daemon: fix length computation in newline stripping

When git-daemon gets a pktline request, we strip off any trailing newline, replacing it with a NUL. Clients prior to 5ad312bede (in git v1.4.0) would send: git-upload-pack repo.git\n and we need to strip it off to understand their request. After 5ad312bede, we send the host attribute but no newline, like: git-upload-pack repo.git\0host=example.com\0 Both of these are parsed correctly by git-daemon. But if some client were to combine the two: git-upload-pack repo.git\n\0host=example.com\0 we don't parse it correctly. The problem is that we use the "len" variable to record the position of the NUL separator, but then decrement it when we strip the newline. So we start with: git-upload-pack repo.git\n\0host=example.com\0 ^-- len and end up with: git-upload-pack repo.git\0\0host=example.com\0 ^-- len This is arguably correct, since "len" tells us the length of the initial string, but we don't actually use it for that. What we do use it for is finding the offset of the extended attributes; they used to be at len+1, but are now at len+2. We can solve that by just leaving "len" where it is. We don't have to care about the length of the shortened string, since we just treat it like a C string. No version of Git ever produced such a string, but it seems like the daemon code meant to handle this case (and it seems like a reasonable thing for somebody to do in a 3rd-party implementation). Reported-by: Michael Haggerty <mhagger@alum.mit.edu> Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Jan 24, 2018 at 19:58 UTC ed15e58efefc7f9dc1281860289e48e8f9c9b8fa
2 files changed +17 -4
daemon.c
+2 -4
@@ -760,10 +760,8 @@ static int execute(void)
760 alarm(0);
761
762 len = strlen(line);
763 - if (len && line[len-1] == '\n') {
764 - line[--len] = 0;
765 - pktlen--;
766 - }
763 + if (len && line[len-1] == '\n')
764 + line[len-1] = 0;
765
766 /* parse additional args hidden behind a NUL byte */
767 if (len != pktlen)
t/t5570-git-daemon.sh
+15
@@ -196,5 +196,20 @@ test_expect_success 'daemon log records all attributes' '
196 test_cmp expect actual
197 '
198
199 +test_expect_success FAKENC 'hostname interpolation works after LF-stripping' '
200 + {
201 + printf "git-upload-pack /interp.git\n\0host=localhost" | packetize
202 + printf "0000"
203 + } >input &&
204 + fake_nc "$GIT_DAEMON_HOST_PORT" <input >output &&
205 + depacketize <output >output.raw &&
206 +
207 + # just pick out the value of master, which avoids any protocol
208 + # particulars
209 + perl -lne "print \$1 if m{^(\\S+) refs/heads/master}" <output.raw >actual &&
210 + git -C "$repo" rev-parse master >expect &&
211 + test_cmp expect actual
212 +'
213 +
214 stop_git_daemon
215 test_done