git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 1/4] worktree add: don't read out of bounds in worktree_basename()

From
René Scharfe <l.s.r@web.de>
Date
Aug 25, 2026, 18:03 UTC
Message-ID
<20260825180350.2099-2-l.s.r@web.de>
In-Reply-To
<20260825180350.2099-1-l.s.r@web.de>

When we search for the start of the basename and `len` is zero, `name` ends up being `path` - 1, out of bounds. Avoid that by checking before decrementing.

Fixes https://github.com/git-for-windows/git/issues/6346.
Original-patch-by: Matthias Aßhauer <mha1993@live.de>
Signed-off-by: René Scharfe <l.s.r@web.de>
---
 builtin/worktree.c | 8 +++-----
 1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/builtin/worktree.c b/builtin/worktree.c
index 654d27c3e1..a770dd5ead 100644
--- a/builtin/worktree.c
+++ b/builtin/worktree.c
@@ -303,11 +303,9 @@ static const char *worktree_basename(const char *path, int *olen)
 	while (len && is_dir_sep(path[len - 1]))
 		len--;
 
-	for (name = path + len - 1; name > path; name--)
-		if (is_dir_sep(*name)) {
-			name++;
-			break;
-		}
+	name = path + len;
+	while (name > path && !is_dir_sep(name[-1]))
+		name--;
 
 	*olen = len;
 	return name;
-- 
2.55.0
Previous: Junio C HamanoNext: René Scharfe
Message 9 of 10 in “worktree add: worktree_basename() fixes”
  1. 0/4 worktree add: worktree_basename() fixesRené Scharfe, Aug 25, 2026
  2. 4/4 worktree add: let worktree_basename() return string copyRené Scharfe, Aug 25, 2026
  3. Junio C HamanoAug 25, 2026
  4. René ScharfeAug 26, 2026
  5. Junio C HamanoAug 26, 2026
  6. Junio C HamanoAug 31, 2026
  7. 3/4 worktree add: trim slashes when deriving branch name from pathRené Scharfe, Aug 25, 2026
  8. Junio C HamanoAug 25, 2026
  9. 1/4 worktree add: don't read out of bounds in worktree_basename()René Scharfe, Aug 25, 2026
  10. 2/4 worktree add: reject separator-only pathRené Scharfe, Aug 25, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.