git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] strbuf_readlink semantics update.

From
Pierre Habouzit <madcoder@debian.org>
Date
Dec 23, 2008, 10:21 UTC
Message-ID
<20081223102127.GA21485@artemis.corp>
In-Reply-To
<1230026749-25360-1-git-send-email-madcoder@debian.org>

when readlink fails, the strbuf shall not be destroyed. It's not how read_file_or_gitlink works for example.

Fix strbuf_readlink callers to destroy the buffer when appropriate.

Fix read_old_data possible leaks in case of errors, since even when no data has been read, the strbufs may have grown to prepare the reads. strbuf_release must be called on them.

Signed-off-by: Pierre Habouzit <madcoder@debian.org>
---
  I know it somehow add lines to the callers, but it's actually more
  important to keep consistency among the strbuf APIs than to save 10
  SLOCs.
 builtin-apply.c |    8 ++++++--
 combine-diff.c  |    1 +
 diff.c          |    4 +++-
 read-cache.c    |    4 +++-
 sha1_file.c     |    1 +
 strbuf.c        |    2 +-
 6 files changed, 15 insertions(+), 5 deletions(-)
diff --git a/builtin-apply.c b/builtin-apply.c
index 07244b0..c1fe9ca 100644
--- a/builtin-apply.c
+++ b/builtin-apply.c
@@ -2306,8 +2306,10 @@ static int apply_data(struct patch *patch, struct stat *st, struct cache_entry *
 		/* We have a patched copy in memory use that */
 		strbuf_add(&buf, tpatch->result, tpatch->resultsize);
 	} else if (cached) {
-		if (read_file_or_gitlink(ce, &buf))
+		if (read_file_or_gitlink(ce, &buf)) {
+			strbuf_release(&buf);
 			return error("read of %s failed", patch->old_name);
+		}
 	} else if (patch->old_name) {
 		if (S_ISGITLINK(patch->old_mode)) {
 			if (ce) {
@@ -2320,8 +2322,10 @@ static int apply_data(struct patch *patch, struct stat *st, struct cache_entry *
 				patch->fragments = NULL;
 			}
 		} else {
-			if (read_old_data(st, patch->old_name, &buf))
+			if (read_old_data(st, patch->old_name, &buf)) {
+				strbuf_release(&buf);
 				return error("read of %s failed", patch->old_name);
+			}
 		}
 	}
 
diff --git a/combine-diff.c b/combine-diff.c
index bccc018..674745d 100644
--- a/combine-diff.c
+++ b/combine-diff.c
@@ -706,6 +706,7 @@ static void show_patch_diff(struct combine_diff_path *elem, int num_parent,
 			struct strbuf buf = STRBUF_INIT;
 
 			if (strbuf_readlink(&buf, elem->path, st.st_size) < 0) {
+				strbuf_release(&buf);
 				error("readlink(%s): %s", elem->path,
 				      strerror(errno));
 				return;
diff --git a/diff.c b/diff.c
index b57d9ac..41f7e1c 100644
--- a/diff.c
+++ b/diff.c
@@ -1778,8 +1778,10 @@ int diff_populate_filespec(struct diff_filespec *s, int size_only)
 		if (S_ISLNK(st.st_mode)) {
 			struct strbuf sb = STRBUF_INIT;
 
-			if (strbuf_readlink(&sb, s->path, s->size))
+			if (strbuf_readlink(&sb, s->path, s->size)) {
+				strbuf_release(&sb);
 				goto err_empty;
+			}
 			s->size = sb.len;
 			s->data = strbuf_detach(&sb, NULL);
 			s->should_free = 1;
diff --git a/read-cache.c b/read-cache.c
index db166da..9673d91 100644
--- a/read-cache.c
+++ b/read-cache.c
@@ -104,8 +104,10 @@ static int ce_compare_link(struct cache_entry *ce, size_t expected_size)
 	enum object_type type;
 	struct strbuf sb = STRBUF_INIT;
 
-	if (strbuf_readlink(&sb, ce->name, expected_size))
+	if (strbuf_readlink(&sb, ce->name, expected_size)) {
+		strbuf_release(&sb);
 		return -1;
+	}
 
 	buffer = read_sha1_file(ce->sha1, &type, &size);
 	if (buffer) {
diff --git a/sha1_file.c b/sha1_file.c
index 52d1ead..a62b53d 100644
--- a/sha1_file.c
+++ b/sha1_file.c
@@ -2538,6 +2538,7 @@ int index_path(unsigned char *sha1, const char *path, struct stat *st, int write
 	case S_IFLNK:
 		if (strbuf_readlink(&sb, path, st->st_size)) {
 			char *errstr = strerror(errno);
+			strbuf_release(&sb);
 			return error("readlink(\"%s\"): %s", path,
 			             errstr);
 		}
diff --git a/strbuf.c b/strbuf.c
index 254a7ee..b1f2a97 100644
--- a/strbuf.c
+++ b/strbuf.c
@@ -311,7 +311,7 @@ int strbuf_readlink(struct strbuf *sb, const char *path, size_t hint)
 		/* .. the buffer was too small - try again */
 		hint *= 2;
 	}
-	strbuf_release(sb);
+	sb->buf[sb->len] = '\0';
 	return -1;
 }
 
-- 
1.6.1.rc4.306.g849c2
Previous: Pierre HabouzitNext: Linus Torvalds
Message 26 of 33 in “Be careful about lstat()-vs-readlink()”
  1. 0/5 Be careful about lstat()-vs-readlink()Linus Torvalds, Dec 17, 2008
  2. 1/5 Add generic 'strbuf_readlink()' helper functionLinus Torvalds, Dec 17, 2008
  3. 2/5 Make 'ce_compare_link()' use the new 'strbuf_readlink()'Linus Torvalds, Dec 17, 2008
  4. 3/5 Make 'index_path()' use 'strbuf_readlink()'Linus Torvalds, Dec 17, 2008
  5. 4/5 Make 'diff_populate_filespec()' use the new 'strbuf_readlink()'Linus Torvalds, Dec 17, 2008
  6. 5/5 Make 'prepare_temp_file()' ignore st_size for symlinksLinus Torvalds, Dec 17, 2008
  7. 6/5 make_absolute_path(): check bounds when seeing an overlong symlinkJunio C Hamano, Dec 17, 2008
  8. 7/5 builtin-blame.c: use strbuf_readlink()Junio C Hamano, Dec 17, 2008
  9. 8/5 combine-diff.c: use strbuf_readlink()Junio C Hamano, Dec 17, 2008
  10. Linus TorvaldsDec 17, 2008
  11. Junio C HamanoDec 17, 2008
  12. Junio C HamanoDec 17, 2008
  13. Mark BurtonDec 18, 2008
  14. Linus TorvaldsDec 18, 2008
  15. René ScharfeDec 18, 2008
  16. Linus TorvaldsDec 18, 2008
  17. Olivier GalibertDec 18, 2008
  18. René ScharfeDec 18, 2008
  19. René ScharfeDec 18, 2008
  20. diff.c: fix pointer type warningRené Scharfe, Dec 19, 2008
  21. Junio C HamanoDec 19, 2008
  22. Junio C HamanoDec 17, 2008
  23. Jay SoffianDec 17, 2008
  24. Linus TorvaldsDec 17, 2008
  25. strbuf_readlink semantics update.Pierre Habouzit, Dec 23, 2008
  26. Pierre HabouzitDec 23, 2008
  27. Linus TorvaldsDec 23, 2008
  28. Pierre HabouzitDec 24, 2008
  29. René ScharfeDec 24, 2008
  30. Junio C HamanoDec 25, 2008
  31. Pierre HabouzitJan 4, 2009
  32. strbuf: instate cleanup rule in case of non-memory errorsRené Scharfe, Jan 6, 2009
  33. Junio C HamanoJan 7, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.