{"thread":{"id":"10526","subject":"[BUG] remote.c/match_explicit() ... NULL pointer dereferenciation (git 1.5.3.4)","startedAt":"2007-10-30T10:44:32Z","lastAt":"2007-10-30T18:30:43Z","messageCount":2,"participants":["Melchior FRANZ","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"57561","messageId":"200710301144.32528@rk-nord.at","threadId":"10526","inReplyTo":null,"subject":"[BUG] remote.c/match_explicit() ... NULL pointer dereferenciation (git 1.5.3.4)","fromName":"Melchior FRANZ","fromEmail":"mfranz@aon.at","sentAt":"2007-10-30T10:44:32Z","receivedAt":"2007-10-30T10:44:32Z","isPatch":false,"sender":{"key":"mfranz@aon.at","avatar":null},"body":"Hi,\n\nI'm mucking around with git while implementing a simple, flat\nCVS gateway. For tests I created a local remote clone via\n\"git remote add -f -t master -m master origin /local/path\"\n(as described on the git-remote man-page). When running a\n(wrong) command like  \"git push origin foo\", whereby \"foo\"\nis nowhere defined in the refspec list:\n\n  [remote \"origin\"]\n          url = /local/path\n          fetch = +refs/heads/master:refs/remotes/origin/master\n          push = +master:refs/heads/sync\n\nthen git-send-pack segfaults in remote.c/count_refspec_match\nin the strlen() function, because \"pattern\" contains garbage.\n\n\nAnd this is because in match_explicit() we have these lines:\n\n        if (!matched_src)\n                errs = 1;\n\n        if (dst_value == NULL)\n                dst_value = matched_src->name;\n                                           <<- gdb prints from here\n\n\nand with the unknown refspec \"foo\" both dst_value and matched_src\nare zero:\n\n  (gdb) print dst_value\n  $1 = 0x0\n\n  (gdb) print *rs\n  $2 = {\n    force = 0,\n    pattern = 0,\n    src = 0x808d680 \"foo\",\n    dst = 0x0\n  }\n\n  (gdb) print matched_src\n  $3 = (struct ref *) 0x0\n\n  (gdb) print dst_value\n  $4 = 0x34 <Address 0x34 out of bounds>\n\n\nNo idea, why the NULL-pointer dereferenciation doesn't segfault\nright away, but assigns 0x34 to dst_value. Compiler bug?\n\nm.\n\n\n\nSpec:\n  Linux 2.6.23.1  x86/P4\n  gcc 4.2.1 (SUSE Linux)   (openSuSE 10.3)\n  libc 2.6.1 (20070803)\n  git 1.5.3.4  (compiled with -g -O0)\n"},{"id":"57590","messageId":"7vwst4lajw.fsf@gitster.siamese.dyndns.org","threadId":"10526","inReplyTo":"200710301144.32528@rk-nord.at","subject":"Re: [BUG] remote.c/match_explicit() ... NULL pointer dereferenciation (git 1.5.3.4)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2007-10-30T18:30:43Z","receivedAt":"2007-10-30T18:30:43Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Subject: Prevent send-pack from segfaulting (backport from 'master')\n\n4491e62ae932d5774f628d1bd3be663c11058a73 (Prevent send-pack from\nsegfaulting when a branch doesn't match) \n\nIf we can't find a source match, and we have no destination, we\nneed to abort the match function early before we try to match\nthe destination against the remote.\n\nSigned-off-by: Junio C Hamano <gitster@pobox.com>\n---\n\n  Thanks.  Shawn fixed it on the 'master' side but 'maint' is\n  still using the old code.\n\n remote.c |    5 ++++-\n 1 files changed, 4 insertions(+), 1 deletions(-)\n\ndiff --git a/remote.c b/remote.c\nindex cdbbdcb..9a88917 100644\n--- a/remote.c\n+++ b/remote.c\n@@ -504,8 +504,11 @@ static int match_explicit(struct ref *src, struct ref *dst,\n \tif (!matched_src)\n \t\terrs = 1;\n \n-\tif (dst_value == NULL)\n+\tif (!dst_value) {\n+\t\tif (!matched_src)\n+\t\t\treturn errs;\n \t\tdst_value = matched_src->name;\n+\t}\n \n \tswitch (count_refspec_match(dst_value, dst, &matched_dst)) {\n \tcase 1:\n"}]}