git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git 1.9.0 segfault

From
John Keeping <john@keeping.me.uk>
Date
Mar 8, 2014, 18:12 UTC
Message-ID
<20140308181218.GG18371@serenity.lan>
In-Reply-To
<20140308164651.GA32213@vauxhall.crustytoothpaste.net>
On Sat, Mar 08, 2014 at 04:46:51PM +0000, brian m. carlson wrote:
Show 12 quoted lines
> On Sat, Mar 08, 2014 at 04:23:43PM +0000, Guillaume Gelin wrote:
> > Hi,
> >
> > http://pastebin.com/Np7L54ar
> We're failing to rename because we got an EFAULT, and then we try to
> print the failing filename, and we get a segfault right here:
> 
> 			if (rename(src, dst) < 0 && !ignore_errors)
> 				die_errno (_("renaming '%s' failed"), src);
> 
> I don't know yet if dst is also bad, but clearly src is.  I'm looking
> into it.

The problem seems to be that we change argc when we append nested directories to the list and then continue looping over 'source' which has been realloc'd to be larger. But we do not realloc submodule_gitfile at the same time so we start writing beyond the end of the submodule_gitfile array.

The particular behaviour of glibc's malloc happens to mean (at least on my system) that this starts overwriting 'src'.

This fixes it for me:
-- >8 --
diff --git a/builtin/mv.c b/builtin/mv.c
index 7e26eb5..23f119a 100644
--- a/builtin/mv.c
+++ b/builtin/mv.c
@@ -180,6 +180,9 @@ int cmd_mv(int argc, const char **argv, const char *prefix)
 						modes = xrealloc(modes,
 								(argc + last - first)
 								* sizeof(enum update_mode));
+						submodule_gitfile = xrealloc(submodule_gitfile,
+								(argc + last - first)
+								* sizeof(char *));
 					}
 
 					dst = add_slash(dst);
Previous: brian m. carlsonNext: John Keeping
Message 3 of 21 in “git 1.9.0 segfault”
  1. Guillaume GelinMar 8, 2014
  2. brian m. carlsonMar 8, 2014
  3. John KeepingMar 8, 2014
  4. builtin/mv: fix out of bounds writeJohn Keeping, Mar 8, 2014
  5. brian m. carlsonMar 8, 2014
  6. builtin/mv: fix out of bounds writeJohn Keeping, Mar 8, 2014
  7. mv: prevent mismatched data when ignoring errors.brian m. carlson, Mar 8, 2014
  8. Jeff KingMar 11, 2014
  9. brian m. carlsonMar 11, 2014
  10. Junio C HamanoMar 11, 2014
  11. brian m. carlsonMar 12, 2014
  12. Thomas RastMar 15, 2014
  13. Jeff KingMar 16, 2014
  14. Junio C HamanoMar 16, 2014
  15. Junio C HamanoMar 17, 2014
  16. Michael HaggertyMar 17, 2014
  17. Eric SunshineMar 17, 2014
  18. Jeff KingMar 17, 2014
  19. Junio C HamanoMar 18, 2014
  20. mv: prevent mismatched data when ignoring errors.brian m. carlson, Mar 15, 2014
  21. Jeff KingMar 16, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.