git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 11/26] git: refactor builtin handling to use a `struct strvec`

From
Patrick Steinhardt <ps@pks.im>
Date
Nov 6, 2024, 15:10 UTC
Message-ID
<eae8f7e223f9ec9cbb35a001be75536fbcbe8c66.1730901926.git.ps@pks.im>
In-Reply-To
<cover.1730901926.git.ps@pks.im>

Similar as with the preceding commit, `handle_builtin()` does not properly track lifetimes of the `argv` array and its strings. As it may end up modifying the array this can lead to memory leaks in case it contains allocated strings.

Refactor the function to use a `struct strvec` instead.
Signed-off-by: Patrick Steinhardt <ps@pks.im>
---
 git.c                  | 66 ++++++++++++++++++++----------------------
 t/t0211-trace2-perf.sh |  2 +-
 2 files changed, 32 insertions(+), 36 deletions(-)
diff --git a/git.c b/git.c
index 88356afe5fb..159dd45b082 100644
--- a/git.c
+++ b/git.c
@@ -696,63 +696,57 @@ void load_builtin_commands(const char *prefix, struct cmdnames *cmds)
 }
 
 #ifdef STRIP_EXTENSION
-static void strip_extension(const char **argv)
+static void strip_extension(struct strvec *args)
 {
 	size_t len;
 
-	if (strip_suffix(argv[0], STRIP_EXTENSION, &len))
-		argv[0] = xmemdupz(argv[0], len);
+	if (strip_suffix(args->v[0], STRIP_EXTENSION, &len)) {
+		char *stripped = xmemdupz(args->v[0], len);
+		strvec_replace(args, 0, stripped);
+		free(stripped);
+	}
 }
 #else
 #define strip_extension(cmd)
 #endif
 
-static void handle_builtin(int argc, const char **argv)
+static void handle_builtin(struct strvec *args)
 {
-	struct strvec args = STRVEC_INIT;
-	const char **argv_copy = NULL;
 	const char *cmd;
 	struct cmd_struct *builtin;
 
-	strip_extension(argv);
-	cmd = argv[0];
+	strip_extension(args);
+	cmd = args->v[0];
 
 	/* Turn "git cmd --help" into "git help --exclude-guides cmd" */
-	if (argc > 1 && !strcmp(argv[1], "--help")) {
-		int i;
-
-		argv[1] = argv[0];
-		argv[0] = cmd = "help";
-
-		for (i = 0; i < argc; i++) {
-			strvec_push(&args, argv[i]);
-			if (!i)
-				strvec_push(&args, "--exclude-guides");
-		}
+	if (args->nr > 1 && !strcmp(args->v[1], "--help")) {
+		const char *exclude_guides_arg[] = { "--exclude-guides" };
+
+		strvec_replace(args, 1, args->v[0]);
+		strvec_replace(args, 0, "help");
+		cmd = "help";
+		strvec_splice(args, 2, 0, exclude_guides_arg,
+			      ARRAY_SIZE(exclude_guides_arg));
+	}
 
-		argc++;
+	builtin = get_builtin(cmd);
+	if (builtin) {
+		const char **argv_copy = NULL;
+		int ret;
 
 		/*
 		 * `run_builtin()` will modify the argv array, so we need to
 		 * create a shallow copy such that we can free all of its
 		 * strings.
 		 */
-		CALLOC_ARRAY(argv_copy, argc + 1);
-		COPY_ARRAY(argv_copy, args.v, argc);
+		if (args->nr)
+			DUP_ARRAY(argv_copy, args->v, args->nr + 1);
 
-		argv = argv_copy;
-	}
-
-	builtin = get_builtin(cmd);
-	if (builtin) {
-		int ret = run_builtin(builtin, argc, argv, the_repository);
-		strvec_clear(&args);
+		ret = run_builtin(builtin, args->nr, argv_copy, the_repository);
+		strvec_clear(args);
 		free(argv_copy);
 		exit(ret);
 	}
-
-	strvec_clear(&args);
-	free(argv_copy);
 }
 
 static void execv_dashed_external(const char **argv)
@@ -815,7 +809,7 @@ static int run_argv(struct strvec *args)
 		 * process.
 		 */
 		if (!done_alias)
-			handle_builtin(args->nr, args->v);
+			handle_builtin(args);
 		else if (get_builtin(args->v[0])) {
 			struct child_process cmd = CHILD_PROCESS_INIT;
 			int i;
@@ -916,8 +910,10 @@ int cmd_main(int argc, const char **argv)
 	 * that one cannot handle it.
 	 */
 	if (skip_prefix(cmd, "git-", &cmd)) {
-		argv[0] = cmd;
-		handle_builtin(argc, argv);
+		strvec_push(&args, cmd);
+		strvec_pushv(&args, argv + 1);
+		handle_builtin(&args);
+		strvec_clear(&args);
 		die(_("cannot handle %s as a builtin"), cmd);
 	}
 
diff --git a/t/t0211-trace2-perf.sh b/t/t0211-trace2-perf.sh
index dddc130560b..91260ce97e5 100755
--- a/t/t0211-trace2-perf.sh
+++ b/t/t0211-trace2-perf.sh
@@ -2,7 +2,7 @@
 
 test_description='test trace2 facility (perf target)'
 
-TEST_PASSES_SANITIZE_LEAK=false
+TEST_PASSES_SANITIZE_LEAK=true
 . ./test-lib.sh
 
 # Turn off any inherited trace2 settings for this test.
-- 
2.47.0.229.g8f8d6eee53.dirty
Previous: Rubén JustoNext: Patrick Steinhardt
Message 15 of 39 in “Memory leak fixes (pt.10, final)”
  1. 00/26 Memory leak fixes (pt.10, final)Patrick Steinhardt, Nov 6, 2024
  2. 01/26 builtin/blame: fix leaking blame entries with `--incremental`Patrick Steinhardt, Nov 6, 2024
  3. 02/26 bisect: fix leaking good/bad terms when reading multipe timesPatrick Steinhardt, Nov 6, 2024
  4. 03/26 bisect: fix leaking string in `handle_bad_merge_base()`Patrick Steinhardt, Nov 6, 2024
  5. 04/26 bisect: fix leaking `current_bad_oid`Patrick Steinhardt, Nov 6, 2024
  6. 05/26 bisect: fix multiple leaks in `bisect_next_all()`Patrick Steinhardt, Nov 6, 2024
  7. 06/26 bisect: fix leaking commit list items in `check_merge_base()`Patrick Steinhardt, Nov 6, 2024
  8. 07/26 bisect: fix various cases where we leak commit list itemsPatrick Steinhardt, Nov 6, 2024
  9. 08/26 line-log: fix leak when rewriting commit parentsPatrick Steinhardt, Nov 6, 2024
  10. 09/26 strvec: introduce new `strvec_splice()` functionPatrick Steinhardt, Nov 6, 2024
  11. Rubén JustoNov 10, 2024
  12. Patrick SteinhardtNov 11, 2024
  13. 10/26 git: refactor alias handling to use a `struct strvec`Patrick Steinhardt, Nov 6, 2024
  14. Rubén JustoNov 10, 2024
  15. 11/26 git: refactor builtin handling to use a `struct strvec`Patrick Steinhardt, Nov 6, 2024
  16. 12/26 split-index: fix memory leak in `move_cache_to_base_index()`Patrick Steinhardt, Nov 6, 2024
  17. Rubén JustoNov 10, 2024
  18. 13/26 builtin/sparse-checkout: fix leaking sanitized patternsPatrick Steinhardt, Nov 6, 2024
  19. 14/26 help: refactor to not use globals for reading configPatrick Steinhardt, Nov 6, 2024
  20. 15/26 help: fix leaking `struct cmdnames`Patrick Steinhardt, Nov 6, 2024
  21. Rubén JustoNov 10, 2024
  22. Patrick SteinhardtNov 11, 2024
  23. 16/26 help: fix leaking return value from `help_unknown_cmd()`Patrick Steinhardt, Nov 6, 2024
  24. 17/26 builtin/help: fix leaks in `check_git_cmd()`Patrick Steinhardt, Nov 6, 2024
  25. 18/26 builtin/init-db: fix leaking directory pathsPatrick Steinhardt, Nov 6, 2024
  26. Rubén JustoNov 10, 2024
  27. 19/26 builtin/branch: fix leaking sorting optionsPatrick Steinhardt, Nov 6, 2024
  28. Rubén JustoNov 10, 2024
  29. 20/26 t/helper: fix leaking commit graph in "read-graph" subcommandPatrick Steinhardt, Nov 6, 2024
  30. 21/26 git-compat-util: drop `UNLEAK()` annotationPatrick Steinhardt, Nov 6, 2024
  31. Rubén JustoNov 10, 2024
  32. Patrick SteinhardtNov 11, 2024
  33. 22/26 t5601: work around leak sanitizer issuePatrick Steinhardt, Nov 6, 2024
  34. 23/26 t: mark some tests as leak freePatrick Steinhardt, Nov 6, 2024
  35. 24/26 t: remove unneeded !SANITIZE_LEAK prerequisitesPatrick Steinhardt, Nov 6, 2024
  36. 25/26 test-lib: unconditionally enable leak checkingPatrick Steinhardt, Nov 6, 2024
  37. 26/26 t: remove TEST_PASSES_SANITIZE_LEAK annotationsPatrick Steinhardt, Nov 6, 2024
  38. Rubén JustoNov 10, 2024
  39. Patrick SteinhardtNov 11, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.