From: ZheNing Hu via GitGitGadget <hidden> Date: 2021-05-05 15:31:08
From: ZheNing Hu <redacted>
Johannes Schindelin seems to have introduced a bug in
cc72385f(for-each-ref: let upstream/push optionally
report the remote name), it use `atom->u.remote_ref.option`
which is a member of enumeration in the judgment statement.
When we use other members in the enumeration `used_atom.u`,
and it happened to fill in `remote_ref.push`, this judgment
may still be established and produces errors. So replace the
judgment statement with `starts_with(name, "push")` to fix
the error.
Signed-off-by: ZheNing Hu <redacted>
---
[GSOC] ref-filter: solve bugs caused by enumeration
This is the problem I found in the implementation of git for-each-ref
--format="%(notes)".
I added a new option to the enum used_atom.u , but the program seems to
output the value of "%(push)".
After research, it should be the problem of incorrect use of enumeration
values here.
Thanks, may the force be with you!
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-949%2Fadlternative%2Fref-filter-enum-bug-fix-v1
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-949/adlternative/ref-filter-enum-bug-fix-v1
Pull-Request: https://github.com/gitgitgadget/git/pull/949
ref-filter.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
From: ZheNing Hu via GitGitGadget <hidden> Date: 2021-05-06 16:31:21
From: ZheNing Hu <redacted>
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
used_atom" wants to record. At most only one of the members can be
valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
Modify the condition here to first check whether the atom name
starts with "push", and then check u.remote_ref, to avoid reading
the value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu <redacted>
---
[GSOC] ref-filter: fix read invalid union member bug
Change from last version: Modified the documentation description with
the help of Junio. And modify the processing method of the condition:
check whether the name of the atom starts with "push" and whether
u.remote_ref is non-zero.
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-949%2Fadlternative%2Fref-filter-enum-bug-fix-v2
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-949/adlternative/ref-filter-enum-bug-fix-v2
Pull-Request: https://github.com/gitgitgadget/git/pull/949
Range-diff vs v1:
1: e51ca176f76b ! 1: 0e1923c9d722 [GSOC] ref-filter: solve bugs caused by enumeration
@@ Metadata
Author: ZheNing Hu [off-list ref]
## Commit message ##
- [GSOC] ref-filter: solve bugs caused by enumeration
+ [GSOC] ref-filter: fix read invalid union member bug
- Johannes Schindelin seems to have introduced a bug in
- cc72385f(for-each-ref: let upstream/push optionally
- report the remote name), it use `atom->u.remote_ref.option`
- which is a member of enumeration in the judgment statement.
- When we use other members in the enumeration `used_atom.u`,
- and it happened to fill in `remote_ref.push`, this judgment
- may still be established and produces errors. So replace the
- judgment statement with `starts_with(name, "push")` to fix
- the error.
+ used_atom.u is an union, and it has different members depending on
+ what atom the auxiliary data the union part of the "struct
+ used_atom" wants to record. At most only one of the members can be
+ valid at any one time. Since the code checks u.remote_ref without
+ even making sure if the atom is "push" or "push:" (which are only
+ two cases that u.remote_ref.push becomes valid), but u.remote_ref
+ shares the same storage for other members of the union, the check
+ was reading from an invalid member, which was the bug.
+ Modify the condition here to first check whether the atom name
+ starts with "push", and then check u.remote_ref, to avoid reading
+ the value of invalid member of the union.
+
+ Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu [off-list ref]
## ref-filter.c ##
@@ ref-filter.c: static int populate_value(struct ref_array_item *ref, struct strbu
v->s = xstrdup("");
continue;
- } else if (atom->u.remote_ref.push) {
-+ } else if (starts_with(name, "push")) {
++ } else if (starts_with(name, "push") && atom->u.remote_ref.push) {
const char *branch_name;
v->s = xstrdup("");
if (!skip_prefix(ref->refname, "refs/heads/",
ref-filter.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
From: ZheNing Hu via GitGitGadget <hidden> Date: 2021-05-08 15:26:17
From: ZheNing Hu <redacted>
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
used_atom" wants to record. At most only one of the members can be
valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
Modify the condition here to check whether the atom name
equals to "push" or starts with "push:", to avoid reading the
value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu <redacted>
---
[GSOC] ref-filter: fix read invalid union member bug
Change from last version:
Modify the processing method of the condition: check whether the name of
the atom equals to "push" or starts with "pushs", which can enhanced
security, although it may bring string match overhead.
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-949%2Fadlternative%2Fref-filter-enum-bug-fix-v3
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-949/adlternative/ref-filter-enum-bug-fix-v3
Pull-Request: https://github.com/gitgitgadget/git/pull/949
Range-diff vs v2:
1: 0e1923c9d722 ! 1: 21cf7a44e168 [GSOC] ref-filter: fix read invalid union member bug
@@ Commit message
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
- used_atom" wants to record. At most only one of the members can be
- valid at any one time. Since the code checks u.remote_ref without
+ used_atom" wants to record. At most only one of the members can be
+ valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
- Modify the condition here to first check whether the atom name
- starts with "push", and then check u.remote_ref, to avoid reading
- the value of invalid member of the union.
+ Modify the condition here to check whether the atom name
+ equals to "push" or starts with "push:", to avoid reading the
+ value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu [off-list ref]
@@ ref-filter.c: static int populate_value(struct ref_array_item *ref, struct strbu
v->s = xstrdup("");
continue;
- } else if (atom->u.remote_ref.push) {
-+ } else if (starts_with(name, "push") && atom->u.remote_ref.push) {
++ } else if (!strcmp(atom->name, "push") || starts_with(atom->name, "push:")) {
const char *branch_name;
v->s = xstrdup("");
if (!skip_prefix(ref->refname, "refs/heads/",
ref-filter.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
From: ZheNing Hu via GitGitGadget <hidden> Date: 2021-05-10 15:24:15
From: ZheNing Hu <redacted>
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
used_atom" wants to record. At most only one of the members can be
valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
Modify the condition here to check whether the atom name
equals to "push" or starts with "push:", to avoid reading the
value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu <redacted>
---
[GSOC] ref-filter: fix read invalid union member bug
Change from last version:
Prove that the bug may appear when using %(color) atom. And add
corresponding test for it.
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-949%2Fadlternative%2Fref-filter-enum-bug-fix-v4
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-949/adlternative/ref-filter-enum-bug-fix-v4
Pull-Request: https://github.com/gitgitgadget/git/pull/949
Range-diff vs v3:
1: 21cf7a44e168 ! 1: 8c6c0368a590 [GSOC] ref-filter: fix read invalid union member bug
@@ ref-filter.c: static int populate_value(struct ref_array_item *ref, struct strbu
const char *branch_name;
v->s = xstrdup("");
if (!skip_prefix(ref->refname, "refs/heads/",
+
+ ## t/t6302-for-each-ref-filter.sh ##
+@@ t/t6302-for-each-ref-filter.sh: test_expect_success '%(color) must fail' '
+ test_must_fail git for-each-ref --format="%(color)%(refname)"
+ '
+
++test_expect_success '%(color:#aa22ac) must success' '
++ cat >expect <<-\EOF &&
++ refs/heads/main
++ refs/heads/side
++ refs/odd/spot
++ refs/tags/annotated-tag
++ refs/tags/doubly-annotated-tag
++ refs/tags/doubly-signed-tag
++ refs/tags/four
++ refs/tags/one
++ refs/tags/signed-tag
++ refs/tags/three
++ refs/tags/two
++ EOF
++ git for-each-ref --format="%(color:#aa22ac)%(refname)" >actual &&
++ test_cmp expect actual
++'
++
+ test_expect_success 'left alignment is default' '
+ cat >expect <<-\EOF &&
+ refname is refs/heads/main |refs/heads/main
ref-filter.c | 2 +-
t/t6302-for-each-ref-filter.sh | 18 ++++++++++++++++++
2 files changed, 19 insertions(+), 1 deletion(-)
@@ -117,6 +117,24 @@ test_expect_success '%(color) must fail' 'test_must_failgitfor-each-ref--format="%(color)%(refname)"'+test_expect_success'%(color:#aa22ac) must success''+cat>expect<<-\EOF&&+refs/heads/main+refs/heads/side+refs/odd/spot+refs/tags/annotated-tag+refs/tags/doubly-annotated-tag+refs/tags/doubly-signed-tag+refs/tags/four+refs/tags/one+refs/tags/signed-tag+refs/tags/three+refs/tags/two+EOF+gitfor-each-ref--format="%(color:#aa22ac)%(refname)">actual&&+test_cmpexpectactual+'+ test_expect_success'left alignment is default''cat>expect<<-\EOF&&refnameisrefs/heads/main|refs/heads/main
From: ZheNing Hu via GitGitGadget <hidden> Date: 2021-05-11 15:35:28
From: ZheNing Hu <redacted>
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
used_atom" wants to record. At most only one of the members can be
valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
Modify the condition here to check whether the atom name
equals to "push" or starts with "push:", to avoid reading the
value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu <redacted>
---
[GSOC] ref-filter: fix read invalid union member bug
I and Junio discussed the situation that this bug might actually occur.
The damage that can be found currently is using %(colors:#aa22ac) or
some other %(colors) atoms. But Junio found that testing
%(colors:#aa22ac) alone did not show the expected bug in the commit
before the repair.
So I conducted an experiment:
When we use git push, Git will add some config, these configurations
will affect the result of the execution process related to atom %(push)
in populate_value().
Change from last version: added a new test, which added two
configurations:
git config branch.main.remote origin git config branch.main.merge
refs/heads/main
used to simulate the configuration changes brought by git push.
Finally, a test on the broken atom %(colors:#aa22ac). In the commit
before the repair, breakage occurs. In the commit after the repair,
breakage disappeared.
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-949%2Fadlternative%2Fref-filter-enum-bug-fix-v5
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-949/adlternative/ref-filter-enum-bug-fix-v5
Pull-Request: https://github.com/gitgitgadget/git/pull/949
Range-diff vs v4:
1: 8c6c0368a590 ! 1: b546477e8c87 [GSOC] ref-filter: fix read invalid union member bug
@@ t/t6302-for-each-ref-filter.sh: test_expect_success '%(color) must fail' '
test_must_fail git for-each-ref --format="%(color)%(refname)"
'
-+test_expect_success '%(color:#aa22ac) must success' '
++test_expect_success '%(color:#aa22ac) must successed' '
++ test_when_finished "cd .. && rm -rf ./test" &&
++ mkdir test &&
++ cd test &&
++ git init &&
+ cat >expect <<-\EOF &&
+ refs/heads/main
-+ refs/heads/side
-+ refs/odd/spot
-+ refs/tags/annotated-tag
-+ refs/tags/doubly-annotated-tag
-+ refs/tags/doubly-signed-tag
-+ refs/tags/four
-+ refs/tags/one
-+ refs/tags/signed-tag
-+ refs/tags/three
-+ refs/tags/two
+ EOF
++ git add . &&
++ git branch -M main &&
++ git commit -m "test" &&
++ git remote add origin nowhere &&
++ git config branch.main.remote origin &&
++ git config branch.main.merge refs/heads/main &&
+ git for-each-ref --format="%(color:#aa22ac)%(refname)" >actual &&
+ test_cmp expect actual
+'
ref-filter.c | 2 +-
t/t6302-for-each-ref-filter.sh | 18 ++++++++++++++++++
2 files changed, 19 insertions(+), 1 deletion(-)
From: Junio C Hamano <hidden> Date: 2021-05-12 01:40:17
"ZheNing Hu via GitGitGadget" [off-list ref] writes:
From: ZheNing Hu <redacted>
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
used_atom" wants to record. At most only one of the members can be
valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
Modify the condition here to check whether the atom name
equals to "push" or starts with "push:", to avoid reading the
value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu <redacted>
---
@@ -117,6 +117,24 @@ test_expect_success '%(color) must fail' 'test_must_failgitfor-each-ref--format="%(color)%(refname)"'+test_expect_success'%(color:#aa22ac) must successed''
"succeed".
+ test_when_finished "cd .. && rm -rf ./test" &&
Not a very good practice to chdir around, even if you have
when-finished clean-up. Not worth risking "rm -rf" at random
places when for example somebody breaks when-finished.
Instead...
+ mkdir test &&
Place everything below ...
+ cd test &&
+ git init &&
+ cat >expect <<-\EOF &&
+ refs/heads/main
+ EOF
+ git add . &&
+ git branch -M main &&
This is in a freshly created repository without commit. Does
"branch -M" work for such an unborn branch? Perhaps start this
block like so:
git init test &&
(
cd test &&
test_commit initial &&
git branch -M main &&
cat >expect <<-\EOF &&
refs/heads/main
refs/tags/initial
EOF
git remote add origin nowhere &&
...
... up to here inside a (subshell).
By the way, your use of "git branch -M" makes the test work whether
the default initial branch name is still 'master' or already 'main'
by forcing the branch used for testing to be 'main'. Clever ;-).
Will queue with all of the above suggestions squashed in; please see
if the result is good when it is pushed out later today.
Thanks.
+'
+
test_expect_success 'left alignment is default' '
cat >expect <<-\EOF &&
refname is refs/heads/main |refs/heads/main
base-commit: 311531c9de557d25ac087c1637818bd2aad6eb3a
From: ZheNing Hu <hidden> Date: 2021-05-12 10:37:25
quoted
+ test_when_finished "cd .. && rm -rf ./test" &&
Not a very good practice to chdir around, even if you have
when-finished clean-up. Not worth risking "rm -rf" at random
places when for example somebody breaks when-finished.
OK.
Instead...
quoted
+ mkdir test &&
Place everything below ...
quoted
+ cd test &&
+ git init &&
+ cat >expect <<-\EOF &&
+ refs/heads/main
+ EOF
+ git add . &&
+ git branch -M main &&
This is in a freshly created repository without commit. Does
"branch -M" work for such an unborn branch? Perhaps start this
block like so:
I think "git branch -M" before "git commit" also will be fine.
Of course it's okay to put it after commit and before "test_cmp".
git init test &&
(
cd test &&
test_commit initial &&
git branch -M main &&
cat >expect <<-\EOF &&
refs/heads/main
refs/tags/initial
EOF
git remote add origin nowhere &&
...
I get it now. By executing cd in the subshell, the "cd .." step can be
omitted.
By the way, your use of "git branch -M" makes the test work whether
the default initial branch name is still 'master' or already 'main'
by forcing the branch used for testing to be 'main'. Clever ;-).
Hh, real knowledge comes from practice. Yesterday, I tried it on the old
version of git on some classmates’ computers, and there was an error,
so using "git branch -M main" can avoid this error.
Will queue with all of the above suggestions squashed in; please see
if the result is good when it is pushed out later today.
Thanks.
From: ZheNing Hu via GitGitGadget <hidden> Date: 2021-05-12 12:12:56
From: ZheNing Hu <redacted>
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
used_atom" wants to record. At most only one of the members can be
valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
Modify the condition here to check whether the atom name
equals to "push" or starts with "push:", to avoid reading the
value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu <redacted>
---
[GSOC] ref-filter: fix read invalid union member bug
Change from last version: Modify the test content to make the test more
correct and complete.
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-949%2Fadlternative%2Fref-filter-enum-bug-fix-v6
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-949/adlternative/ref-filter-enum-bug-fix-v6
Pull-Request: https://github.com/gitgitgadget/git/pull/949
Range-diff vs v5:
1: b546477e8c87 ! 1: 518cc41a78a4 [GSOC] ref-filter: fix read invalid union member bug
@@ t/t6302-for-each-ref-filter.sh: test_expect_success '%(color) must fail' '
test_must_fail git for-each-ref --format="%(color)%(refname)"
'
-+test_expect_success '%(color:#aa22ac) must successed' '
-+ test_when_finished "cd .. && rm -rf ./test" &&
++test_expect_success '%(color:#aa22ac) must succeed' '
+ mkdir test &&
-+ cd test &&
-+ git init &&
-+ cat >expect <<-\EOF &&
-+ refs/heads/main
-+ EOF
-+ git add . &&
-+ git branch -M main &&
-+ git commit -m "test" &&
-+ git remote add origin nowhere &&
-+ git config branch.main.remote origin &&
-+ git config branch.main.merge refs/heads/main &&
-+ git for-each-ref --format="%(color:#aa22ac)%(refname)" >actual &&
-+ test_cmp expect actual
++ git init test &&
++ (
++ cd test &&
++ test_commit initial &&
++ git branch -M main &&
++ cat >expect <<-\EOF &&
++ refs/heads/main
++ refs/tags/initial
++ EOF
++ git remote add origin nowhere &&
++ git config branch.main.remote origin &&
++ git config branch.main.merge refs/heads/main &&
++ git for-each-ref --format="%(color:#aa22ac)%(refname)" >actual &&
++ test_cmp expect actual
++ )
+'
+
test_expect_success 'left alignment is default' '
ref-filter.c | 2 +-
t/t6302-for-each-ref-filter.sh | 19 +++++++++++++++++++
2 files changed, 20 insertions(+), 1 deletion(-)
@@ -117,6 +117,25 @@ test_expect_success '%(color) must fail' 'test_must_failgitfor-each-ref--format="%(color)%(refname)"'+test_expect_success'%(color:#aa22ac) must succeed''+mkdirtest&&+gitinittest&&+(+cdtest&&+test_commitinitial&&+gitbranch-Mmain&&+cat>expect<<-\EOF&&+refs/heads/main+refs/tags/initial+EOF+gitremoteaddoriginnowhere&&+gitconfigbranch.main.remoteorigin&&+gitconfigbranch.main.mergerefs/heads/main&&+gitfor-each-ref--format="%(color:#aa22ac)%(refname)">actual&&+test_cmpexpectactual+)+'+ test_expect_success'left alignment is default''cat>expect<<-\EOF&&refnameisrefs/heads/main|refs/heads/main
From: ZheNing Hu via GitGitGadget <hidden> Date: 2021-05-13 15:13:42
From: ZheNing Hu <redacted>
used_atom.u is an union, and it has different members depending on
what atom the auxiliary data the union part of the "struct
used_atom" wants to record. At most only one of the members can be
valid at any one time. Since the code checks u.remote_ref without
even making sure if the atom is "push" or "push:" (which are only
two cases that u.remote_ref.push becomes valid), but u.remote_ref
shares the same storage for other members of the union, the check
was reading from an invalid member, which was the bug.
Modify the condition here to check whether the atom name
equals to "push" or starts with "push:", to avoid reading the
value of invalid member of the union.
Helped-by: Junio C Hamano [off-list ref]
Signed-off-by: ZheNing Hu <redacted>
---
[GSOC] ref-filter: fix read invalid union member bug
Change from last version: Modify the test content, reduce additional
'mkdir' operation and remove temp-dir "test" when finished.
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-949%2Fadlternative%2Fref-filter-enum-bug-fix-v7
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-949/adlternative/ref-filter-enum-bug-fix-v7
Pull-Request: https://github.com/gitgitgadget/git/pull/949
Range-diff vs v6:
1: 518cc41a78a4 ! 1: 50bef8439a85 [GSOC] ref-filter: fix read invalid union member bug
@@ t/t6302-for-each-ref-filter.sh: test_expect_success '%(color) must fail' '
'
+test_expect_success '%(color:#aa22ac) must succeed' '
-+ mkdir test &&
++ test_when_finished rm -fr test &&
+ git init test &&
+ (
+ cd test &&
ref-filter.c | 2 +-
t/t6302-for-each-ref-filter.sh | 19 +++++++++++++++++++
2 files changed, 20 insertions(+), 1 deletion(-)
@@ -117,6 +117,25 @@ test_expect_success '%(color) must fail' 'test_must_failgitfor-each-ref--format="%(color)%(refname)"'+test_expect_success'%(color:#aa22ac) must succeed''+test_when_finishedrm-frtest&&+gitinittest&&+(+cdtest&&+test_commitinitial&&+gitbranch-Mmain&&+cat>expect<<-\EOF&&+refs/heads/main+refs/tags/initial+EOF+gitremoteaddoriginnowhere&&+gitconfigbranch.main.remoteorigin&&+gitconfigbranch.main.mergerefs/heads/main&&+gitfor-each-ref--format="%(color:#aa22ac)%(refname)">actual&&+test_cmpexpectactual+)+'+ test_expect_success'left alignment is default''cat>expect<<-\EOF&&refnameisrefs/heads/main|refs/heads/main