From: Jeff King Date: Wed, 12 Nov 2025 07:55:22 GMT Subject: [PATCH 0/9] asan bonanza Message-ID: <20251112075522.GA978866@coredump.intra.peff.net> This series fixes a handful of issues that ASan finds in our test suite if we tweak a few options to let it look deeper. The cache-tree one was reported to the security list. It's a real bug, but I don't think is an interesting vulnerability (it's a benign read off the end of an mmap'd file that is local and not generally under attacker control). The bitmap bug is also a real bug in new code that I think is not well exercised yet (+cc Taylor for that one). The fsck changes are for false positives in ASan, but I think it is reasonable for it to complain about this sketchy code. ;) I hope the result is nicer to read and reason about, but whether it is worth the churn may be debatable. Along the way we can turn a few knobs that will potentially help us find more problems down the road (but ordered so that "make SANITIZE=address" passes at each step of the series). [1/9]: compat/mmap: mark unused argument in git_munmap() [2/9]: pack-bitmap: handle name-hash lookups in incremental bitmaps [3/9]: Makefile: turn on NO_MMAP when building with ASan [4/9]: cache-tree: avoid strtol() on non-string buffer [5/9]: fsck: assert newline presence in fsck_ident() [6/9]: fsck: avoid strcspn() in fsck_ident() [7/9]: fsck: remove redundant date timestamp check [8/9]: fsck: avoid parse_timestamp() on buffer that isn't NUL-terminated [9/9]: t: enable ASan's strict_string_checks option Makefile | 1 + cache-tree.c | 45 ++++++++++++++++++++++---------- compat/mmap.c | 2 +- fsck.c | 71 ++++++++++++++++++++++++++++++++++++--------------- pack-bitmap.c | 27 +++++++++++++++++--- t/test-lib.sh | 1 + 6 files changed, 107 insertions(+), 40 deletions(-) -Peff