From 5c6782ab9547c31095c120199140a15c58c6fd77 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 25 Jul 2026 11:03:18 -1000 Subject: Bound the cache listing key output --- source/cache.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) (limited to 'source') diff --git a/source/cache.c b/source/cache.c index 561d9e6..aff0f4d 100644 --- a/source/cache.c +++ b/source/cache.c @@ -425,6 +425,8 @@ int cache_ls(const char *path) struct cache_slot slot = { NULL }; struct strbuf fullname = STRBUF_INIT; size_t prefixlen; + char *nul; + int keylen; if (!path) { cache_log("[cgit] cache path not specified\n"); @@ -451,12 +453,17 @@ int cache_ls(const char *path) fullname.buf, strerror(err), err); continue; } - htmlf("%s %s %10"PRIuMAX" %s\n", + // The stored key is NUL-terminated within the buffer, but a + // truncated or corrupt slot may not be. Bound the print to + // what was read so %s cannot run off the end. + nul = memchr(slot.buf, 0, slot.bufsize); + keylen = nul ? (int)(nul - slot.buf) : slot.bufsize; + htmlf("%s %s %10"PRIuMAX" %.*s\n", fullname.buf, sprintftime("%Y-%m-%d %H:%M:%S", slot.cache_st.st_mtime), (uintmax_t)slot.cache_st.st_size, - slot.buf); + keylen, slot.buf); close_slot(&slot); } closedir(dir); -- cgit v2.8.0