From: D. Ben Knoble Date: Sun, 22 Mar 2026 14:21:06 GMT Subject: Re: [PATCH v1] path-walk: fix NULL pointer dereference in error message Message-ID: In-Reply-To: <98833ee0-4d63-4d72-9a0c-d668a421ece4@web.de> On Fri, Mar 20, 2026 at 2:54 PM René Scharfe wrote: > > On 3/20/26 4:16 PM, D. Ben Knoble wrote: > > > > When we compute "child" in either preceding branch using lookup_tree > > or lookup_blob, we only return NULL if !quiet in the object_as_type > > calls (assuming we hit the "else" case there, anyway). But quiet==0 in > > both callers along this path, so !quiet will be truthy and we'll > > error() out there instead, never returning to add_tree_entries. > > error() just prints a message, it doesn't end the program. Ah, thanks! The rest is probably moot then. > > > Since I didn't quickly come up with a reproduction, I can't quite > > prove this, anyway. It's also possible my analysis is based on code > > that has since changed (I happened to have a537e3e6e9 (Merge branch > > 'sp/send-email-validate-charset' into next, 2026-03-06) checked out at > > the moment). > > We could build a tree referencing an object using a mismatched > type to hit that. It's possible by removing the type check from > builtin/mktree.c:mktree_line(), then using the resulting twisted tool: > > $ commit=$(git rev-parse HEAD) > $ tree=$(printf "100644 blob $commit\tcommit\n" | git_evil mktree) > > > Still, fixing such obviously wrong dereference is good, but I wonder > > if we should go further? > > > > You mentioned git-backfill with a tree missing from the local odb; do > > you have a short reproduction script or test-case? > > I don't know about backfill, but this would work: > > $ echo $tree | git pack-objects --path-walk --all foo > > René > Thanks all. -- D. Ben Knoble