git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Possible segfault introduced in commit.c

From
MMMichael Mueller <mmueller@vigilantsw.com>
Date
Apr 25, 2012, 07:59 UTC
Message-ID
<CANV9Rr_ev+34Wd030cps0UbgjRYD0=L2DQhbrCOkBVWG-2xaug@mail.gmail.com>
Hi all,

As you might already know, we analyze git regularly with Sentry (our static analysis tool). Today it picked up a new NULL pointer dereference in commit.c:366:

    void commit_list_reverse(struct commit_list **list_p)
    {
        struct commit_list *prev = NULL, *curr = *list_p, *next;
        if (!list_p)
            return;
        /* function continues... */
    }

list_p is dereferenced on the first line, then tested for NULL on the very next statement. If it's possible that list_p is NULL, this will be a segfault. If it can't be NULL, then the check is unnecessary (and probably misleading).

Introduced here: https://github.com/gitster/git/commit/fbc08ea

Best, Mike

-- 
Mike Mueller
Phone: (401) 405-1525
Email: mmueller@vigilantsw.com

http://www.vigilantsw.com/
Next: Jeff King
Message 1 of 8 in “Possible segfault introduced in commit.c”
  1. Michael MuellerApr 25, 2012
  2. Jeff KingApr 25, 2012
  3. René ScharfeApr 25, 2012
  4. 1/3 sequencer: export commit_list_append()René Scharfe, Apr 25, 2012
  5. Junio C HamanoApr 25, 2012
  6. René ScharfeApr 30, 2012
  7. 2/3 revision: append to list instead of insert and reverseRené Scharfe, Apr 25, 2012
  8. 3/3 commit: remove commit_list_reverse()René Scharfe, Apr 25, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.