Re: [PATCH v1] path-walk: fix NULL pointer dereference in error message
- From
René Scharfe <l.s.r@web.de>
- Date
- Mar 20, 2026, 18:54 UTC
- Message-ID
- <98833ee0-4d63-4d72-9a0c-d668a421ece4@web.de>
- In-Reply-To
- <CALnO6CDnwYaAPhp67kaYWtV48ULjWAR6ks1khVXmSs1oWUbRDQ@mail.gmail.com>
On 3/20/26 4:16 PM, D. Ben Knoble wrote:
Show 6 quoted lines
> > When we compute "child" in either preceding branch using lookup_tree > or lookup_blob, we only return NULL if !quiet in the object_as_type > calls (assuming we hit the "else" case there, anyway). But quiet==0 in > both callers along this path, so !quiet will be truthy and we'll > error() out there instead, never returning to add_tree_entries.
error() just prints a message, it doesn't end the program.
Show 5 quoted lines
> Since I didn't quickly come up with a reproduction, I can't quite > prove this, anyway. It's also possible my analysis is based on code > that has since changed (I happened to have a537e3e6e9 (Merge branch > 'sp/send-email-validate-charset' into next, 2026-03-06) checked out at > the moment).
We could build a tree referencing an object using a mismatched type to hit that. It's possible by removing the type check from builtin/mktree.c:mktree_line(), then using the resulting twisted tool:
$ commit=$(git rev-parse HEAD) $ tree=$(printf "100644 blob $commit\tcommit\n" | git_evil mktree)
Show 5 quoted lines
> Still, fixing such obviously wrong dereference is good, but I wonder > if we should go further? > > You mentioned git-backfill with a tree missing from the local odb; do > you have a short reproduction script or test-case?
I don't know about backfill, but this would work:
$ echo $tree | git pack-objects --path-walk --all foo
René