{"thread":{"id":"65664","subject":"[PATCH] apply: plug strbuf leak","startedAt":"2026-05-20T06:28:55Z","lastAt":"2026-05-20T06:48:30Z","messageCount":2,"participants":["Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"543732","messageId":"xmqq33zm4msa.fsf@gitster.g","threadId":"65664","inReplyTo":null,"subject":"[PATCH] apply: plug strbuf leak","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-05-20T06:28:53Z","receivedAt":"2026-05-20T06:28:55Z","isPatch":true,"body":"Depending on how read_patch_file() fails, it may already have read\nmany bytes into the supplied strbuf.  Either the caller or the callee\nshould release the strbuf.\n\nHere we choose to make the sole caller of the function responsible\nfor releasing it, as it makes the error handling slightly simpler.\n\nSigned-off-by: Junio C Hamano <gitster@pobox.com>\n---\n apply.c | 4 +++-\n 1 file changed, 3 insertions(+), 1 deletion(-)\n\ndiff --git a/apply.c b/apply.c\nindex 4aa1694cfa..0167902325 100644\n--- a/apply.c\n+++ b/apply.c\n@@ -4881,8 +4881,10 @@ static int apply_patch(struct apply_state *state,\n \n \tstate->patch_input_file = filename;\n \tstate->linenr = 1;\n-\tif (read_patch_file(&buf, fd) < 0)\n+\tif (read_patch_file(&buf, fd) < 0) {\n+\t\tstrbuf_release(&buf);\n \t\treturn -128;\n+\t}\n \toffset = 0;\n \twhile (offset < buf.len) {\n \t\tstruct patch *patch;\n-- \n2.54.0-398-ga4b2d32071\n\n"},{"id":"543734","messageId":"xmqqtss237b8.fsf@gitster.g","threadId":"65664","inReplyTo":"xmqq33zm4msa.fsf@gitster.g","subject":"Re: [PATCH] apply: plug strbuf leak","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-05-20T06:48:27Z","receivedAt":"2026-05-20T06:48:30Z","isPatch":true,"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> Depending on how read_patch_file() fails, it may already have read\n> many bytes into the supplied strbuf.  Either the caller or the callee\n> should release the strbuf.\n>\n> Here we choose to make the sole caller of the function responsible\n> for releasing it, as it makes the error handling slightly simpler.\n>\n> Signed-off-by: Junio C Hamano <gitster@pobox.com>\n> ---\n>  apply.c | 4 +++-\n>  1 file changed, 3 insertions(+), 1 deletion(-)\n>\n> diff --git a/apply.c b/apply.c\n> index 4aa1694cfa..0167902325 100644\n> --- a/apply.c\n> +++ b/apply.c\n> @@ -4881,8 +4881,10 @@ static int apply_patch(struct apply_state *state,\n>  \n>  \tstate->patch_input_file = filename;\n>  \tstate->linenr = 1;\n> -\tif (read_patch_file(&buf, fd) < 0)\n> +\tif (read_patch_file(&buf, fd) < 0) {\n> +\t\tstrbuf_release(&buf);\n>  \t\treturn -128;\n> +\t}\n\nAh, my mistake.  This was one of the two \"oh, we found longstanding\nissues immediately after enabling EXPENSIVE tests on\" fixes Peff\nalready fixed for us.\n\n>  \toffset = 0;\n>  \twhile (offset < buf.len) {\n>  \t\tstruct patch *patch;\n"}]}