git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] fmt-merge-msg: prevent use-after-free with signed tags

From
Taylor Blau <me@ttaylorr.com>
Date
Jan 11, 2022, 15:42 UTC
Message-ID
<Yd2lU/ecNx1uIt7Q@nand.local>
In-Reply-To
<20220111084115.esuyxeopdpaq7g7y@fs>
On Tue, Jan 11, 2022 at 09:41:15AM +0100, Fabian Stelzer wrote:
> fmt_merge_msg_sigs() could probably use some additional refactoring to avoid
> these multiple pointers to the same (detached) buffer. But thats for another
> time.

I thought similarly when trying to looking at the original bisection. But now that we're in the release candidate phase, I figure that any less-than-minimal fix was liable to cause more harm than good.

It is worth looking at in the future, though.

Thanks, Taylor

Previous: Fabian Stelzer
Message 8 of 8 in “git ssh signing changed broke tag merge message contents”
  1. Linus TorvaldsJan 10, 2022
  2. Taylor BlauJan 10, 2022
  3. Linus TorvaldsJan 10, 2022
  4. Junio C HamanoJan 10, 2022
  5. fmt-merge-msg: prevent use-after-free with signed tagsTaylor Blau, Jan 10, 2022
  6. Junio C HamanoJan 10, 2022
  7. Fabian StelzerJan 11, 2022
  8. Taylor BlauJan 11, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.