git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/3] pretty.c: fix null pointer dereference

From
Jeff King <peff@peff.net>
Date
Feb 24, 2026, 08:41 UTC
Message-ID
<20260224084149.GA986367@coredump.intra.peff.net>
In-Reply-To
<aZ1JND7sGspCJEoc@exploit>
On Tue, Feb 24, 2026 at 08:08:35AM +0100, Mirko Faina wrote:
Show 45 quoted lines
> On Mon, Feb 23, 2026 at 10:25:07PM -0800, Junio C Hamano wrote:
> > Interesting.
> > 
> > Are any of the existing calls to this function that passes
> > CMIT_FMT_USERFORMAT trigger a segfault with certain condition?
> > 
> > For example, there are only two places where CMIT_FMT_USERFORMAT is
> > assigned to something.  One is save_user_format() where user_format
> > gets a non NULL string before rev->commit_format gets assigned
> > CMIT_FMT_USERFORMAT.  Another is git_pretty_formats_config() that
> > parses configuration variables "pretty.*" and populate
> > commit_formats map.  This is later used in get_commit_format() and
> > that function always calls save_user_format() we just saw when the
> > format used is CMIT_FMT_USERFORMAT.  So the existing code paths seem
> > to be safe by design.
> > 
> > What I am wondering is if a NULL user_format should be flagged as a
> > programming error, instead of getting swept under the rug like this
> > patch does.  IOW,
> > 
> > 	int commit_format_is_empty(enum cmit_fmt fmt)
> > 	{
> > 		if (fmt != CMIT_FMT_USERFORMAT)
> > 			return 0;
> > 		if (!user_format)
> > 			BUG("never called save_user_format() and using USERFORMAT?");
> > 		return !*user_format;
> > 	}
> 
> This doesn't convince me, I think it is a bug. If dereferencing NULL was
> done on purpose why not use die() instead? Also, the only way for us to
> check user_format is through commit_format_is_empty() as it is static.
> In a complex config setup it might be useful to double check just to be
> sure, and I wouldn't want the program to crash on a failed check.
> 
> save_user_format() is not available neither, so evaluation of the format
> string has to be done through get_commit_format(). If I pass any of the
> predefined formats (CMIT_FMT_*) get_commit_format() won't set
> user_format. So the only way for us to check if it was set is through
> commit_format_is_empty() (well technically there's
> rev_info->commit_format but it still doesn't feel like it was
> intentional).
> 
> But if the intended behaviour was for the program to crash then I take
> issue with the name.

I am not quite sure what you are asking. No, the intent of that function is not to crash. It is to check whether the user passed us an empty string. Like the "git diff-tree --format= $commit" example given in the commit message of b9c7d6e433 (pretty: make empty userformats truly empty, 2014-07-29). If they did, then the first character of the string will be the NUL terminator.

So dropping the "*" as your patch 1/3 does is just wrong. It is losing the check for an empty string and replacing it with a check for a NULL pointer.

The user_format string should never be NULL if we are using CMIT_FMT_USERFORMAT. That's not checked for explicitly here, but is an assumption of the pretty.c code. If there's some way to violate that assumption, that's a bug (but it sounds from digging that there isn't).

If you have _new_ code which is using CMIT_FMT_USERFORMAT without setting user_format to a non-NULL value, we might need to work around that assumption. But I think what your 2/3 is doing is not quite at the right level, which is the source of the trouble. I'll respond separately to that patch.

-Peff
Previous: Mirko FainaNext: Mirko Faina
Message 108 of 113 in “format-patch: better commit list for cover letter”
  1. format-patch: better commit list for cover letterMirko Faina, Feb 20, 2026
  2. format-patch: better commit list for cover letterMirko Faina, Feb 20, 2026
  3. Mirko FainaFeb 21, 2026
  4. Junio C HamanoFeb 21, 2026
  5. Mirko FainaFeb 21, 2026
  6. Junio C HamanoFeb 21, 2026
  7. Junio C HamanoFeb 21, 2026
  8. Mirko FainaFeb 21, 2026
  9. Junio C HamanoFeb 21, 2026
  10. Mirko FainaFeb 21, 2026
  11. 0/3 format-patch: add cover-letter-format optionMirko Faina, Feb 24, 2026
  12. Mirko FainaFeb 24, 2026
  13. 0/2 format-patch: add cover-letter-format optionMirko Faina, Feb 24, 2026
  14. 1/2 format-patch: add ability to use alt cover formatMirko Faina, Feb 24, 2026
  15. Junio C HamanoFeb 24, 2026
  16. Mirko FainaFeb 24, 2026
  17. Junio C HamanoFeb 25, 2026
  18. Jeff KingFeb 25, 2026
  19. Junio C HamanoFeb 24, 2026
  20. Jeff KingFeb 25, 2026
  21. Mirko FainaFeb 25, 2026
  22. 2/2 format-patch: add commitListFormat configMirko Faina, Feb 24, 2026
  23. Junio C HamanoFeb 24, 2026
  24. Mirko FainaFeb 25, 2026
  25. Junio C HamanoFeb 25, 2026
  26. Mirko FainaFeb 26, 2026
  27. Junio C HamanoFeb 26, 2026
  28. Junio C HamanoFeb 24, 2026
  29. Junio C HamanoFeb 24, 2026
  30. Mirko FainaFeb 25, 2026
  31. Junio C HamanoFeb 25, 2026
  32. 0/4 format-patch: add cover-letter-format optionMirko Faina, Feb 27, 2026
  33. 1/4 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Feb 27, 2026
  34. 2/4 format-patch: move cover letter summary generationMirko Faina, Feb 27, 2026
  35. 4/4 format-patch: add commitListFormat configMirko Faina, Feb 27, 2026
  36. 3/4 format-patch: add ability to use alt cover formatMirko Faina, Feb 27, 2026
  37. Junio C HamanoFeb 27, 2026
  38. Mirko FainaFeb 27, 2026
  39. 0/4 format-patch: add cover-letter-format optionMirko Faina, Feb 27, 2026
  40. 1/4 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Feb 27, 2026
  41. 3/4 format-patch: add ability to use alt cover formatMirko Faina, Feb 27, 2026
  42. 2/4 format-patch: move cover letter summary generationMirko Faina, Feb 27, 2026
  43. 4/4 format-patch: add commitListFormat configMirko Faina, Feb 27, 2026
  44. 5/4 docs: add usage for the cover-letter fmt featureMirko Faina, Feb 27, 2026
  45. Junio C HamanoFeb 27, 2026
  46. Mirko FainaFeb 27, 2026
  47. Junio C HamanoFeb 27, 2026
  48. 0/5 format-patch: add cover-letter-format optionMirko Faina, Feb 27, 2026
  49. 1/5 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Feb 27, 2026
  50. 2/5 format-patch: move cover letter summary generationMirko Faina, Feb 27, 2026
  51. 3/5 format-patch: add ability to use alt cover formatMirko Faina, Feb 27, 2026
  52. 4/5 format-patch: add commitListFormat configMirko Faina, Feb 27, 2026
  53. 5/5 docs: add usage for the cover-letter fmt featureMirko Faina, Feb 27, 2026
  54. Junio C HamanoMar 6, 2026
  55. Mirko FainaMar 6, 2026
  56. 0/5 format-patch: add cover-letter-format optionMirko Faina, Mar 6, 2026
  57. 1/5 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Mar 6, 2026
  58. 2/5 format-patch: move cover letter summary generationMirko Faina, Mar 6, 2026
  59. 3/5 format-patch: add ability to use alt cover formatMirko Faina, Mar 6, 2026
  60. Junio C HamanoMar 10, 2026
  61. Mirko FainaMar 10, 2026
  62. 4/5 format-patch: add commitListFormat configMirko Faina, Mar 6, 2026
  63. 5/5 docs: add usage for the cover-letter fmt featureMirko Faina, Mar 6, 2026
  64. Junio C HamanoMar 6, 2026
  65. 0/5 format-patch: add cover-letter-format optionMirko Faina, Mar 6, 2026
  66. 1/5 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Mar 6, 2026
  67. Phillip WoodMar 10, 2026
  68. Mirko FainaMar 10, 2026
  69. 2/5 format-patch: move cover letter summary generationMirko Faina, Mar 6, 2026
  70. 3/5 format-patch: add ability to use alt cover formatMirko Faina, Mar 6, 2026
  71. Phillip WoodMar 10, 2026
  72. MroikMar 10, 2026
  73. 4/5 format-patch: add commitListFormat configMirko Faina, Mar 6, 2026
  74. Phillip WoodMar 10, 2026
  75. Junio C HamanoMar 10, 2026
  76. Mirko FainaMar 10, 2026
  77. Phillip WoodMar 11, 2026
  78. Junio C HamanoMar 11, 2026
  79. Phillip WoodMar 11, 2026
  80. Junio C HamanoMar 11, 2026
  81. Mirko FainaMar 10, 2026
  82. 5/5 docs: add usage for the cover-letter fmt featureMirko Faina, Mar 6, 2026
  83. Bert WesargMar 10, 2026
  84. Phillip WoodMar 10, 2026
  85. 0/4 format-patch: add cover-letter-format optionMirko Faina, Mar 12, 2026
  86. 1/4 format-patch: move cover letter summary generationMirko Faina, Mar 12, 2026
  87. Junio C HamanoMar 12, 2026
  88. 2/4 format-patch: add ability to use alt cover formatMirko Faina, Mar 12, 2026
  89. Junio C HamanoMar 12, 2026
  90. Mirko FainaMar 12, 2026
  91. Junio C HamanoMar 12, 2026
  92. Junio C HamanoMar 12, 2026
  93. Phillip WoodMar 13, 2026
  94. Junio C HamanoMar 13, 2026
  95. Mirko FainaMar 13, 2026
  96. Junio C HamanoMar 13, 2026
  97. 3/4 format-patch: add "chronological" format for coverMirko Faina, Mar 12, 2026
  98. Junio C HamanoMar 12, 2026
  99. 4/4 format-patch: add commitListFormat configMirko Faina, Mar 12, 2026
  100. Junio C HamanoMar 12, 2026
  101. Junio C HamanoMar 12, 2026
  102. Mirko FainaMar 12, 2026
  103. Junio C HamanoMar 12, 2026
  104. 1/3 pretty.c: fix null pointer dereferenceMirko Faina, Feb 24, 2026
  105. Junio C HamanoFeb 24, 2026
  106. Mirko FainaFeb 24, 2026
  107. Mirko FainaFeb 24, 2026
  108. Jeff KingFeb 24, 2026
  109. 2/3 format-patch: add ability to use alt cover formatMirko Faina, Feb 24, 2026
  110. Jeff KingFeb 24, 2026
  111. Mirko FainaFeb 24, 2026
  112. Jeff KingFeb 24, 2026
  113. 3/3 format-patch: add commitListFormat configMirko Faina, Feb 24, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.