{"thread":{"id":"13310","subject":"git-fetch segfault in git 1.5.5.1","startedAt":"2008-04-28T18:41:38Z","lastAt":"2008-04-29T07:30:42Z","messageCount":3,"participants":["Dave Jones","Alex Riesen","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"75423","messageId":"20080428184138.GA30702@redhat.com","threadId":"13310","inReplyTo":null,"subject":"git-fetch segfault in git 1.5.5.1","fromName":"Dave Jones","fromEmail":"davej@redhat.com","sentAt":"2008-04-28T18:41:38Z","receivedAt":"2008-04-28T18:41:38Z","isPatch":false,"sender":{"key":"davej@redhat.com","avatar":null},"body":"Since master.kernel.org updated to latest, I noticed that I could crash\ngit-fetch by doing this..\n\nexport KERNEL=/pub/scm/linux/kernel/git/\ngit fetch $KERNEL/torvalds/linux-2.6 master:linus\n\n(gdb) bt\n#0  0x000000349fd6d44b in free () from /lib64/libc.so.6\n#1  0x000000000048f4eb in transport_unlock_pack (transport=0x7ce530) at transport.c:811\n#2  0x000000349fd31b25 in exit () from /lib64/libc.so.6\n#3  0x00000000004043d8 in handle_internal_command (argc=3, argv=0x7fffea4449f0) at git.c:379\n#4  0x0000000000404547 in main (argc=3, argv=0x7fffea4449f0) at git.c:443\n#5  0x000000349fd1c784 in __libc_start_main () from /lib64/libc.so.6\n#6  0x0000000000403ef9 in ?? ()\n#7  0x00007fffea4449d8 in ?? ()\n#8  0x0000000000000000 in ?? ()\n\nI then remembered, my .bashrc has this..\n\nexport MALLOC_PERTURB_=$(($RANDOM % 255 + 1))\n\nwhich is handy for showing up such bugs.\n\nMore info on this glibc feature is at http://udrepper.livejournal.com/11429.html\n\n\tDave\n\n-- \nhttp://www.codemonkey.org.uk\n"},{"id":"75449","messageId":"20080428202335.GA10600@steel.home","threadId":"13310","inReplyTo":"20080428184138.GA30702@redhat.com","subject":"[PATCH] Fix use after free() in builtin-fetch","fromName":"Alex Riesen","fromEmail":"raa.lkml@gmail.com","sentAt":"2008-04-28T20:23:35Z","receivedAt":"2008-04-28T20:23:35Z","isPatch":true,"sender":{"key":"raa.lkml@gmail.com","avatar":"https://avatars.githubusercontent.com/u/324101?v=4"},"body":"As reported by Dave Jones:\n\nSince master.kernel.org updated to latest, I noticed that I could crash\ngit-fetch by doing this..\n\nexport KERNEL=/pub/scm/linux/kernel/git/\ngit fetch $KERNEL/torvalds/linux-2.6 master:linus\n\n(gdb) bt\n 0  0x000000349fd6d44b in free () from /lib64/libc.so.6\n 1  0x000000000048f4eb in transport_unlock_pack (transport=0x7ce530) at transport.c:811\n 2  0x000000349fd31b25 in exit () from /lib64/libc.so.6\n 3  0x00000000004043d8 in handle_internal_command (argc=3, argv=0x7fffea4449f0) at git.c:379\n 4  0x0000000000404547 in main (argc=3, argv=0x7fffea4449f0) at git.c:443\n 5  0x000000349fd1c784 in __libc_start_main () from /lib64/libc.so.6\n 6  0x0000000000403ef9 in ?? ()\n 7  0x00007fffea4449d8 in ?? ()\n 8  0x0000000000000000 in ?? ()\n\nI then remembered, my .bashrc has this..\n\nexport MALLOC_PERTURB_=$(($RANDOM % 255 + 1))\n\nwhich is handy for showing up such bugs.\n\nMore info on this glibc feature is at http://udrepper.livejournal.com/11429.html\n\nSigned-off-by: Alex Riesen <raa.lkml@gmail.com>\n---\nDave Jones, Mon, Apr 28, 2008 20:41:38 +0200:\n> (gdb) bt\n> #0  0x000000349fd6d44b in free () from /lib64/libc.so.6\n> #1  0x000000000048f4eb in transport_unlock_pack (transport=0x7ce530) at transport.c:811\n> #2  0x000000349fd31b25 in exit () from /lib64/libc.so.6\n\natexit strikes again. Besides, I believe, do_fetch has no bussiness in\ndeallocation of resources it did not allocate.\n\n builtin-fetch.c |    8 +++++---\n 1 files changed, 5 insertions(+), 3 deletions(-)\n\ndiff --git a/builtin-fetch.c b/builtin-fetch.c\nindex 139a6b1..167f948 100644\n--- a/builtin-fetch.c\n+++ b/builtin-fetch.c\n@@ -577,8 +577,6 @@ static int do_fetch(struct transport *transport,\n \t\tfree_refs(ref_map);\n \t}\n \n-\ttransport_disconnect(transport);\n-\n \treturn 0;\n }\n \n@@ -599,6 +597,7 @@ int cmd_fetch(int argc, const char **argv, const char *prefix)\n \tint i;\n \tstatic const char **refs = NULL;\n \tint ref_nr = 0;\n+\tint exit_code;\n \n \t/* Record the command line for the reflog */\n \tstrbuf_addstr(&default_rla, \"fetch\");\n@@ -652,6 +651,9 @@ int cmd_fetch(int argc, const char **argv, const char *prefix)\n \n \tsignal(SIGINT, unlock_pack_on_signal);\n \tatexit(unlock_pack);\n-\treturn do_fetch(transport,\n+\texit_code = do_fetch(transport,\n \t\t\tparse_fetch_refspec(ref_nr, refs), ref_nr);\n+\ttransport_disconnect(transport);\n+\ttransport = NULL;\n+\treturn exit_code;\n }\n-- \n1.5.5.1.118.g6dd1b6.dirty\n"},{"id":"75509","messageId":"7vtzhl6rtp.fsf@gitster.siamese.dyndns.org","threadId":"13310","inReplyTo":"20080428202335.GA10600@steel.home","subject":"Re: [PATCH] Fix use after free() in builtin-fetch","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-04-29T07:30:42Z","receivedAt":"2008-04-29T07:30:42Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Alex Riesen <raa.lkml@gmail.com> writes:\n\n> As reported by Dave Jones:\n> ...\n> export MALLOC_PERTURB_=$(($RANDOM % 255 + 1))\n>\n> which is handy for showing up such bugs.\n>\n> More info on this glibc feature is at http://udrepper.livejournal.com/11429.html\n>\n> Signed-off-by: Alex Riesen <raa.lkml@gmail.com>\n\nThanks.  I can reproduce the issue and the fix (and can even bisect this\ndown to ba22785 (Reduce the number of connects when fetching, 2008-02-04),\nwhich makes perfect sense).\n\nWill apply to 'maint' and merge up.\n"}]}