path.c: make get_pathname() call sites return const char *
Before the previous commit, get_pathname returns an array of PATH_MAX length. Even if git_path() and similar functions does not use the whole array, git_path() caller can, in theory. After the commit, get_pathname() may return a buffer that has just enough room for the returned string and git_path() caller should never write beyond that. Make git_path(), mkpath() and git_path_submodule() return a const buffer to make sure callers do not write in it at all. This could have been part of the previous commit, but the "const" conversion is too much distraction from the core changes in path.c. Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Nguyễn Thái Ngọc Duy committed
Nov 30, 2014 at 15:24 UTC
dcf692625ac569fefbe52269061230f4fde10e47
15 files changed
+36
-32
builtin/checkout.c
+1
-1
@@ -589,7 +589,7 @@ static void update_refs_for_switch(const struct checkout_opts *opts,
589
if (opts->new_branch_log && !log_all_ref_updates) {
590
int temp;
591
char log_file[PATH_MAX];
592
- char *ref_name = mkpath("refs/heads/%s", opts->new_orphan_branch);
592
+ const char *ref_name = mkpath("refs/heads/%s", opts->new_orphan_branch);
593
594
temp = log_all_ref_updates;
595
log_all_ref_updates = 1;
builtin/clone.c
+5
-4
@@ -290,16 +290,17 @@ static void copy_alternates(struct strbuf *src, struct strbuf *dst,
290
struct strbuf line = STRBUF_INIT;
291
292
while (strbuf_getline(&line, in, '\n') != EOF) {
293
- char *abs_path, abs_buf[PATH_MAX];
293
+ char *abs_path;
294
if (!line.len || line.buf[0] == '#')
295
continue;
296
if (is_absolute_path(line.buf)) {
297
add_to_alternates_file(line.buf);
298
continue;
299
}
300
- abs_path = mkpath("%s/objects/%s", src_repo, line.buf);
301
- normalize_path_copy(abs_buf, abs_path);
302
- add_to_alternates_file(abs_buf);
300
+ abs_path = mkpathdup("%s/objects/%s", src_repo, line.buf);
301
+ normalize_path_copy(abs_path, abs_path);
302
+ add_to_alternates_file(abs_path);
303
+ free(abs_path);
304
}
305
strbuf_release(&line);
306
fclose(in);
builtin/fetch.c
+3
-2
@@ -587,7 +587,8 @@ static int store_updated_refs(const char *raw_url, const char *remote_name,
587
struct strbuf note = STRBUF_INIT;
588
const char *what, *kind;
589
struct ref *rm;
590
- char *url, *filename = dry_run ? "/dev/null" : git_path("FETCH_HEAD");
590
+ char *url;
591
+ const char *filename = dry_run ? "/dev/null" : git_path("FETCH_HEAD");
592
int want_status;
593
594
fp = fopen(filename, "a");
@@ -821,7 +822,7 @@ static void check_not_current_branch(struct ref *ref_map)
822
823
static int truncate_fetch_head(void)
824
{
824
- char *filename = git_path("FETCH_HEAD");
825
+ const char *filename = git_path("FETCH_HEAD");
826
FILE *fp = fopen(filename, "w");
827
828
if (!fp)
builtin/fsck.c
+2
-2
@@ -225,12 +225,12 @@ static void check_unreachable_object(struct object *obj)
225
printf("dangling %s %s\n", typename(obj->type),
226
sha1_to_hex(obj->sha1));
227
if (write_lost_and_found) {
228
- char *filename = git_path("lost-found/%s/%s",
228
+ const char *filename = git_path("lost-found/%s/%s",
229
obj->type == OBJ_COMMIT ? "commit" : "other",
230
sha1_to_hex(obj->sha1));
231
FILE *f;
232
233
- if (safe_create_leading_directories(filename)) {
233
+ if (safe_create_leading_directories_const(filename)) {
234
error("Could not create lost-found");
235
return;
236
}
builtin/receive-pack.c
+1
-1
@@ -869,7 +869,7 @@ static void run_update_post_hook(struct command *commands)
869
int argc;
870
const char **argv;
871
struct child_process proc = CHILD_PROCESS_INIT;
872
- char *hook;
872
+ const char *hook;
873
874
hook = find_hook("post-update");
875
for (argc = 0, cmd = commands; cmd; cmd = cmd->next) {
builtin/remote.c
+1
-1
@@ -582,7 +582,7 @@ static int migrate_file(struct remote *remote)
582
{
583
struct strbuf buf = STRBUF_INIT;
584
int i;
585
- char *path = NULL;
585
+ const char *path = NULL;
586
587
strbuf_addf(&buf, "remote.%s.url", remote->name);
588
for (i = 0; i < remote->url_nr; i++)
builtin/repack.c
+5
-3
@@ -284,7 +284,8 @@ int cmd_repack(int argc, const char **argv, const char *prefix)
284
failed = 0;
285
for_each_string_list_item(item, &names) {
286
for (ext = 0; ext < ARRAY_SIZE(exts); ext++) {
287
- char *fname, *fname_old;
287
+ const char *fname_old;
288
+ char *fname;
289
fname = mkpathdup("%s/pack-%s%s", packdir,
290
item->string, exts[ext].name);
291
if (!file_exists(fname)) {
@@ -312,7 +313,8 @@ int cmd_repack(int argc, const char **argv, const char *prefix)
313
if (failed) {
314
struct string_list rollback_failure = STRING_LIST_INIT_DUP;
315
for_each_string_list_item(item, &rollback) {
315
- char *fname, *fname_old;
316
+ const char *fname_old;
317
+ char *fname;
318
fname = mkpathdup("%s/%s", packdir, item->string);
319
fname_old = mkpath("%s/old-%s", packdir, item->string);
320
if (rename(fname_old, fname))
@@ -365,7 +367,7 @@ int cmd_repack(int argc, const char **argv, const char *prefix)
367
/* Remove the "old-" files */
368
for_each_string_list_item(item, &names) {
369
for (ext = 0; ext < ARRAY_SIZE(exts); ext++) {
368
- char *fname;
370
+ const char *fname;
371
fname = mkpath("%s/old-%s%s",
372
packdir,
373
item->string,
cache.h
+3
-3
@@ -687,9 +687,9 @@ extern char *mkpathdup(const char *fmt, ...)
687
__attribute__((format (printf, 1, 2)));
688
689
/* Return a statically allocated filename matching the sha1 signature */
690
-extern char *mkpath(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
691
-extern char *git_path(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
692
-extern char *git_path_submodule(const char *path, const char *fmt, ...)
690
+extern const char *mkpath(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
691
+extern const char *git_path(const char *fmt, ...) __attribute__((format (printf, 1, 2)));
692
+extern const char *git_path_submodule(const char *path, const char *fmt, ...)
693
__attribute__((format (printf, 2, 3)));
694
695
/*
fast-import.c
+1
-1
@@ -405,7 +405,7 @@ static void dump_marks_helper(FILE *, uintmax_t, struct mark_set *);
405
406
static void write_crash_report(const char *err)
407
{
408
- char *loc = git_path("fast_import_crash_%"PRIuMAX, (uintmax_t) getpid());
408
+ const char *loc = git_path("fast_import_crash_%"PRIuMAX, (uintmax_t) getpid());
409
FILE *rpt = fopen(loc, "w");
410
struct branch *b;
411
unsigned long lu;
notes-merge.c
+3
-3
@@ -280,7 +280,7 @@ static void check_notes_merge_worktree(struct notes_merge_options *o)
280
"(%s exists).", git_path("NOTES_MERGE_*"));
281
}
282
283
- if (safe_create_leading_directories(git_path(
283
+ if (safe_create_leading_directories_const(git_path(
284
NOTES_MERGE_WORKTREE "/.test")))
285
die_errno("unable to create directory %s",
286
git_path(NOTES_MERGE_WORKTREE));
@@ -295,8 +295,8 @@ static void write_buf_to_worktree(const unsigned char *obj,
295
const char *buf, unsigned long size)
296
{
297
int fd;
298
- char *path = git_path(NOTES_MERGE_WORKTREE "/%s", sha1_to_hex(obj));
299
- if (safe_create_leading_directories(path))
298
+ const char *path = git_path(NOTES_MERGE_WORKTREE "/%s", sha1_to_hex(obj));
299
+ if (safe_create_leading_directories_const(path))
300
die_errno("unable to create directory for '%s'", path);
301
if (file_exists(path))
302
die("found existing file at '%s'", path);
path.c
+3
-3
@@ -106,7 +106,7 @@ char *mkpathdup(const char *fmt, ...)
106
return strbuf_detach(&sb, NULL);
107
}
108
109
-char *mkpath(const char *fmt, ...)
109
+const char *mkpath(const char *fmt, ...)
110
{
111
va_list args;
112
struct strbuf *pathname = get_pathname();
@@ -116,7 +116,7 @@ char *mkpath(const char *fmt, ...)
116
return cleanup_path(pathname->buf);
117
}
118
119
-char *git_path(const char *fmt, ...)
119
+const char *git_path(const char *fmt, ...)
120
{
121
struct strbuf *pathname = get_pathname();
122
va_list args;
@@ -154,7 +154,7 @@ void home_config_paths(char **global, char **xdg, char *file)
154
free(to_free);
155
}
156
157
-char *git_path_submodule(const char *path, const char *fmt, ...)
157
+const char *git_path_submodule(const char *path, const char *fmt, ...)
158
{
159
struct strbuf *buf = get_pathname();
160
const char *git_dir;
refs.c
+4
-4
@@ -1351,7 +1351,7 @@ static int resolve_gitlink_ref_recursive(struct ref_cache *refs,
1351
{
1352
int fd, len;
1353
char buffer[128], *p;
1354
- char *path;
1354
+ const char *path;
1355
1356
if (recursion > MAXDEPTH || strlen(refname) > MAXREFLEN)
1357
return -1;
@@ -2229,7 +2229,7 @@ static struct ref_lock *lock_ref_sha1_basic(const char *refname,
2229
const struct string_list *skip,
2230
int flags, int *type_p)
2231
{
2232
- char *ref_file;
2232
+ const char *ref_file;
2233
const char *orig_refname = refname;
2234
struct ref_lock *lock;
2235
int last_errno = 0;
@@ -2303,7 +2303,7 @@ static struct ref_lock *lock_ref_sha1_basic(const char *refname,
2303
lock->force_write = 1;
2304
2305
retry:
2306
- switch (safe_create_leading_directories(ref_file)) {
2306
+ switch (safe_create_leading_directories_const(ref_file)) {
2307
case SCLD_OK:
2308
break; /* success */
2309
case SCLD_VANISHED:
@@ -2743,7 +2743,7 @@ static int rename_tmp_log(const char *newrefname)
2743
int attempts_remaining = 4;
2744
2745
retry:
2746
- switch (safe_create_leading_directories(git_path("logs/%s", newrefname))) {
2746
+ switch (safe_create_leading_directories_const(git_path("logs/%s", newrefname))) {
2747
case SCLD_OK:
2748
break; /* success */
2749
case SCLD_VANISHED:
run-command.c
+2
-2
@@ -794,9 +794,9 @@ int finish_async(struct async *async)
794
#endif
795
}
796
797
-char *find_hook(const char *name)
797
+const char *find_hook(const char *name)
798
{
799
- char *path = git_path("hooks/%s", name);
799
+ const char *path = git_path("hooks/%s", name);
800
if (access(path, X_OK) < 0)
801
path = NULL;
802
run-command.h
+1
-1
@@ -52,7 +52,7 @@ int start_command(struct child_process *);
52
int finish_command(struct child_process *);
53
int run_command(struct child_process *);
54
55
-extern char *find_hook(const char *name);
55
+extern const char *find_hook(const char *name);
56
LAST_ARG_MUST_BE_NULL
57
extern int run_hook_le(const char *const *env, const char *name, ...);
58
extern int run_hook_ve(const char *const *env, const char *name, va_list args);
sha1_file.c
+1
-1
@@ -405,7 +405,7 @@ void add_to_alternates_file(const char *reference)
405
{
406
struct lock_file *lock = xcalloc(1, sizeof(struct lock_file));
407
int fd = hold_lock_file_for_append(lock, git_path("objects/info/alternates"), LOCK_DIE_ON_ERROR);
408
- char *alt = mkpath("%s\n", reference);
408
+ const char *alt = mkpath("%s\n", reference);
409
write_or_die(fd, alt, strlen(alt));
410
if (commit_lock_file(lock))
411
die("could not close alternates file");