fast-import: fix read of uninitialized argv memory

Fast-import shares code between its command-line parser and the "option" command. To do so, it strips the "--" from any command-line options and passes them to the option parser. However, it does not confirm that the option even begins with "--" before blindly passing "arg + 2". It does confirm that the option starts with "-", so the only affected case was: git fast-import - which would read uninitialized memory after the argument. We can fix it by using skip_prefix and checking the result. As a bonus, this gets rid of some magic numbers. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Jun 18, 2014 at 15:46 UTC ff45c0d4a316d620d118ec628dd8e78597a23321
1 file changed +8 -5
fast-import.c
+8 -5
@@ -3342,18 +3342,21 @@ static void parse_argv(void)
3342 if (*a != '-' || !strcmp(a, "--"))
3343 break;
3344
3345 - if (parse_one_option(a + 2))
3345 + if (!skip_prefix(a, "--", &a))
3346 + die("unknown option %s", a);
3347 +
3348 + if (parse_one_option(a))
3349 continue;
3350
3348 - if (parse_one_feature(a + 2, 0))
3351 + if (parse_one_feature(a, 0))
3352 continue;
3353
3351 - if (starts_with(a + 2, "cat-blob-fd=")) {
3352 - option_cat_blob_fd(a + 2 + strlen("cat-blob-fd="));
3354 + if (skip_prefix(a, "cat-blob-fd=", &a)) {
3355 + option_cat_blob_fd(a);
3356 continue;
3357 }
3358
3356 - die("unknown option %s", a);
3359 + die("unknown option --%s", a);
3360 }
3361 if (i != global_argc)
3362 usage(fast_import_usage);