From: Yuvraj Singh Chauhan Date: Fri, 20 Mar 2026 11:48:23 GMT Subject: [PATCH v1] path-walk: fix NULL pointer dereference in error message Message-ID: <20260320114823.3151961-1-ysinghcin@gmail.com> When lookup_tree() or lookup_blob() cannot find a tree entry's object, 'o' is set to NULL via: o = child ? &child->object : NULL; The subsequent null-check catches this correctly, but then dereferences 'o' to format the error message: error(_("failed to find object %s"), oid_to_hex(&o->oid)); This causes a segfault instead of the intended diagnostic output. Fix this by using &entry.oid instead. 'entry' is the struct name_entry populated by tree_entry() on each loop iteration and holds the OID of the failing lookup -- which is exactly what the error should report. This crash is reachable via git-backfill(1) when a tree entry's object is absent from the local object database. Signed-off-by: Yuvraj Singh Chauhan --- path-walk.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/path-walk.c b/path-walk.c index 364e4cfa19..839582380c 100644 --- a/path-walk.c +++ b/path-walk.c @@ -171,7 +171,7 @@ static int add_tree_entries(struct path_walk_context *ctx, if (!o) { error(_("failed to find object %s"), - oid_to_hex(&o->oid)); + oid_to_hex(&entry.oid)); return -1; } -- 2.53.0.582.gca1db8a0f7