From: Brian Gernhardt Date: Mon, 23 Nov 2009 17:20:07 GMT Subject: Re: [PATCH 1/2] http-backend: Fix access beyond end of string. Message-ID: <9201C178-AABF-4320-B7B0-FEE841300E69@gernhardtsoftware.com> In-Reply-To: <7viqdb0zhs.fsf@alter.siamese.dyndns.org> On Nov 16, 2009, at 1:12 AM, Junio C Hamano wrote: > n = out[0].rm_eo - out[0].rm_so; /* allocation */ > ... validate and fail invalid method ... > cmd_arg = xmalloc(n); > memcpy(cmd_arg, dir + out[0].rm_so + 1, n-1); > cmd_arg[n-1] = '\0'; I just thought I'd point out that this change (committed as 48aec1b) fixed the problem I was having with t5541-http-push (and a couple others) hanging. Looks like that one extra byte was overwriting something that malloc/free wanted to keep intact on OS X. ~~ Brian