{"thread":{"id":"65166","subject":"[PATCH] history: initialize rev_info in cmd_history_reword()","startedAt":"2026-03-08T09:57:10Z","lastAt":"2026-03-10T12:16:13Z","messageCount":2,"participants":["René Scharfe","Patrick Steinhardt"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"538194","messageId":"b0b8633f-be95-48eb-8244-d0e3f1a7be72@web.de","threadId":"65166","inReplyTo":null,"subject":"[PATCH] history: initialize rev_info in cmd_history_reword()","fromName":"René Scharfe","fromEmail":"l.s.r@web.de","sentAt":"2026-03-08T09:57:02Z","receivedAt":"2026-03-08T09:57:10Z","isPatch":true,"sender":{"key":"l.s.r@web.de","avatar":"https://avatars.githubusercontent.com/u/26122331?v=4"},"body":"git history reword expects a single valid revision argument and errors\nout if it doesn't get it.  In that case the struct rev_info passed to\nrelease_revisions() for cleanup is still uninitialized, which can result\nin attempts to free(3) random pointers.  Avoid that by initializing the\nstructure.\n\nSigned-off-by: René Scharfe <l.s.r@web.de>\n---\n builtin/history.c | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/builtin/history.c b/builtin/history.c\nindex 1cf6c668cf..88822a184f 100644\n--- a/builtin/history.c\n+++ b/builtin/history.c\n@@ -425,7 +425,7 @@ static int cmd_history_reword(int argc,\n \t};\n \tstruct strbuf reflog_msg = STRBUF_INIT;\n \tstruct commit *original, *rewritten;\n-\tstruct rev_info revs;\n+\tstruct rev_info revs = { 0 };\n \tint ret;\n \n \targc = parse_options(argc, argv, prefix, options, usage, 0);\n-- \n2.53.0\n"},{"id":"538406","messageId":"abALiEDdNXCTzVux@pks.im","threadId":"65166","inReplyTo":"b0b8633f-be95-48eb-8244-d0e3f1a7be72@web.de","subject":"Re: [PATCH] history: initialize rev_info in cmd_history_reword()","fromName":"Patrick Steinhardt","fromEmail":"ps@pks.im","sentAt":"2026-03-10T12:16:08Z","receivedAt":"2026-03-10T12:16:13Z","isPatch":true,"sender":{"key":"ps@pks.im","avatar":"https://avatars.githubusercontent.com/u/4056630?v=4"},"body":"On Sun, Mar 08, 2026 at 10:57:02AM +0100, René Scharfe wrote:\n> git history reword expects a single valid revision argument and errors\n> out if it doesn't get it.  In that case the struct rev_info passed to\n> release_revisions() for cleanup is still uninitialized, which can result\n> in attempts to free(3) random pointers.  Avoid that by initializing the\n> structure.\n\nThis looks obviously correct to me. Thanks!\n\nPatrick\n"}]}