git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/3] remote-curl: fix memory leak in show_http_message()

From
Taylor Blau <me@ttaylorr.com>
Date
Dec 9, 2025, 23:52 UTC
Message-ID
<aTi2W0f03kwf0ONx@nand.local>
In-Reply-To
<438223792264169082db8a1be5cb419b657bda26.1764160227.git.gitgitgadget@gmail.com>
On Wed, Nov 26, 2025 at 12:30:26PM +0000, Vaidas Pilkauskas via GitGitGadget wrote:
Show 18 quoted lines
> diff --git a/remote-curl.c b/remote-curl.c
> index 5959461cd3..dd0680e5ae 100644
> --- a/remote-curl.c
> +++ b/remote-curl.c
> @@ -371,6 +371,7 @@ static int show_http_message(struct strbuf *type, struct strbuf *charset,
>  			     struct strbuf *msg)
>  {
>  	const char *p, *eol;
> +	struct strbuf msgbuf = STRBUF_INIT;
>
>  	/*
>  	 * We only show text/plain parts, as other types are likely
> @@ -378,19 +379,24 @@ static int show_http_message(struct strbuf *type, struct strbuf *charset,
>  	 */
>  	if (strcmp(type->buf, "text/plain"))
>  		return -1;
> +
> +	strbuf_addbuf(&msgbuf, msg);

Hmm. Looking at the list of show_http_message() callers, it looks like they all follow the pattern of constructing a strbuf "msg", passing it to this function, and then calling die() with some user-friendly message.

I agree that the patch here does address that leak, but I wonder if we should do it in a way that doesn't involve copying the "msg" buffer. One thing we could do is rename 'show_http_message()' to make it clear that it's fatal and then free the re-encoded buffer ourselves (along with the other buffers type and charset), perhaps like so (on top of the previous patch in lieu of this one):

--- 8< ---
diff --git a/remote-curl.c b/remote-curl.c
index 5959461cd34..9d8359665ee 100644
--- a/remote-curl.c
+++ b/remote-curl.c
@@ -367,23 +367,25 @@ static void free_discovery(struct discovery *d)
 	}
 }

-static int show_http_message(struct strbuf *type, struct strbuf *charset,
-			     struct strbuf *msg)
+static void show_http_message_fatal(struct strbuf *type, struct strbuf *charset,
+				    struct strbuf *msg, const char *fmt, ...)
 {
 	const char *p, *eol;
+	va_list ap;
+	report_fn die_message_routine = get_die_message_routine();

 	/*
 	 * We only show text/plain parts, as other types are likely
 	 * to be ugly to look at on the user's terminal.
 	 */
 	if (strcmp(type->buf, "text/plain"))
-		return -1;
+		goto out;
 	if (charset->len)
 		strbuf_reencode(msg, charset->buf, get_log_output_encoding());

 	strbuf_trim(msg);
 	if (!msg->len)
-		return -1;
+		goto out;

 	p = msg->buf;
 	do {
@@ -391,7 +393,15 @@ static int show_http_message(struct strbuf *type, struct strbuf *charset,
 		fprintf(stderr, "remote: %.*s\n", (int)(eol - p), p);
 		p = eol + 1;
 	} while(*eol);
-	return 0;
+
+out:
+	strbuf_release(type);
+	strbuf_release(charset);
+	strbuf_release(msg);
+
+	va_start(ap, fmt);
+	die_message_routine(fmt, ap);
+	va_end(ap);
 }

 static int get_protocol_http_header(enum protocol_version version,
@@ -518,25 +528,27 @@ static struct discovery *discover_refs(const char *service, int for_push)
 	case HTTP_OK:
 		break;
 	case HTTP_MISSING_TARGET:
-		show_http_message(&type, &charset, &buffer);
-		die(_("repository '%s' not found"),
-		    transport_anonymize_url(url.buf));
+		show_http_message_fatal(&type, &charset, &buffer,
+					_("repository '%s' not found"),
+					transport_anonymize_url(url.buf));
--- >8 ---

(...and so on for the remaining cases).

Thanks,
Taylor
Previous: Vaidas Pilkauskas via GitGitGadgetNext: Vaidas Pilkauskas via GitGitGadget
Message 6 of 49 in “http: add support for HTTP 429 rate limit retries”
  1. 0/3 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Nov 26, 2025
  2. 1/3 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Nov 26, 2025
  3. Taylor BlauDec 9, 2025
  4. Vaidas PilkauskasDec 12, 2025
  5. 2/3 remote-curl: fix memory leak in show_http_message()Vaidas Pilkauskas via GitGitGadget, Nov 26, 2025
  6. Taylor BlauDec 9, 2025
  7. 3/3 http: add trace2 logging for retry operationsVaidas Pilkauskas via GitGitGadget, Nov 26, 2025
  8. 0/2 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Dec 18, 2025
  9. 1/2 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Dec 18, 2025
  10. Taylor BlauFeb 11, 2026
  11. Jeff KingFeb 11, 2026
  12. Vaidas PilkauskasFeb 13, 2026
  13. Jeff KingFeb 15, 2026
  14. Vaidas PilkauskasFeb 13, 2026
  15. 2/2 http: add trace2 logging for retry operationsVaidas Pilkauskas via GitGitGadget, Dec 18, 2025
  16. Taylor BlauFeb 11, 2026
  17. 0/3 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Feb 17, 2026
  18. 1/3 strbuf: fix incorrect alloc size in strbuf_reencode()Vaidas Pilkauskas via GitGitGadget, Feb 17, 2026
  19. Junio C HamanoFeb 17, 2026
  20. Vaidas PilkauskasFeb 18, 2026
  21. 2/3 remote-curl: introduce show_http_message_fatal() helperVaidas Pilkauskas via GitGitGadget, Feb 17, 2026
  22. 3/3 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Feb 17, 2026
  23. 0/5 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Feb 18, 2026
  24. 1/5 strbuf: pass correct alloc to strbuf_attach() in strbuf_reencode()Vaidas Pilkauskas via GitGitGadget, Feb 18, 2026
  25. 2/5 strbuf_attach: fix all call sites to pass correct allocVaidas Pilkauskas via GitGitGadget, Feb 18, 2026
  26. Junio C HamanoFeb 20, 2026
  27. Vaidas PilkauskasFeb 23, 2026
  28. 3/5 strbuf: replace strbuf_grow() in strbuf_attach() with BUG() checkVaidas Pilkauskas via GitGitGadget, Feb 18, 2026
  29. 4/5 remote-curl: introduce show_http_message_fatal() helperVaidas Pilkauskas via GitGitGadget, Feb 18, 2026
  30. 5/5 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Feb 18, 2026
  31. 0/4 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Feb 23, 2026
  32. 1/4 strbuf: pass correct alloc to strbuf_attach() in strbuf_reencode()Vaidas Pilkauskas via GitGitGadget, Feb 23, 2026
  33. 2/4 strbuf_attach: fix call sites to pass correct allocVaidas Pilkauskas via GitGitGadget, Feb 23, 2026
  34. 3/4 remote-curl: introduce show_http_message_fatal() helperVaidas Pilkauskas via GitGitGadget, Feb 23, 2026
  35. Jeff KingMar 10, 2026
  36. 4/4 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Feb 23, 2026
  37. Jeff KingMar 10, 2026
  38. Junio C HamanoFeb 24, 2026
  39. Junio C HamanoMar 9, 2026
  40. Jeff KingMar 10, 2026
  41. Junio C HamanoMar 10, 2026
  42. 0/3 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Mar 17, 2026
  43. 2/3 strbuf_attach: fix call sites to pass correct allocVaidas Pilkauskas via GitGitGadget, Mar 17, 2026
  44. 3/3 http: add support for HTTP 429 rate limit retriesVaidas Pilkauskas via GitGitGadget, Mar 17, 2026
  45. Taylor BlauMar 21, 2026
  46. 1/3 strbuf: pass correct alloc to strbuf_attach() in strbuf_reencode()Vaidas Pilkauskas via GitGitGadget, Mar 17, 2026
  47. Taylor BlauMar 21, 2026
  48. Junio C HamanoMar 21, 2026
  49. Vaidas PilkauskasMar 23, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.