git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] revision: fix missing null for freed memory

From
Emily Klassen <forivall@gmail.com>
Date
Feb 10, 2025, 20:56 UTC
Message-ID
<CADY4h_o_wfUpjSBhWa9TPU_G-G8qpENpUeOKGQDY8dq6Zb2+qg@mail.gmail.com>
In-Reply-To
<xmqqtt91dbzt.fsf@gitster.g>
On Mon, Feb 10, 2025 at 8:02 AM Junio C Hamano <gitster@pobox.com> wrote:
Show 13 quoted lines
>
> Emily M Klassen <forivall@gmail.com> writes:
>
> > Subject: Re: [PATCH] revision: fix missing null for freed memory
> >
> > "git log --graph --no-graph" missed cleaning up the output_prefix and
> > output_prefix_data pointers. This resulted in a segfault when using "--patch",
> > "--name-status" or "--name-only", as the output_prefix_data continued to be in
> > use after free()
>
> Rereading the title, I cannot make sense out of "fix missing null"
> and guess what it wants to say.  Is "null" here used as a verb to
> mean "to assign a NULL to a variable that points at ..."?

Yeah, this was meant to say something like "fix missing null assignment after freeing graph data", and I didn't really have the energy to think of a better summary at the time.

Show 14 quoted lines
>
>     revision: clear graph callback upon "--no-graph"
>
>     "git log --graph --no-graph" first populates the .output_prefix
>     member of diffopt, which is a callback function, to compute
>     "--graph" header, and then discards the data the callback needs
>     to compute the graph header but forgets to clear .output_prefix
>     pointer in response to "--no-graph".  At runtime, we end up
>     calling the function that we should not.
>
>     Clear the member to stop making callback, and for a better
>     hyginene, also clear the pointer pointing at a freed memory.
>
> or something?
Yup, this works well. A small bit of rephrasing for readability:
    revision: clear graph prefix callback upon "--no-graph"
    "git log --graph --no-graph" misses some cleanup: handling
    "--graph", it assigns the .output_prefix member of diffopt, which
    is a callback function to compute the graph prefix when displaying
    a diff. Then, when handling "--no-graph" it discards the data the
    callback needs to compute the graph header but forgets to clear
    .output_prefix pointer.  At runtime, we  call the function when we
    should not. It also passes a stale pointer to the data, which leads
    to a segfault when the callback is used for "--patch",
    "--name-status" or "--name-only".
    Clear the member to stop the callback from being called, and for
    hygiene, also clear the pointer pointing at a freed memory.
>
> Other than that, as I said earlier, the patch looks good.
>
> Thanks.

Awesome. I'll also add a test before re-submitting, as mentioned in your other message.

Thanks for the feedback!
Show 22 quoted lines
>
> > Signed-off-by: Emily M Klassen <forivall@gmail.com>
> > ---
> > I previously reported this a few hours ago, and ended up digging in and figuring
> > it out. I'll make sure to bottom reply in the follow ups to this patch.
> >
> >  revision.c | 2 ++
> >  1 file changed, 2 insertions(+)
> >
> > diff --git a/revision.c b/revision.c
> > index 474fa1e767..84cb028e11 100644
> > --- a/revision.c
> > +++ b/revision.c
> > @@ -2615,6 +2615,8 @@ static int handle_revision_opt(struct rev_info *revs, int argc, const char **arg
> >               graph_clear(revs->graph);
> >               revs->graph = graph_init(revs);
> >       } else if (!strcmp(arg, "--no-graph")) {
> > +             revs->diffopt.output_prefix = NULL;
> > +             revs->diffopt.output_prefix_data = NULL;
> >               graph_clear(revs->graph);
> >               revs->graph = NULL;
> >       } else if (!strcmp(arg, "--encode-email-headers")) {
Previous: Junio C HamanoNext: Junio C Hamano
Message 4 of 12 in “revision: fix missing null for freed memory”
  1. revision: fix missing null for freed memoryEmily M Klassen, Feb 8, 2025
  2. Junio C HamanoFeb 8, 2025
  3. Junio C HamanoFeb 10, 2025
  4. Emily KlassenFeb 10, 2025
  5. Junio C HamanoFeb 13, 2025
  6. Patrick SteinhardtFeb 11, 2025
  7. D. Ben KnobleFeb 11, 2025
  8. D. Ben KnobleFeb 11, 2025
  9. Jeff KingFeb 11, 2025
  10. Junio C HamanoFeb 11, 2025
  11. Patrick SteinhardtFeb 12, 2025
  12. Ben KnobleFeb 13, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.