git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 3/2] remote: fix poential ref_map list corruption in ref_remove_duplicates

From
Julian Phillips <julian@quantumfyre.co.uk>
Date
Oct 26, 2009, 23:12 UTC
Message-ID
<20091026231215.91316.47162.julian@quantumfyre.co.uk>
In-Reply-To
<20091025212813.48498.51868.julian@quantumfyre.co.uk>

The prev pointer was not being updated when the peer_ref member pointer was NULL, which means that that any items in the list with a NULL peer_ref immediately preceeding a duplicate would be dropped without being freed.

Signed-off-by: Julian Phillips <julian@quantumfyre.co.uk>
---

Having fixed the access after free bug, I realised that there was still a problem. This one didn't show up in the tests - due to the rather specific circumstances required, but may occur in real use.

 remote.c |    3 +--
 1 files changed, 1 insertions(+), 2 deletions(-)
diff --git a/remote.c b/remote.c
index 1380b20..4f9f0cc 100644
--- a/remote.c
+++ b/remote.c
@@ -738,7 +738,7 @@ void ref_remove_duplicates(struct ref *ref_map)
 	struct string_list refs = { NULL, 0, 0, 0 };
 	struct string_list_item *item = NULL;
 	struct ref *prev = NULL, *next = NULL;
-	for (; ref_map; ref_map = next) {
+	for (; ref_map; prev = ref_map, ref_map = next) {
 		next = ref_map->next;
 		if (!ref_map->peer_ref)
 			continue;
@@ -758,7 +758,6 @@ void ref_remove_duplicates(struct ref *ref_map)
 
 		item = string_list_insert(ref_map->peer_ref->name, &refs);
 		item->util = ref_map;
-		prev = ref_map;
 	}
 	string_list_clear(&refs, 0);
 }
-- 
1.6.5.rc2
Previous: Julian PhillipsNext: Julian Phillips
Message 3 of 4 in “Speedup fetch with large numbers of refs”
  1. 0/2 Speedup fetch with large numbers of refsJulian Phillips, Oct 25, 2009
  2. 1/2 remote: Make ref_remove_duplicates faster for large numbers of refsJulian Phillips, Oct 25, 2009
  3. 3/2 remote: fix poential ref_map list corruption in ref_remove_duplicatesJulian Phillips, Oct 26, 2009
  4. 2/2 fetch: Speed up fetch of large numbers of refsJulian Phillips, Oct 25, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.