{"thread":{"id":"22111","subject":"[PATCH] Fix segfault in fast-export","startedAt":"2010-01-07T03:58:39Z","lastAt":"2010-01-18T17:44:38Z","messageCount":2,"participants":["Mike Mueller","Heiko Voigt"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"130975","messageId":"20100107035839.GM8510@samus.subfocal.net","threadId":"22111","inReplyTo":null,"subject":"[PATCH] Fix segfault in fast-export","fromName":"Mike Mueller","fromEmail":"mmueller@vigilantsw.com","sentAt":"2010-01-07T03:58:39Z","receivedAt":"2010-01-07T03:58:39Z","isPatch":true,"sender":{"key":"mmueller@vigilantsw.com","avatar":null},"body":"Hi all,\n\nI'm working on a C++ static analyzer (Vigilant Sentry), and git\nis one of my test subjects.  In git-1.6.6, I found a crash in the\nfast-export command:\n\nThe problem is in builtin-fast-export.c, function export_marks:\n\n    f = fopen(file, \"w\");\n    if (!f)\n        error(\"Unable to open marks file %s for writing.\", file);\n   \n    for (i = 0; i < idnums.size; i++) {\n        if (deco->base && deco->base->type == 1) {\n            mark = ptr_to_mark(deco->decoration);\n            if (fprintf(f, \":%\"PRIu32\" %s\\n\", mark,\n                sha1_to_hex(deco->base->sha1)) < 0) {\n                e = 1;\n                break;\n            }\n        }\n        deco++;\n    }\n   \n    e |= ferror(f);\n    e |= fclose(f);\n\nIf fopen() fails, the error message is printed, but the function\ndoesn't exit.  The subsequent calls to fprintf and/or ferror will\nfail because f is NULL.  A simple way to reproduce is to export\nto a path you don't have write access to:\n   \n    $ git fast-export --export-marks=/foo\n    error: Unable to open marks file /foo for writing.\n    Segmentation fault (core dumped)\n\nI've attached a trivial patch that calls die_errno instead of\nerror, so the program exits if f is NULL.\n\nRegards,\nMike\n\n-- \nMike Mueller\nmmueller@vigilantsw.com\n\nhttp://www.vigilantsw.com/\n\n\ndiff --git a/builtin-fast-export.c b/builtin-fast-export.c\nindex b0a4029..963e89b 100644\n--- a/builtin-fast-export.c\n+++ b/builtin-fast-export.c\n@@ -503,7 +503,7 @@ static void export_marks(char *file)\n \n \tf = fopen(file, \"w\");\n \tif (!f)\n-\t\terror(\"Unable to open marks file %s for writing.\", file);\n+\t\tdie_errno(\"Unable to open marks file %s for writing\", file);\n \n \tfor (i = 0; i < idnums.size; i++) {\n \t\tif (deco->base && deco->base->type == 1) {\n"},{"id":"132040","messageId":"20100118174437.GB9576@book.hvoigt.net","threadId":"22111","inReplyTo":"20100107035839.GM8510@samus.subfocal.net","subject":"Re: [PATCH] Fix segfault in fast-export","fromName":"Heiko Voigt","fromEmail":"hvoigt@hvoigt.net","sentAt":"2010-01-18T17:44:38Z","receivedAt":"2010-01-18T17:44:38Z","isPatch":true,"sender":{"key":"hvoigt@hvoigt.net","avatar":"https://avatars.githubusercontent.com/u/184958?v=4"},"body":"Hi,\n\nif want your change included in git you probably want to CC: Junio and\ninline your patch so its easier to comment. Please see the file\nDocumentation/SubmittingPatches for tips on how to do it with your\nmailer.\n\ncheers Heiko\n\nP.S.: and include a commit message in your patch\n\nOn Wed, Jan 06, 2010 at 10:58:39PM -0500, Mike Mueller wrote:\n> Hi all,\n> \n> I'm working on a C++ static analyzer (Vigilant Sentry), and git\n> is one of my test subjects.  In git-1.6.6, I found a crash in the\n> fast-export command:\n> \n> The problem is in builtin-fast-export.c, function export_marks:\n> \n>     f = fopen(file, \"w\");\n>     if (!f)\n>         error(\"Unable to open marks file %s for writing.\", file);\n>    \n>     for (i = 0; i < idnums.size; i++) {\n>         if (deco->base && deco->base->type == 1) {\n>             mark = ptr_to_mark(deco->decoration);\n>             if (fprintf(f, \":%\"PRIu32\" %s\\n\", mark,\n>                 sha1_to_hex(deco->base->sha1)) < 0) {\n>                 e = 1;\n>                 break;\n>             }\n>         }\n>         deco++;\n>     }\n>    \n>     e |= ferror(f);\n>     e |= fclose(f);\n> \n> If fopen() fails, the error message is printed, but the function\n> doesn't exit.  The subsequent calls to fprintf and/or ferror will\n> fail because f is NULL.  A simple way to reproduce is to export\n> to a path you don't have write access to:\n>    \n>     $ git fast-export --export-marks=/foo\n>     error: Unable to open marks file /foo for writing.\n>     Segmentation fault (core dumped)\n> \n> I've attached a trivial patch that calls die_errno instead of\n> error, so the program exits if f is NULL.\n> \n> Regards,\n> Mike\n> \n> -- \n> Mike Mueller\n> mmueller@vigilantsw.com\n> \n> http://www.vigilantsw.com/\n\n> diff --git a/builtin-fast-export.c b/builtin-fast-export.c\n> index b0a4029..963e89b 100644\n> --- a/builtin-fast-export.c\n> +++ b/builtin-fast-export.c\n> @@ -503,7 +503,7 @@ static void export_marks(char *file)\n>  \n>  \tf = fopen(file, \"w\");\n>  \tif (!f)\n> -\t\terror(\"Unable to open marks file %s for writing.\", file);\n> +\t\tdie_errno(\"Unable to open marks file %s for writing\", file);\n>  \n>  \tfor (i = 0; i < idnums.size; i++) {\n>  \t\tif (deco->base && deco->base->type == 1) {\n"}]}