git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] http: fix memory leak in fetch_and_setup_pack_index()

From
LorenzoPegorari <lorenzo.pegorari2002@gmail.com>
Date
May 28, 2026, 23:49 UTC
Message-ID
<ahjUmMCKxREamQE-@lorenzo-VM>
In-Reply-To
<agx5tblaCZNsYEBq@lorenzo-VM>

Inside the function `fetch_and_setup_pack_index()`, when the pack obtained using `parse_pack_index()` fails to be verified by `verify_pack_index()`, the function returns without closing and freeing said pack.

Fix this by calling `close_pack_index()` to munmap the index file for the leaking pack (which might have been mmapped by `fetch_pack_index()` or `verify_pack_index()`), and then free it, when the verification fails.

Also, do some more cleanup by removing the useless call to the function `unlink()`. This is not necessary anymore since 63aca3f7f1 (dumb-http: store downloaded pack idx as tempfile, 2024-10-25), when `fetch_pack_index()` started registering its return value (in this case `tmp_idx`) as a tempfile to be deleted at process exit.

Signed-off-by: LorenzoPegorari <lorenzo.pegorari2002@gmail.com>
---
 http.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/http.c b/http.c
index 67c9c6fc60..99da4d7529 100644
--- a/http.c
+++ b/http.c
@@ -2538,18 +2538,18 @@ static int fetch_and_setup_pack_index(struct packfile_list *packs,
 
 	new_pack = parse_pack_index(the_repository, sha1, tmp_idx);
 	if (!new_pack) {
-		unlink(tmp_idx);
 		free(tmp_idx);
-
 		return -1; /* parse_pack_index() already issued error message */
 	}
 
 	ret = verify_pack_index(new_pack);
-	if (!ret)
-		close_pack_index(new_pack);
+
+	close_pack_index(new_pack);
 	free(tmp_idx);
-	if (ret)
+	if (ret) {
+		free(new_pack);
 		return -1;
+	}
 
 	packfile_list_prepend(packs, new_pack);
 	return 0;
-- 
2.54.0.129.g2dffd77b94.dirty
Previous: Jeff KingNext: Jeff King
Message 5 of 13 in “http: fix memory leak in fetch_and_setup_pack_index()”
  1. http: fix memory leak in fetch_and_setup_pack_index()LorenzoPegorari, May 19, 2026
  2. Jeff KingMay 19, 2026
  3. Lorenzo PegorariMay 28, 2026
  4. Jeff KingMay 29, 2026
  5. http: fix memory leak in fetch_and_setup_pack_index()LorenzoPegorari, May 28, 2026
  6. Jeff KingMay 29, 2026
  7. Jeff KingMay 29, 2026
  8. Lorenzo PegorariJun 1, 2026
  9. Lorenzo PegorariJun 1, 2026
  10. 0/2 http: fix memory leak in fetch_and_setup_pack_index()LorenzoPegorari, Jun 1, 2026
  11. 1/2 http: cleanup function fetch_and_setup_pack_index()LorenzoPegorari, Jun 1, 2026
  12. 2/2 http: fix memory leak in fetch_and_setup_pack_index()LorenzoPegorari, Jun 1, 2026
  13. Jeff KingJun 2, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.