git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] fix segv with corrupt tag object

From
Stefan Sperling <stsp@stsp.name>
Date
Aug 24, 2019, 23:09 UTC
Message-ID
<20190824230944.GA14132@jessup.stsp.name>

A tag object which lacks newlines won't be parsed correctly. Git fails to detect this error and crashes due to a NULL deref:

$ git archive 1.0.0 Segmentation fault (core dumped) $ git checkout 1.0.0 Segmentation fault (core dumped) $

See the attached tarball for a reproduction repository. Also mirrored at https://stsp.name/git-checkout-tag-segv-repo.tgz

With the patch below:

$ git checkout 1.0.0 fatal: reference is not a tree: 1.0.0 $ git archive 1.0.0 fatal: not a tree object: a99665eea5ee50171b5b7249880aa2ae35e35823 $

diff --git a/tree.c b/tree.c
index 4720945e6a..92d8bd57a3 100644
--- a/tree.c
+++ b/tree.c
@@ -252,9 +252,11 @@ struct tree *parse_tree_indirect(const struct object_id *oid)
 			return (struct tree *) obj;
 		else if (obj->type == OBJ_COMMIT)
 			obj = &(get_commit_tree(((struct commit *)obj))->object);
-		else if (obj->type == OBJ_TAG)
+		else if (obj->type == OBJ_TAG) {
 			obj = ((struct tag *) obj)->tagged;
-		else
+			if (!obj)
+				return NULL;
+		} else
 			return NULL;
 		if (!obj->parsed)
 			parse_object(the_repository, &obj->oid);
Next: René Scharfe
Message 1 of 8 in “fix segv with corrupt tag object”
  1. fix segv with corrupt tag objectStefan Sperling, Aug 24, 2019
  2. René ScharfeAug 25, 2019
  3. Stefan SperlingAug 26, 2019
  4. Junio C HamanoAug 26, 2019
  5. Stefan SperlingAug 26, 2019
  6. Jeff KingAug 26, 2019
  7. René ScharfeAug 29, 2019
  8. Junio C HamanoAug 30, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.