s\n", typename(obj->type),
226 sha1_to_hex(obj->sha1));
227 if (write_lost_and_found) {
228 - char *filename = git_path("lost-found/%s/%s",
228 + const char *filename = git_path("lost-found/%s/%s",
229 obj->type == OBJ_COMMIT ? "commit" : "other",
230 sha1_to_hex(obj->sha1));
231 FILE *f;
232
233 - if (safe_create_leading_directories(filename)) {
233 + if (safe_create_leading_directories_const(filename)) {
234 error("Could not create lost-found");
235 return;
236 }
builtin/receive-pack.c
+1 -1
@@ -869,7 +869,7 @@ static void run_update_post_hook(struct command *commands)
869 int argc;
870 const char **argv;
871 struct child_process proc = CHILD_PROCESS_INIT;
872 - char *hook;
872 + const char *hook;
873
874 hook = find_hook("post-update");
875 for (argc = 0, cmd = commands; cmd; cmd = cmd->next) {
builtin/remote.c
+1 -1
@@ -582,7 +582,7 @@ static int migrate_file(struct remote *remote)
582 {
583 struct strbuf buf = STRBUF_INIT;
584 int i;
585 - char *path = NULL;
585 + const char *path = NULL;
586
587 strbuf_addf(&buf, "remote.%s.url", remote->name);
588 for (i = 0; i < remote->url_nr; i++)
builtin/repack.c
+5 -3
@@ -284,7 +284,8 @@ int cmd_repack(int argc, const char **argv, const char *prefix)
284 failed = 0;
285 for_each_string_list_item(item, &names) {
286 for (ext = 0; ext < ARRAY_SIZE(exts); ext++) {
287 - char *fname, *fname_old;
287 + const char *fname_old;
288 + char *fname;
289 fname = mkpathdup("%s/pack-%s%s", packdir,
290 item->string, exts[ext].name);
291 if (!file_exists(fname)) {
@@ -312,7 +313,8 @@ int cmd_repack(int argc, const char **argv, const char *prefix)
313 if (failed) {
314 struct string_list rollback_failure = STRING_LIST_INIT_DUP;
315 for_each_string_list_item(item, &rollback) {
315 - char *fname, *fname_old;
316 + const char *fname_old;
317 + char *fname;
318 fname = mkpathdup("%s/%s", packdir, item->string);
319 fname_old = mkpath("%s/old-%s", packdir, item->string);
320 if (rename(fname_old, fname))
@@ -365,7 +367,7 @@ int cmd_repack(int argc, const char **argv, const char *prefix)
367 /* Remove the "old-" files */
368 for_each_string_list_item(item, &names) {
369 for (ext = 0; ext < ARRAY_SIZE(exts); ext++) {
368 - char *fname;
370 + const char *fname;
371 fname = mkpath("%s/old-%s%s",
372 packdir,
373 item->string,
cache.h
+3 -3
@@ -687,9 +687,9 @@ extern char *mkpathdup(const char *fmt, ...)
687 __attribute__((format (printf, 1, 2)));
688
689 /* Return a statically allocated filename matching the sha1 signature */
690 -extern char *mkpath(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
691 -extern char *git_path(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
692 -extern char *git_path_submodule(const char *path, const char *fmt, ...)
690 +extern const char *mkpath(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
691 +extern const char *git_path(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
692 +extern const char *git_path_submodule(const char *path, const char *fmt, ...)
693 __attribute__((format (printf, 2, 3)));
694
695 /*
fast-import.c
+1 -1
@@ -405,7 +405,7 @@ static void dump_marks_helper(FILE *, uintmax_t, struct mark_set *);
405
406 static void write_crash_report(const char *err)
407 {
408 - char *loc = git_path("fast_import_crash_%"PRIuMAX, (uintmax_t) getpid());
408 + const char *loc = git_path("fast_import_crash_%"PRIuMAX, (uintmax_t) getpid());
409 FILE *rpt = fopen(loc, "w");
410 struct branch *b;
411 unsigned long lu;
notes-merge.c
+3 -3
@@ -280,7 +280,7 @@ static void check_notes_merge_worktree(struct notes_merge_options *o)
280 "(%s exists).", git_path("NOTES_MERGE_*"));
281 }
282
283 - if (safe_create_leading_directories(git_path(
283 + if (safe_create_leading_directories_const(git_path(
284 NOTES_MERGE_WORKTREE "/.test")))
285 die_errno("unable to create directory %s",
286 git_path(NOTES_MERGE_WORKTREE));
@@ -295,8 +295,8 @@ static void write_buf_to_worktree(const unsigned char *obj,
295 const char *buf, unsigned long size)
296 {
297 int fd;
298 - char *path = git_path(NOTES_MERGE_WORKTREE "/%s", sha1_to_hex(obj));
299 - if (safe_create_leading_directories(path))
298 + const char *path = git_path(NOTES_MERGE_WORKTREE "/%s", sha1_to_hex(obj));
299 + if (safe_create_leading_directories_const(path))
300 die_errno("unable to create directory for '%s'", path);
301 if (file_exists(path))
302 die("found existing file at '%s'", path);
path.c
+3 -3
@@ -106,7 +106,7 @@ char *mkpathdup(const char *fmt, ...)
106 return strbuf_detach(&sb, NULL);
107 }
108
109 -char *mkpath(const char *fmt, ...)
109 +const char *mkpath(const char *fmt, ...)
110 {
111 va_list args;
112 struct strbuf *pathname = get_pathname();
@@ -116,7 +116,7 @@ char *mkpath(const char *fmt, ...)
116 return cleanup_path(pathname->buf);
117 }
118
119 -char *git_path(const char *fmt, ...)
119 +const char *git_path(const char *fmt, ...)
120 {
121 struct strbuf *pathname = get_pathname();
122 va_list args;
@@ -154,7 +154,7 @@ void home_config_paths(char **global, char **xdg, char *file)
154 free(to_free);
155 }
156
157 -char *git_path_submodule(const char *path, const char *fmt, ...)
157 +const char *git_path_submodule(const char *path, const char *fmt, ...)
158 {
159 struct strbuf *buf = get_pathname();
160 const char *git_dir;
refs.c
+4 -4
@@ -1351,7 +1351,7 @@ static int resolve_gitlink_ref_recursive(struct ref_cache *refs,
1351 {
1352 int fd, len;
1353 char buffer[128], *p;
1354 - char *path;
1354 + const char *path;
1355
1356 if (recursion > MAXDEPTH || strlen(refname) > MAXREFLEN)
1357 return -1;
@@ -2229,7 +2229,7 @@ static struct ref_lock *lock_ref_sha1_basic(const char *refname,
2229 const struct string_list *skip,
2230 int flags, int *type_p)
2231 {
2232 - char *ref_file;
2232 + const char *ref_file;
2233 const char *orig_refname = refname;
2234 struct ref_lock *lock;
2235 int last_errno = 0;
@@ -2303,7 +2303,7 @@ static struct ref_lock *lock_ref_sha1_basic(const char *refname,
2303 lock->force_write = 1;
2304
2305 retry:
2306 - switch (safe_create_leading_directories(ref_file)) {
2306 + switch (safe_create_leading_directories_const(ref_file)) {
2307 case SCLD_OK:
2308 break; /* success */
2309 case SCLD_VANISHED:
@@ -2743,7 +2743,7 @@ static int rename_tmp_log(const char *newrefname)
2743 int attempts_remaining = 4;
2744
2745 retry:
2746 - switch (safe_create_leading_directories(git_path("logs/%s", newrefname))) {
2746 + switch (safe_create_leading_directories_const(git_path("logs/%s", newrefname))) {
2747 case SCLD_OK:
2748 break; /* success */
2749 case SCLD_VANISHED:
run-command.c
+2 -2
@@ -794,9 +794,9 @@ int finish_async(struct async *async)
794 #endif
795 }
796
797 -char *find_hook(const char *name)
797 +const char *find_hook(const char *name)
798 {
799 - char *path = git_path("hooks/%s", name);
799 + const char *path = git_path("hooks/%s", name);
800 if (access(path, X_OK) < 0)
801 path = NULL;
802
run-command.h
+1 -1
@@ -52,7 +52,7 @@ int start_command(struct child_process *);
52 int finish_command(struct child_process *);
53 int run_command(struct child_process *);
54
55 -extern char *find_hook(const char *name);
55 +extern const char *find_hook(const char *name);
56 LAST_ARG_MUST_BE_NULL
57 extern int run_hook_le(const char *const *env, const char *name, ...);
58 extern int run_hook_ve(const char *const *env, const char *name, va_list args);
sha1_file.c
+1 -1
@@ -405,7 +405,7 @@ void add_to_alternates_file(const char *reference)
405 {
406 struct lock_file *lock = xcalloc(1, sizeof(struct lock_file));
407 int fd = hold_lock_file_for_append(lock, git_path("objects/info/alternates"), LOCK_DIE_ON_ERROR);
408 - char *alt = mkpath("%s\n", reference);
408 + const char *alt = mkpath("%s\n", reference);
409 write_or_die(fd, alt, strlen(alt));
410 if (commit_lock_file(lock))
411 die("could not close alternates file");