From: René Scharfe Date: Fri, 20 Mar 2026 18:54:21 GMT Subject: Re: [PATCH v1] path-walk: fix NULL pointer dereference in error message Message-ID: <98833ee0-4d63-4d72-9a0c-d668a421ece4@web.de> In-Reply-To: On 3/20/26 4:16 PM, D. Ben Knoble wrote: > > When we compute "child" in either preceding branch using lookup_tree > or lookup_blob, we only return NULL if !quiet in the object_as_type > calls (assuming we hit the "else" case there, anyway). But quiet==0 in > both callers along this path, so !quiet will be truthy and we'll > error() out there instead, never returning to add_tree_entries. error() just prints a message, it doesn't end the program. > Since I didn't quickly come up with a reproduction, I can't quite > prove this, anyway. It's also possible my analysis is based on code > that has since changed (I happened to have a537e3e6e9 (Merge branch > 'sp/send-email-validate-charset' into next, 2026-03-06) checked out at > the moment). We could build a tree referencing an object using a mismatched type to hit that. It's possible by removing the type check from builtin/mktree.c:mktree_line(), then using the resulting twisted tool: $ commit=$(git rev-parse HEAD) $ tree=$(printf "100644 blob $commit\tcommit\n" | git_evil mktree) > Still, fixing such obviously wrong dereference is good, but I wonder > if we should go further? > > You mentioned git-backfill with a tree missing from the local odb; do > you have a short reproduction script or test-case? I don't know about backfill, but this would work: $ echo $tree | git pack-objects --path-walk --all foo René