git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Fix leak in credential_apply_config

From
Jeff King <peff@peff.net>
Date
Aug 20, 2021, 17:56 UTC
Message-ID
<YR/sxISzR0RebVMZ@coredump.intra.peff.net>
In-Reply-To
<ffa1786e-f69f-3d76-98dc-7fa5cdbd31c0@gmail.com>
On Fri, Aug 20, 2021 at 10:58:56AM -0400, Derrick Stolee wrote:
Show 22 quoted lines
> On 8/20/2021 4:44 AM, Mike Hommey wrote:
> >  	normalized_url = url_normalize(url.buf, &config.url);
> >  
> >  	git_config(urlmatch_config_entry, &config);
> > +	string_list_clear(&config.vars, 1);
> >  	free(normalized_url);
> >  	strbuf_release(&url);
> 
> A good find! This is obviously correct and a valuable change
> to make. If you are interested in doing a little extra work,
> then I think there is something more we could do here.
> 
> I took a look at the rest of "struct urlmatch_config" to see
> if anything else needed to be cleared, and it turns out that
> config.url.url is an allocated string, but happens to be
> equal to normalized_url, which is freed here.
> 
> Perhaps the optimal organization would be to have a
> clear_urlmatch_config() method that clears all allocated data
> within the config, and change things like url_normalize()
> return a 'const char *' to make it clear that the url should
> be freed somewhere else.

Yeah, I had the same thought; it feels like we're peeking into details of how url_config works (especially the knowledge that we we should be passing free_util).

> It would help unify the handling of code that is somewhat
> duplicated (but slightly different each time) across
> credential_apply_config(), http_init(), get_urlmatch(),
> and cmd__urlmatch_normalization().
Agreed. It looks like http_init() has the same leak that is fixed here.
-Peff
Previous: Derrick StoleeNext: Jeff King
Message 3 of 4 in “Fix leak in credential_apply_config”
  1. Fix leak in credential_apply_configMike Hommey, Aug 20, 2021
  2. Derrick StoleeAug 20, 2021
  3. Jeff KingAug 20, 2021
  4. Jeff KingAug 20, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.