index-pack: terminate object buffers with NUL
[git/git.git] / fsck.c
CommitLineData
355885d5
MK
1#include "cache.h"
2#include "object.h"
3#include "blob.h"
4#include "tree.h"
5#include "tree-walk.h"
6#include "commit.h"
7#include "tag.h"
8#include "fsck.h"
cec097be 9#include "refs.h"
355885d5
MK
10
11static int fsck_walk_tree(struct tree *tree, fsck_walk_func walk, void *data)
12{
13 struct tree_desc desc;
14 struct name_entry entry;
15 int res = 0;
16
17 if (parse_tree(tree))
18 return -1;
19
20 init_tree_desc(&desc, tree->buffer, tree->size);
21 while (tree_entry(&desc, &entry)) {
22 int result;
23
24 if (S_ISGITLINK(entry.mode))
25 continue;
26 if (S_ISDIR(entry.mode))
27 result = walk(&lookup_tree(entry.sha1)->object, OBJ_TREE, data);
28 else if (S_ISREG(entry.mode) || S_ISLNK(entry.mode))
29 result = walk(&lookup_blob(entry.sha1)->object, OBJ_BLOB, data);
30 else {
82247e9b 31 result = error("in tree %s: entry %s has bad mode %.6o",
355885d5
MK
32 sha1_to_hex(tree->object.sha1), entry.path, entry.mode);
33 }
34 if (result < 0)
35 return result;
36 if (!res)
37 res = result;
38 }
39 return res;
40}
41
42static int fsck_walk_commit(struct commit *commit, fsck_walk_func walk, void *data)
43{
44 struct commit_list *parents;
45 int res;
46 int result;
47
48 if (parse_commit(commit))
49 return -1;
50
51 result = walk((struct object *)commit->tree, OBJ_TREE, data);
52 if (result < 0)
53 return result;
54 res = result;
55
56 parents = commit->parents;
57 while (parents) {
58 result = walk((struct object *)parents->item, OBJ_COMMIT, data);
59 if (result < 0)
60 return result;
61 if (!res)
62 res = result;
63 parents = parents->next;
64 }
65 return res;
66}
67
68static int fsck_walk_tag(struct tag *tag, fsck_walk_func walk, void *data)
69{
70 if (parse_tag(tag))
71 return -1;
72 return walk(tag->tagged, OBJ_ANY, data);
73}
74
75int fsck_walk(struct object *obj, fsck_walk_func walk, void *data)
76{
77 if (!obj)
78 return -1;
79 switch (obj->type) {
80 case OBJ_BLOB:
81 return 0;
82 case OBJ_TREE:
83 return fsck_walk_tree((struct tree *)obj, walk, data);
84 case OBJ_COMMIT:
85 return fsck_walk_commit((struct commit *)obj, walk, data);
86 case OBJ_TAG:
87 return fsck_walk_tag((struct tag *)obj, walk, data);
88 default:
89 error("Unknown object type for %s", sha1_to_hex(obj->sha1));
90 return -1;
91 }
92}
ba002f3b
MK
93
94/*
95 * The entries in a tree are ordered in the _path_ order,
96 * which means that a directory entry is ordered by adding
97 * a slash to the end of it.
98 *
99 * So a directory called "a" is ordered _after_ a file
100 * called "a.c", because "a/" sorts after "a.c".
101 */
102#define TREE_UNORDERED (-1)
103#define TREE_HAS_DUPS (-2)
104
105static int verify_ordered(unsigned mode1, const char *name1, unsigned mode2, const char *name2)
106{
107 int len1 = strlen(name1);
108 int len2 = strlen(name2);
109 int len = len1 < len2 ? len1 : len2;
110 unsigned char c1, c2;
111 int cmp;
112
113 cmp = memcmp(name1, name2, len);
114 if (cmp < 0)
115 return 0;
116 if (cmp > 0)
117 return TREE_UNORDERED;
118
119 /*
120 * Ok, the first <len> characters are the same.
121 * Now we need to order the next one, but turn
122 * a '\0' into a '/' for a directory entry.
123 */
124 c1 = name1[len];
125 c2 = name2[len];
126 if (!c1 && !c2)
127 /*
128 * git-write-tree used to write out a nonsense tree that has
129 * entries with the same name, one blob and one tree. Make
130 * sure we do not have duplicate entries.
131 */
132 return TREE_HAS_DUPS;
133 if (!c1 && S_ISDIR(mode1))
134 c1 = '/';
135 if (!c2 && S_ISDIR(mode2))
136 c2 = '/';
137 return c1 < c2 ? 0 : TREE_UNORDERED;
138}
139
140static int fsck_tree(struct tree *item, int strict, fsck_error error_func)
141{
142 int retval;
c479d14a 143 int has_null_sha1 = 0;
ba002f3b
MK
144 int has_full_path = 0;
145 int has_empty_name = 0;
5d34a435
JK
146 int has_dot = 0;
147 int has_dotdot = 0;
5c17f512 148 int has_dotgit = 0;
ba002f3b
MK
149 int has_zero_pad = 0;
150 int has_bad_modes = 0;
151 int has_dup_entries = 0;
152 int not_properly_sorted = 0;
153 struct tree_desc desc;
154 unsigned o_mode;
155 const char *o_name;
ba002f3b
MK
156
157 init_tree_desc(&desc, item->buffer, item->size);
158
159 o_mode = 0;
160 o_name = NULL;
ba002f3b
MK
161
162 while (desc.size) {
163 unsigned mode;
164 const char *name;
c479d14a 165 const unsigned char *sha1;
ba002f3b 166
c479d14a 167 sha1 = tree_entry_extract(&desc, &name, &mode);
ba002f3b 168
effd12ec
HS
169 has_null_sha1 |= is_null_sha1(sha1);
170 has_full_path |= !!strchr(name, '/');
171 has_empty_name |= !*name;
172 has_dot |= !strcmp(name, ".");
173 has_dotdot |= !strcmp(name, "..");
174 has_dotgit |= !strcmp(name, ".git");
ba002f3b
MK
175 has_zero_pad |= *(char *)desc.buffer == '0';
176 update_tree_entry(&desc);
177
178 switch (mode) {
179 /*
180 * Standard modes..
181 */
182 case S_IFREG | 0755:
183 case S_IFREG | 0644:
184 case S_IFLNK:
185 case S_IFDIR:
186 case S_IFGITLINK:
187 break;
188 /*
189 * This is nonstandard, but we had a few of these
190 * early on when we honored the full set of mode
191 * bits..
192 */
193 case S_IFREG | 0664:
194 if (!strict)
195 break;
196 default:
197 has_bad_modes = 1;
198 }
199
200 if (o_name) {
201 switch (verify_ordered(o_mode, o_name, mode, name)) {
202 case TREE_UNORDERED:
203 not_properly_sorted = 1;
204 break;
205 case TREE_HAS_DUPS:
206 has_dup_entries = 1;
207 break;
208 default:
209 break;
210 }
211 }
212
213 o_mode = mode;
214 o_name = name;
ba002f3b
MK
215 }
216
217 retval = 0;
c479d14a
JK
218 if (has_null_sha1)
219 retval += error_func(&item->object, FSCK_WARN, "contains entries pointing to null sha1");
ba002f3b
MK
220 if (has_full_path)
221 retval += error_func(&item->object, FSCK_WARN, "contains full pathnames");
222 if (has_empty_name)
223 retval += error_func(&item->object, FSCK_WARN, "contains empty pathname");
5d34a435
JK
224 if (has_dot)
225 retval += error_func(&item->object, FSCK_WARN, "contains '.'");
226 if (has_dotdot)
227 retval += error_func(&item->object, FSCK_WARN, "contains '..'");
5c17f512
JK
228 if (has_dotgit)
229 retval += error_func(&item->object, FSCK_WARN, "contains '.git'");
ba002f3b
MK
230 if (has_zero_pad)
231 retval += error_func(&item->object, FSCK_WARN, "contains zero-padded file modes");
232 if (has_bad_modes)
233 retval += error_func(&item->object, FSCK_WARN, "contains bad file modes");
234 if (has_dup_entries)
235 retval += error_func(&item->object, FSCK_ERROR, "contains duplicate file entries");
236 if (not_properly_sorted)
237 retval += error_func(&item->object, FSCK_ERROR, "not properly sorted");
238 return retval;
239}
240
4d0d8975
JS
241static int require_end_of_header(const void *data, unsigned long size,
242 struct object *obj, fsck_error error_func)
243{
244 const char *buffer = (const char *)data;
245 unsigned long i;
246
247 for (i = 0; i < size; i++) {
248 switch (buffer[i]) {
249 case '\0':
250 return error_func(obj, FSCK_ERROR,
251 "unterminated header: NUL at offset %d", i);
252 case '\n':
253 if (i + 1 < size && buffer[i + 1] == '\n')
254 return 0;
255 }
256 }
257
258 return error_func(obj, FSCK_ERROR, "unterminated header");
259}
260
de42180f 261static int fsck_ident(const char **ident, struct object *obj, fsck_error error_func)
daae1922 262{
d4b8de04
JK
263 char *end;
264
53f53cff 265 if (**ident == '<')
daae1922 266 return error_func(obj, FSCK_ERROR, "invalid author/committer line - missing space before email");
53f53cff
DI
267 *ident += strcspn(*ident, "<>\n");
268 if (**ident == '>')
269 return error_func(obj, FSCK_ERROR, "invalid author/committer line - bad name");
daae1922
JN
270 if (**ident != '<')
271 return error_func(obj, FSCK_ERROR, "invalid author/committer line - missing email");
53f53cff
DI
272 if ((*ident)[-1] != ' ')
273 return error_func(obj, FSCK_ERROR, "invalid author/committer line - missing space before email");
daae1922
JN
274 (*ident)++;
275 *ident += strcspn(*ident, "<>\n");
276 if (**ident != '>')
277 return error_func(obj, FSCK_ERROR, "invalid author/committer line - bad email");
278 (*ident)++;
279 if (**ident != ' ')
280 return error_func(obj, FSCK_ERROR, "invalid author/committer line - missing space before date");
281 (*ident)++;
282 if (**ident == '0' && (*ident)[1] != ' ')
283 return error_func(obj, FSCK_ERROR, "invalid author/committer line - zero-padded date");
7ca36d93 284 if (date_overflows(strtoul(*ident, &end, 10)))
d4b8de04
JK
285 return error_func(obj, FSCK_ERROR, "invalid author/committer line - date causes integer overflow");
286 if (end == *ident || *end != ' ')
daae1922 287 return error_func(obj, FSCK_ERROR, "invalid author/committer line - bad date");
d4b8de04 288 *ident = end + 1;
daae1922
JN
289 if ((**ident != '+' && **ident != '-') ||
290 !isdigit((*ident)[1]) ||
291 !isdigit((*ident)[2]) ||
292 !isdigit((*ident)[3]) ||
293 !isdigit((*ident)[4]) ||
294 ((*ident)[5] != '\n'))
295 return error_func(obj, FSCK_ERROR, "invalid author/committer line - bad time zone");
296 (*ident) += 6;
297 return 0;
298}
299
bc6b8fc1 300static int fsck_commit_buffer(struct commit *commit, const char *buffer,
90a398bb 301 unsigned long size, fsck_error error_func)
ba002f3b 302{
ba002f3b
MK
303 unsigned char tree_sha1[20], sha1[20];
304 struct commit_graft *graft;
9d02150c 305 unsigned parent_count, parent_line_count = 0;
daae1922 306 int err;
ba002f3b 307
4d0d8975
JS
308 if (require_end_of_header(buffer, size, &commit->object, error_func))
309 return -1;
310
cf4fff57 311 if (!skip_prefix(buffer, "tree ", &buffer))
ba002f3b 312 return error_func(&commit->object, FSCK_ERROR, "invalid format - expected 'tree' line");
2d820a61 313 if (get_sha1_hex(buffer, tree_sha1) || buffer[40] != '\n')
ba002f3b 314 return error_func(&commit->object, FSCK_ERROR, "invalid 'tree' line format - bad sha1");
2d820a61 315 buffer += 41;
cf4fff57 316 while (skip_prefix(buffer, "parent ", &buffer)) {
2d820a61 317 if (get_sha1_hex(buffer, sha1) || buffer[40] != '\n')
ba002f3b 318 return error_func(&commit->object, FSCK_ERROR, "invalid 'parent' line format - bad sha1");
2d820a61 319 buffer += 41;
9d02150c 320 parent_line_count++;
ba002f3b
MK
321 }
322 graft = lookup_commit_graft(commit->object.sha1);
9d02150c 323 parent_count = commit_list_count(commit->parents);
ba002f3b 324 if (graft) {
9d02150c 325 if (graft->nr_parent == -1 && !parent_count)
ba002f3b 326 ; /* shallow commit */
9d02150c 327 else if (graft->nr_parent != parent_count)
ba002f3b
MK
328 return error_func(&commit->object, FSCK_ERROR, "graft objects missing");
329 } else {
9d02150c 330 if (parent_count != parent_line_count)
ba002f3b
MK
331 return error_func(&commit->object, FSCK_ERROR, "parent objects missing");
332 }
cf4fff57 333 if (!skip_prefix(buffer, "author ", &buffer))
ba002f3b 334 return error_func(&commit->object, FSCK_ERROR, "invalid format - expected 'author' line");
daae1922
JN
335 err = fsck_ident(&buffer, &commit->object, error_func);
336 if (err)
337 return err;
cf4fff57 338 if (!skip_prefix(buffer, "committer ", &buffer))
daae1922 339 return error_func(&commit->object, FSCK_ERROR, "invalid format - expected 'committer' line");
daae1922
JN
340 err = fsck_ident(&buffer, &commit->object, error_func);
341 if (err)
342 return err;
ba002f3b
MK
343 if (!commit->tree)
344 return error_func(&commit->object, FSCK_ERROR, "could not load commit's tree %s", sha1_to_hex(tree_sha1));
345
346 return 0;
347}
348
90a398bb
JS
349static int fsck_commit(struct commit *commit, const char *data,
350 unsigned long size, fsck_error error_func)
bc6b8fc1 351{
90a398bb
JS
352 const char *buffer = data ? data : get_commit_buffer(commit, &size);
353 int ret = fsck_commit_buffer(commit, buffer, size, error_func);
354 if (!data)
355 unuse_commit_buffer(commit, buffer);
bc6b8fc1
JK
356 return ret;
357}
358
cec097be
JS
359static int fsck_tag_buffer(struct tag *tag, const char *data,
360 unsigned long size, fsck_error error_func)
361{
362 unsigned char sha1[20];
363 int ret = 0;
364 const char *buffer;
365 char *to_free = NULL, *eol;
366 struct strbuf sb = STRBUF_INIT;
367
368 if (data)
369 buffer = data;
370 else {
371 enum object_type type;
372
373 buffer = to_free =
374 read_sha1_file(tag->object.sha1, &type, &size);
375 if (!buffer)
376 return error_func(&tag->object, FSCK_ERROR,
377 "cannot read tag object");
378
379 if (type != OBJ_TAG) {
380 ret = error_func(&tag->object, FSCK_ERROR,
381 "expected tag got %s",
382 typename(type));
383 goto done;
384 }
385 }
386
387 if (require_end_of_header(buffer, size, &tag->object, error_func))
388 goto done;
389
390 if (!skip_prefix(buffer, "object ", &buffer)) {
391 ret = error_func(&tag->object, FSCK_ERROR, "invalid format - expected 'object' line");
392 goto done;
393 }
394 if (get_sha1_hex(buffer, sha1) || buffer[40] != '\n') {
395 ret = error_func(&tag->object, FSCK_ERROR, "invalid 'object' line format - bad sha1");
396 goto done;
397 }
398 buffer += 41;
399
400 if (!skip_prefix(buffer, "type ", &buffer)) {
401 ret = error_func(&tag->object, FSCK_ERROR, "invalid format - expected 'type' line");
402 goto done;
403 }
404 eol = strchr(buffer, '\n');
405 if (!eol) {
406 ret = error_func(&tag->object, FSCK_ERROR, "invalid format - unexpected end after 'type' line");
407 goto done;
408 }
409 if (type_from_string_gently(buffer, eol - buffer, 1) < 0)
410 ret = error_func(&tag->object, FSCK_ERROR, "invalid 'type' value");
411 if (ret)
412 goto done;
413 buffer = eol + 1;
414
415 if (!skip_prefix(buffer, "tag ", &buffer)) {
416 ret = error_func(&tag->object, FSCK_ERROR, "invalid format - expected 'tag' line");
417 goto done;
418 }
419 eol = strchr(buffer, '\n');
420 if (!eol) {
421 ret = error_func(&tag->object, FSCK_ERROR, "invalid format - unexpected end after 'type' line");
422 goto done;
423 }
424 strbuf_addf(&sb, "refs/tags/%.*s", (int)(eol - buffer), buffer);
425 if (check_refname_format(sb.buf, 0))
7add4419
JK
426 error_func(&tag->object, FSCK_WARN, "invalid 'tag' name: %.*s",
427 (int)(eol - buffer), buffer);
cec097be
JS
428 buffer = eol + 1;
429
430 if (!skip_prefix(buffer, "tagger ", &buffer))
431 /* early tags do not contain 'tagger' lines; warn only */
432 error_func(&tag->object, FSCK_WARN, "invalid format - expected 'tagger' line");
433 else
434 ret = fsck_ident(&buffer, &tag->object, error_func);
435
436done:
437 strbuf_release(&sb);
438 free(to_free);
439 return ret;
440}
441
90a398bb
JS
442static int fsck_tag(struct tag *tag, const char *data,
443 unsigned long size, fsck_error error_func)
ba002f3b
MK
444{
445 struct object *tagged = tag->tagged;
446
447 if (!tagged)
448 return error_func(&tag->object, FSCK_ERROR, "could not load tagged object");
cec097be
JS
449
450 return fsck_tag_buffer(tag, data, size, error_func);
ba002f3b
MK
451}
452
90a398bb
JS
453int fsck_object(struct object *obj, void *data, unsigned long size,
454 int strict, fsck_error error_func)
ba002f3b
MK
455{
456 if (!obj)
457 return error_func(obj, FSCK_ERROR, "no valid object to fsck");
458
459 if (obj->type == OBJ_BLOB)
460 return 0;
461 if (obj->type == OBJ_TREE)
462 return fsck_tree((struct tree *) obj, strict, error_func);
463 if (obj->type == OBJ_COMMIT)
90a398bb
JS
464 return fsck_commit((struct commit *) obj, (const char *) data,
465 size, error_func);
ba002f3b 466 if (obj->type == OBJ_TAG)
90a398bb
JS
467 return fsck_tag((struct tag *) obj, (const char *) data,
468 size, error_func);
ba002f3b
MK
469
470 return error_func(obj, FSCK_ERROR, "unknown type '%d' (internal fsck error)",
471 obj->type);
472}
d6ffc8d7
MK
473
474int fsck_error_function(struct object *obj, int type, const char *fmt, ...)
475{
476 va_list ap;
f285a2d7 477 struct strbuf sb = STRBUF_INIT;
d6ffc8d7 478
5dd56489 479 strbuf_addf(&sb, "object %s:", sha1_to_hex(obj->sha1));
d6ffc8d7
MK
480
481 va_start(ap, fmt);
ebeb6090 482 strbuf_vaddf(&sb, fmt, ap);
d6ffc8d7
MK
483 va_end(ap);
484
9db56f71 485 error("%s", sb.buf);
d6ffc8d7
MK
486 strbuf_release(&sb);
487 return 1;
488}