git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [patch] git: fix memory leak #2 in read-cache.c

From
IMIngo Molnar <mingo@elte.hu>
Date
Apr 14, 2005, 13:25 UTC
Message-ID
<20050414132550.GA25496@elte.hu>
In-Reply-To
<20050414123934.GA15420@elte.hu>
* Ingo Molnar <mingo@elte.hu> wrote:
> this patch fixes a memory leak in read-cache.c: when there's cache 
> entry collision we should free the previous one.
> +		free(active_cache[pos]);
>  		active_cache[pos] = ce;

i'm having second thoughs about this one: active_cache entries are not always malloc()-ed - e.g. read_cache() will construct them from the mmap() of the index file. Which must not be free()d!

one safe solution would be to malloc() all these entries and copy them over from the index file? Slightly slower but safer and free()-able when update-cache.c notices a collision. The (tested) patch below does this.

this would also make Martin Schlemmer's update-cache.c fix safe.

(without this second patch, free(active_cache[pos]) might crash, and that crash is would possibly be remote exploitable via a special repository that tricks the index file to look in a certain way.)

	Ingo
Signed-off-by: Ingo Molnar <mingo@elte.hu>

--- read-cache.c.orig +++ read-cache.c

@@ -453,10 +453,17 @@ int read_cache(void)
 
 	offset = sizeof(*hdr);
 	for (i = 0; i < hdr->entries; i++) {
-		struct cache_entry *ce = map + offset;
+		struct cache_entry *ce = map + offset, *tmp;
 		offset = offset + ce_size(ce);
-		active_cache[i] = ce;
+
+		tmp = malloc(ce_size(ce));
+		if (!tmp)
+			return error("malloc failed");
+		memcpy(tmp, ce, ce_size(ce));
+		active_cache[i] = tmp;
 	}
+	munmap(map, size);
+
 	return active_nr;
 
 unmap:
Previous: Ingo MolnarNext: Martin Schlemmer
Message 18 of 22 in “git: fix memory leak in checkout-cache.c”
  1. git: fix memory leak in checkout-cache.cIngo Molnar, Apr 14, 2005
  2. git: fix memory leak #2 in checkout-cache.cIngo Molnar, Apr 14, 2005
  3. git: cleanup in ls-tree.cIngo Molnar, Apr 14, 2005
  4. git: fix memory leaks in read-tree.cIngo Molnar, Apr 14, 2005
  5. git: fix rare memory leak in rev-tree.cIngo Molnar, Apr 14, 2005
  6. git: report parse_commit() errors in rev-tree.cIngo Molnar, Apr 14, 2005
  7. git: fix memory leak in show-diff.cIngo Molnar, Apr 14, 2005
  8. git: fix overflow in update-cache.cIngo Molnar, Apr 14, 2005
  9. cleanup: read_sha1_file() -> malloc_read_sha1_file()Ingo Molnar, Apr 14, 2005
  10. git: fix 1-byte overflow in show-files.cIngo Molnar, Apr 14, 2005
  11. Petr BaudisApr 17, 2005
  12. Ingo MolnarApr 18, 2005
  13. git: fix memory leaks in update-cache.cIngo Molnar, Apr 14, 2005
  14. git: clean up add_file_to_cache() in update-cache.cIngo Molnar, Apr 14, 2005
  15. git: fix memory leak #3 in update-cache.cIngo Molnar, Apr 14, 2005
  16. git: fix memory leaks in read-cache.cIngo Molnar, Apr 14, 2005
  17. git: fix memory leak #2 in read-cache.cIngo Molnar, Apr 14, 2005
  18. Ingo MolnarApr 14, 2005
  19. Martin SchlemmerApr 14, 2005
  20. Linus TorvaldsApr 14, 2005
  21. Ingo MolnarApr 14, 2005
  22. git: fix memory leak in write-tree.cIngo Molnar, Apr 14, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.