diff options
author | Jacques Germishuys <jacquesg@striata.com> | 2014-04-11 22:57:15 +0200 |
---|---|---|
committer | Jacques Germishuys <jacquesg@striata.com> | 2014-04-15 17:22:17 +0200 |
commit | a56b418d8541e04f02be1227772b13762bfebaed (patch) | |
tree | f70e5f9f04b75b7fe8049a135fb2ea979299a19c /src/diff.c | |
parent | d8cc1fb653387d9acc28b075147084cf452c43dc (diff) | |
download | libgit2-a56b418d8541e04f02be1227772b13762bfebaed.tar.gz |
Sanitize git_diff_format_email_options' summary parameter
It will form part of the subject line and should thus be one line.
Diffstat (limited to 'src/diff.c')
-rw-r--r-- | src/diff.c | 20 |
1 files changed, 19 insertions, 1 deletions
diff --git a/src/diff.c b/src/diff.c index ba3cd26b5..cb05a5faf 100644 --- a/src/diff.c +++ b/src/diff.c @@ -1544,6 +1544,7 @@ int git_diff_format_email( const git_diff_format_email_options *opts) { git_diff_stats *stats = NULL; + char *summary = NULL, *loc = NULL; bool ignore_marker; unsigned int format_flags = 0; int error; @@ -1565,8 +1566,24 @@ int git_diff_format_email( } } + /* the summary we receive may not be clean. + * it could potentially contain new line characters + * or not be set, sanitize, */ + if ((loc = strpbrk(opts->summary, "\r\n")) != NULL) { + size_t offset = 0; + + if ((offset = (loc - opts->summary)) == 0) { + giterr_set(GITERR_INVALID, "summary is empty"); + error = -1; + } + + summary = git__calloc(offset + 1, sizeof(char)); + GITERR_CHECK_ALLOC(summary); + strncpy(summary, opts->summary, offset); + } + error = git_diff_format_email__append_header_tobuf(out, - opts->id, opts->author, opts->summary, + opts->id, opts->author, summary == NULL ? opts->summary : summary, opts->patch_no, opts->total_patches, ignore_marker); if (error < 0) @@ -1583,6 +1600,7 @@ int git_diff_format_email( error = git_buf_puts(out, "--\nlibgit2 " LIBGIT2_VERSION "\n\n"); on_error: + git__free(summary); git_diff_stats_free(stats); return error; |