git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Fix leak in credential_apply_config

From
Derrick Stolee <stolee@gmail.com>
Date
Aug 20, 2021, 14:58 UTC
Message-ID
<ffa1786e-f69f-3d76-98dc-7fa5cdbd31c0@gmail.com>
In-Reply-To
<20210820084413.1503711-1-mh@glandium.org>
On 8/20/2021 4:44 AM, Mike Hommey wrote:
Show 6 quoted lines
>  	normalized_url = url_normalize(url.buf, &config.url);
>  
>  	git_config(urlmatch_config_entry, &config);
> +	string_list_clear(&config.vars, 1);
>  	free(normalized_url);
>  	strbuf_release(&url);

A good find! This is obviously correct and a valuable change to make. If you are interested in doing a little extra work, then I think there is something more we could do here.

I took a look at the rest of "struct urlmatch_config" to see if anything else needed to be cleared, and it turns out that config.url.url is an allocated string, but happens to be equal to normalized_url, which is freed here.

Perhaps the optimal organization would be to have a clear_urlmatch_config() method that clears all allocated data within the config, and change things like url_normalize() return a 'const char *' to make it clear that the url should be freed somewhere else.

It would help unify the handling of code that is somewhat duplicated (but slightly different each time) across credential_apply_config(), http_init(), get_urlmatch(), and cmd__urlmatch_normalization().

Thanks, -Stolee

Previous: Mike HommeyNext: Jeff King
Message 2 of 4 in “Fix leak in credential_apply_config”
  1. Fix leak in credential_apply_configMike Hommey, Aug 20, 2021
  2. Derrick StoleeAug 20, 2021
  3. Jeff KingAug 20, 2021
  4. Jeff KingAug 20, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.