http: offer to cast `size_t` to `curl_off_t` safely

This commit moves the `xcurl_off_t()` function, which validates that a given value fits within the `curl_off_t` data type and then casts it, to a more central place so that it can be used outside of `remote-curl.c`, too. At the same time, this function is renamed to conform better with the naming convention of the helper functions that safely cast from one data type to another which has been well established in `git-compat-util.h`. With this move, `gettext.h` must be `#include`d in `http.h` to allow the error message to remain translatable. Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Johannes Schindelin committed Sep 26, 2025 at 10:32 UTC e4efcd70604f2a294e020ec2e1bc38f01892cd19
2 files changed +13 -11
http.h
+10
@@ -8,6 +8,7 @@ struct packed_git;
8 #include <curl/curl.h>
9 #include <curl/easy.h>
10
11 +#include "gettext.h"
12 #include "strbuf.h"
13 #include "remote.h"
14
@@ -95,6 +96,15 @@ static inline int missing__target(int code, int result)
96
97 #define missing_target(a) missing__target((a)->http_code, (a)->curl_result)
98
99 +static inline curl_off_t cast_size_t_to_curl_off_t(size_t a)
100 +{
101 + uintmax_t size = a;
102 + if (size > maximum_signed_value_of_type(curl_off_t))
103 + die(_("number too large to represent as curl_off_t "
104 + "on this platform: %"PRIuMAX), (uintmax_t)a);
105 + return (curl_off_t)a;
106 +}
107 +
108 /*
109 * Normalize curl results to handle CURL_FAILONERROR (or lack thereof). Failing
110 * http codes have their "result" converted to CURLE_HTTP_RETURNED_ERROR, and
remote-curl.c
+3 -11
@@ -894,14 +894,6 @@ static int probe_rpc(struct rpc_state *rpc, struct slot_results *results)
894 return err;
895 }
896
897 -static curl_off_t xcurl_off_t(size_t len)
898 -{
899 - uintmax_t size = len;
900 - if (size > maximum_signed_value_of_type(curl_off_t))
901 - die(_("cannot handle pushes this big"));
902 - return (curl_off_t)size;
903 -}
904 -
897 /*
898 * If flush_received is true, do not attempt to read any more; just use what's
899 * in rpc->buf.
@@ -999,7 +991,7 @@ retry:
991 * and we just need to send it.
992 */
993 curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDS, gzip_body);
1002 - curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE_LARGE, xcurl_off_t(gzip_size));
994 + curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE_LARGE, cast_size_t_to_curl_off_t(gzip_size));
995
996 } else if (use_gzip && 1024 < rpc->len) {
997 /* The client backend isn't giving us compressed data so
@@ -1030,7 +1022,7 @@ retry:
1022
1023 headers = curl_slist_append(headers, "Content-Encoding: gzip");
1024 curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDS, gzip_body);
1033 - curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE_LARGE, xcurl_off_t(gzip_size));
1025 + curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE_LARGE, cast_size_t_to_curl_off_t(gzip_size));
1026
1027 if (options.verbosity > 1) {
1028 fprintf(stderr, "POST %s (gzip %lu to %lu bytes)\n",
@@ -1043,7 +1035,7 @@ retry:
1035 * more normal Content-Length approach.
1036 */
1037 curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDS, rpc->buf);
1046 - curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE_LARGE, xcurl_off_t(rpc->len));
1038 + curl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE_LARGE, cast_size_t_to_curl_off_t(rpc->len));
1039 if (options.verbosity > 1) {
1040 fprintf(stderr, "POST %s (%lu bytes)\n",
1041 rpc->service_name, (unsigned long)rpc->len);