git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] reftable/iter: fix UB in indexed_table_ref_iter_next

From
TETsahi Elkayam <tsahi.elkayam@protonmail.com>
Date
Jan 8, 2026, 16:52 UTC
Message-ID
<f4gLTILYbAvRqE-aKM3PTyIajeuZBM2Vgo5V66Q8gI6gpI0niPpz8w_lMa29V4Rou2TJ95SKwm2B16KitVrt47KtCzY-eRBm7kemh0iw82s=@protonmail.com>
In-Reply-To
<aVvR6U6EJ9wfKk8l@pks.im>

The indexed_table_ref_iter_next() function provides reverse mappings from object IDs to references. It currently accesses ref->value.val2 without checking the reference's value_type, leading to undefined behavior when encountering unpeeled references (REFTABLE_REF_VAL1).

While the current "obj" table implementation is suboptimal—it yields all reference records within a block and relies on manual filtering—this manual comparison is necessary to ensure the yielded record actually matches the target OID prefix requested by the caller.

Fix the undefined behavior by checking the value_type before performing the memory comparison. Additionally, replace the "/* BUG */" comment with a TODO explaining the current implementation's inefficiency, as suggested by the maintainer.

Signed-off-by: Tsahi Elkayam <Tsahi.Elkayam@Protonmail.com>
---
 reftable/iter.c | 13 ++++++++++---
 1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/reftable/iter.c b/reftable/iter.c
index 2ecc52b336..2eee65bb1e 100644
--- a/reftable/iter.c
+++ b/reftable/iter.c
@@ -171,12 +171,19 @@ static int indexed_table_ref_iter_next(void *p, struct reftable_record rec)
 			}
 			continue;
 		}
-		/* BUG */
-		if (!memcmp(it->oid.buf, ref->value.val2.target_value,
-			    it->oid.len) ||
-		    !memcmp(it->oid.buf, ref->value.val2.value, it->oid.len)) {
+
+		/*
+		 * TODO: The current implementation is suboptimal as it yields
+		 * all ref records in the block rather than filtering by the
+		 * OID prefix. This manual comparison is still necessary.
+		 */
+		if (ref->value_type == REFTABLE_REF_VAL2 &&
+		    (!memcmp(it->oid.buf, ref->value.val2.target_value,
+			     it->oid.len) ||
+		     !memcmp(it->oid.buf, ref->value.val2.value, it->oid.len)))
+			return 0;
+
+		if (ref->value_type == REFTABLE_REF_VAL1 &&
+		    !memcmp(it->oid.buf, ref->value.val1, it->oid.len))
 			return 0;
-		}
 	}
 }
--
2.47.1
Previous: Patrick SteinhardtNext: Patrick Steinhardt
Message 3 of 4 in “reftable/iter: fix undefined behavior in indexed_table_ref_iter_next”
  1. reftable/iter: fix undefined behavior in indexed_table_ref_iter_nextTsahi Elkayam, Jan 4, 2026
  2. Patrick SteinhardtJan 5, 2026
  3. reftable/iter: fix UB in indexed_table_ref_iter_nextTsahi Elkayam, Jan 8, 2026
  4. Patrick SteinhardtJan 9, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.