git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] reftable/iter: fix undefined behavior in indexed_table_ref_iter_next

From
TETsahi Elkayam <tsahi.elkayam@protonmail.com>
Date
Jan 4, 2026, 10:46 UTC
Message-ID
<iaPdageDbUKEIQVlnOugIRhoojxnFo3j-WJFWY0eC5el1Epu3sxEnto6Lrd3bhAYL0Ry8T3czP5UPhLHX_gfWCDiCoLuMofdRkqfOSYP-Jk=@protonmail.com>

The indexed_table_ref_iter_next() function accesses ref->value.val2 without first checking the ref's value_type. This is undefined behavior when the ref is not of type REFTABLE_REF_VAL2.

The correct pattern is already used in filtering_ref_iterator_next() which checks value_type before accessing the appropriate union member. Apply the same pattern here:

 - Check for REFTABLE_REF_VAL2 before accessing val2 members
 - Add missing check for REFTABLE_REF_VAL1 to handle single-value refs

This was marked with a "/* BUG */" comment indicating the issue was known but not yet fixed.

Signed-off-by: Tsahi Elkayam <Tsahi.Elkayam@protonmail.com>
---
 reftable/iter.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/reftable/iter.c b/reftable/iter.c
index 2ecc52b336..2eee65bb1e 100644
--- a/reftable/iter.c
+++ b/reftable/iter.c
@@ -171,12 +171,15 @@ static int indexed_table_ref_iter_next(void *p, struct reftable_record *rec)
 			}
 			continue;
 		}
-		/* BUG */
-		if (!memcmp(it->oid.buf, ref->value.val2.target_value,
-			    it->oid.len) ||
-		    !memcmp(it->oid.buf, ref->value.val2.value, it->oid.len)) {
+		if (ref->value_type == REFTABLE_REF_VAL2 &&
+		    (!memcmp(it->oid.buf, ref->value.val2.target_value,
+			     it->oid.len) ||
+		     !memcmp(it->oid.buf, ref->value.val2.value, it->oid.len)))
+			return 0;
+
+		if (ref->value_type == REFTABLE_REF_VAL1 &&
+		    !memcmp(it->oid.buf, ref->value.val1, it->oid.len))
 			return 0;
-		}
 	}
 }
 
-- 
2.37.1 (Apple Git-137.1)




Sent with Proton Mail secure email.
Next: Patrick Steinhardt
Message 1 of 4 in “reftable/iter: fix undefined behavior in indexed_table_ref_iter_next”
  1. reftable/iter: fix undefined behavior in indexed_table_ref_iter_nextTsahi Elkayam, Jan 4, 2026
  2. Patrick SteinhardtJan 5, 2026
  3. reftable/iter: fix UB in indexed_table_ref_iter_nextTsahi Elkayam, Jan 8, 2026
  4. Patrick SteinhardtJan 9, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.