strtoul_ui: reject negative values
strtoul_ui uses strtoul to get a long unsigned, then checks that casting to unsigned does not lose information and return the casted value. On 64 bits architecture, checking that the cast does not change the value catches most errors, but when sizeof(int) == sizeof(long) (e.g. i386), the check does nothing. Unfortunately, strtoul silently accepts negative values, and as a result strtoul_ui("-1", ...) raised no error. This patch catches negative values before it's too late, i.e. before calling strtoul. Reported-by: Max Kirillov <max@max630.net> Signed-off-by: Matthieu Moy <Matthieu.Moy@imag.fr> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Matthieu Moy committed
Sep 17, 2015 at 18:28 UTC
e6f2599cbade92bcbb831d8e4845ab6f6211176c
1 file changed
+3
git-compat-util.h
+3
@@ -812,6 +812,9 @@ static inline int strtoul_ui(char const *s, int base, unsigned int *result)
812
char *p;
813
814
errno = 0;
815
+ /* negative values would be accepted by strtoul */
816
+ if (strchr(s, '-'))
817
+ return -1;
818
ul = strtoul(s, &p, base);
819
if (errno || *p || p == s || (unsigned int) ul != ul)
820
return -1;