git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] config: don't segfault when given --path with a missing value

From
Jeff King <peff@peff.net>
Date
Nov 15, 2012, 16:08 UTC
Message-ID
<20121115160847.GA6157@sigill.intra.peff.net>
In-Reply-To
<1352868604-20459-1-git-send-email-cmn@elego.de>
On Tue, Nov 13, 2012 at 08:50:04PM -0800, Carlos Martín Nieto wrote:
Show 7 quoted lines
> When given a variable without a value, such as '[section] var' and
> asking git-config to treat it as a path, git_config_pathname returns
> an error and doesn't modify its output parameter. show_config assumes
> that the call is always successful and sets a variable to indicate
> that vptr should be freed. In case of an error however, trying to do
> this will cause the program to be killed, as it's pointing to memory
> in the stack.
Whoops.
> Set the must_free_vptr flag depending on the return value of
> git_config_pathname so it's accurate.

That is definitely the right thing to do. But do we also need to take note of the error for later? After this code:

>  	} else if (types == TYPE_PATH) {
> -		git_config_pathname(&vptr, key_, value_);
> -		must_free_vptr = 1;
> +		must_free_vptr = !git_config_pathname(&vptr, key_, value_);

We don't have any clue that nothing got written into vptr. Which means it still points at the stack buffer "value", which contains uninitialized bytes. We will later try to print it, thinking it has the expanded path in it.

Do we need something like:
  if (!git_config_pathname(&vptr, key_, value_))
          must_free_vptr = 1;
  else
          vptr = "";
?
-Peff
Previous: Carlos Martín NietoNext: Jeff King
Message 2 of 6 in “config: don't segfault when given --path with a missing value”
  1. config: don't segfault when given --path with a missing valueCarlos Martín Nieto, Nov 14, 2012
  2. Jeff KingNov 15, 2012
  3. Jeff KingNov 15, 2012
  4. Jeff KingNov 15, 2012
  5. config: don't segfault when given --path with a missing valueCarlos Martín Nieto, Nov 15, 2012
  6. Jeff KingNov 15, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.