From: Tsahi Elkayam Date: Thu, 08 Jan 2026 16:52:05 GMT Subject: [PATCH v2] reftable/iter: fix UB in indexed_table_ref_iter_next Message-ID: In-Reply-To: The indexed_table_ref_iter_next() function provides reverse mappings from object IDs to references. It currently accesses ref->value.val2 without checking the reference's value_type, leading to undefined behavior when encountering unpeeled references (REFTABLE_REF_VAL1). While the current "obj" table implementation is suboptimal—it yields all reference records within a block and relies on manual filtering—this manual comparison is necessary to ensure the yielded record actually matches the target OID prefix requested by the caller. Fix the undefined behavior by checking the value_type before performing the memory comparison. Additionally, replace the "/* BUG */" comment with a TODO explaining the current implementation's inefficiency, as suggested by the maintainer. Signed-off-by: Tsahi Elkayam --- reftable/iter.c | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/reftable/iter.c b/reftable/iter.c index 2ecc52b336..2eee65bb1e 100644 --- a/reftable/iter.c +++ b/reftable/iter.c @@ -171,12 +171,19 @@ static int indexed_table_ref_iter_next(void *p, struct reftable_record rec) } continue; } - /* BUG */ - if (!memcmp(it->oid.buf, ref->value.val2.target_value, - it->oid.len) || - !memcmp(it->oid.buf, ref->value.val2.value, it->oid.len)) { + + /* + * TODO: The current implementation is suboptimal as it yields + * all ref records in the block rather than filtering by the + * OID prefix. This manual comparison is still necessary. + */ + if (ref->value_type == REFTABLE_REF_VAL2 && + (!memcmp(it->oid.buf, ref->value.val2.target_value, + it->oid.len) || + !memcmp(it->oid.buf, ref->value.val2.value, it->oid.len))) + return 0; + + if (ref->value_type == REFTABLE_REF_VAL1 && + !memcmp(it->oid.buf, ref->value.val1, it->oid.len)) return 0; - } } } -- 2.47.1