http-push: fix xml_entities() string parsing overrun

xml_entities() in http-push.c did not properly stop at the end of the
string being examined, which would occasionally cause nonsense to be
appended to escaped URL strings and result in failed DAV XML queries

Signed-off-by: Seth Hunter <>;
Signed-off-by: Junio C Hamano <>;

 		case '&':
 			strbuf_addstr(&buf, "&amp;");
+		case 0:
+			return strbuf_detach(&buf, NULL);
