git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 15/26] help: fix leaking `struct cmdnames`

From
Rubén Justo <rjusto@gmail.com>
Date
Nov 10, 2024, 21:46 UTC
Message-ID
<c376f2ef-fc43-4815-8e26-f13da3729ed1@gmail.com>
In-Reply-To
<2fb012662d6c5720be1fe86973640c7a2d6f5681.1730901926.git.ps@pks.im>
On Wed, Nov 06, 2024 at 04:11:03PM +0100, Patrick Steinhardt wrote:
Show 38 quoted lines
> We're populating multiple `struct cmdnames`, but don't ever free them.
> Create a common exit path where we do so.
> 
> Note that this also requires us to use `FREE_AND_NULL()` when freeing
> `cmdnames::names`, as we may otherwise try to free it multiple times.
> 
> Signed-off-by: Patrick Steinhardt <ps@pks.im>
> ---
>  help.c | 24 +++++++++++++++++-------
>  1 file changed, 17 insertions(+), 7 deletions(-)
> 
> diff --git a/help.c b/help.c
> index 8794f81db9b..51adc530d7a 100644
> --- a/help.c
> +++ b/help.c
> @@ -169,7 +169,7 @@ void cmdnames_release(struct cmdnames *cmds)
>  	int i;
>  	for (i = 0; i < cmds->cnt; ++i)
>  		free(cmds->names[i]);
> -	free(cmds->names);
> +	FREE_AND_NULL(cmds->names);
>  	cmds->cnt = 0;
>  	cmds->alloc = 0;
>  }
> @@ -619,6 +619,7 @@ const char *help_unknown_cmd(const char *cmd)
>  	struct cmdnames main_cmds = { 0 };
>  	struct cmdnames other_cmds = { 0 };
>  	struct cmdname_help *common_cmds;
> +	const char *assumed = NULL;
>  
>  	read_early_config(the_repository, git_unknown_cmd_config, &cfg);
>  
> @@ -630,7 +631,7 @@ const char *help_unknown_cmd(const char *cmd)
>  
>  	if (cfg.autocorrect == AUTOCORRECT_NEVER) {
>  		fprintf_ln(stderr, _("git: '%s' is not a git command. See 'git --help'."), cmd);
> -		exit(1);
> +		goto out;

We haven't set a value for `assumed` at this point, so it's NULL, and in the new exit path we `exit(1)` when `assumed` is NULL. OK.

However, I think we don't need this change. And keeping the `exit(1)` close to the error message seems like a good idea. Perhaps, in another series, we could change it to `die()`.

Show 22 quoted lines
>  	}
>  
>  	load_command_list("git-", &main_cmds, &other_cmds);
> @@ -695,7 +696,7 @@ const char *help_unknown_cmd(const char *cmd)
>  			; /* still counting */
>  	}
>  	if (cfg.autocorrect && n == 1 && SIMILAR_ENOUGH(best_similarity)) {
> -		const char *assumed = main_cmds.names[0]->name;
> +		assumed = main_cmds.names[0]->name;
>  		main_cmds.names[0] = NULL;
>  		cmdnames_release(&main_cmds);
>  		fprintf_ln(stderr,
> @@ -714,8 +715,10 @@ const char *help_unknown_cmd(const char *cmd)
>  			answer = git_prompt(msg.buf, PROMPT_ECHO);
>  			strbuf_release(&msg);
>  			if (!(starts_with(answer, "y") ||
> -			      starts_with(answer, "Y")))
> -				exit(1);
> +			      starts_with(answer, "Y"))) {
> +				assumed = NULL;
> +				goto out;
> +			}
OK.  But, as above, I don't think we need to change this either.
Show 10 quoted lines
>  		} else {
>  			fprintf_ln(stderr,
>  				   _("Continuing in %0.1f seconds, "
> @@ -723,7 +726,8 @@ const char *help_unknown_cmd(const char *cmd)
>  				   (float)cfg.autocorrect/10.0, assumed);
>  			sleep_millisec(cfg.autocorrect * 100);
>  		}
> -		return assumed;
> +
> +		goto out;
OK.
Show 15 quoted lines
>  	}
>  
>  	fprintf_ln(stderr, _("git: '%s' is not a git command. See 'git --help'."), cmd);
> @@ -738,7 +742,13 @@ const char *help_unknown_cmd(const char *cmd)
>  			fprintf(stderr, "\t%s\n", main_cmds.names[i]->name);
>  	}
>  
> -	exit(1);
> +out:
> +	cmdnames_release(&cfg.aliases);
> +	cmdnames_release(&main_cmds);
> +	cmdnames_release(&other_cmds);
> +	if (!assumed)
> +		exit(1);
> +	return assumed;
OK.
Show 6 quoted lines
>  }
>  
>  void get_version_info(struct strbuf *buf, int show_build_options)
> -- 
> 2.47.0.229.g8f8d6eee53.dirty
> 
Previous: Patrick SteinhardtNext: Patrick Steinhardt
Message 21 of 39 in “Memory leak fixes (pt.10, final)”
  1. 00/26 Memory leak fixes (pt.10, final)Patrick Steinhardt, Nov 6, 2024
  2. 01/26 builtin/blame: fix leaking blame entries with `--incremental`Patrick Steinhardt, Nov 6, 2024
  3. 02/26 bisect: fix leaking good/bad terms when reading multipe timesPatrick Steinhardt, Nov 6, 2024
  4. 03/26 bisect: fix leaking string in `handle_bad_merge_base()`Patrick Steinhardt, Nov 6, 2024
  5. 04/26 bisect: fix leaking `current_bad_oid`Patrick Steinhardt, Nov 6, 2024
  6. 05/26 bisect: fix multiple leaks in `bisect_next_all()`Patrick Steinhardt, Nov 6, 2024
  7. 06/26 bisect: fix leaking commit list items in `check_merge_base()`Patrick Steinhardt, Nov 6, 2024
  8. 07/26 bisect: fix various cases where we leak commit list itemsPatrick Steinhardt, Nov 6, 2024
  9. 08/26 line-log: fix leak when rewriting commit parentsPatrick Steinhardt, Nov 6, 2024
  10. 09/26 strvec: introduce new `strvec_splice()` functionPatrick Steinhardt, Nov 6, 2024
  11. Rubén JustoNov 10, 2024
  12. Patrick SteinhardtNov 11, 2024
  13. 10/26 git: refactor alias handling to use a `struct strvec`Patrick Steinhardt, Nov 6, 2024
  14. Rubén JustoNov 10, 2024
  15. 11/26 git: refactor builtin handling to use a `struct strvec`Patrick Steinhardt, Nov 6, 2024
  16. 12/26 split-index: fix memory leak in `move_cache_to_base_index()`Patrick Steinhardt, Nov 6, 2024
  17. Rubén JustoNov 10, 2024
  18. 13/26 builtin/sparse-checkout: fix leaking sanitized patternsPatrick Steinhardt, Nov 6, 2024
  19. 14/26 help: refactor to not use globals for reading configPatrick Steinhardt, Nov 6, 2024
  20. 15/26 help: fix leaking `struct cmdnames`Patrick Steinhardt, Nov 6, 2024
  21. Rubén JustoNov 10, 2024
  22. Patrick SteinhardtNov 11, 2024
  23. 16/26 help: fix leaking return value from `help_unknown_cmd()`Patrick Steinhardt, Nov 6, 2024
  24. 17/26 builtin/help: fix leaks in `check_git_cmd()`Patrick Steinhardt, Nov 6, 2024
  25. 18/26 builtin/init-db: fix leaking directory pathsPatrick Steinhardt, Nov 6, 2024
  26. Rubén JustoNov 10, 2024
  27. 19/26 builtin/branch: fix leaking sorting optionsPatrick Steinhardt, Nov 6, 2024
  28. Rubén JustoNov 10, 2024
  29. 20/26 t/helper: fix leaking commit graph in "read-graph" subcommandPatrick Steinhardt, Nov 6, 2024
  30. 21/26 git-compat-util: drop `UNLEAK()` annotationPatrick Steinhardt, Nov 6, 2024
  31. Rubén JustoNov 10, 2024
  32. Patrick SteinhardtNov 11, 2024
  33. 22/26 t5601: work around leak sanitizer issuePatrick Steinhardt, Nov 6, 2024
  34. 23/26 t: mark some tests as leak freePatrick Steinhardt, Nov 6, 2024
  35. 24/26 t: remove unneeded !SANITIZE_LEAK prerequisitesPatrick Steinhardt, Nov 6, 2024
  36. 25/26 test-lib: unconditionally enable leak checkingPatrick Steinhardt, Nov 6, 2024
  37. 26/26 t: remove TEST_PASSES_SANITIZE_LEAK annotationsPatrick Steinhardt, Nov 6, 2024
  38. Rubén JustoNov 10, 2024
  39. Patrick SteinhardtNov 11, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.