git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3] object-name: avoid use-after-free in get_oid_with_context_1()

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 17, 2026, 15:43 UTC
Message-ID
<xmqq1pbw7nwi.fsf@gitster.g>
In-Reply-To
<20260817082127.81132-1-diy2903@gmail.com>
Shlok Kulshreshtha <diy2903@gmail.com> writes:
Show 16 quoted lines
> When a ":<path>" argument names a relative path, resolve_relative_path()
> returns a newly allocated string and "cp" is pointed at it:
>
> 	new_path = resolve_relative_path(repo, cp);
> 	if (!new_path) {
> 		namelen = namelen - (cp - name);
> 	} else {
> 		cp = new_path;
> 		namelen = strlen(cp);
> 	}
>
> From there on "cp" and "new_path" name the same allocation. Later the
> memory location that "new_path" points to is freed.
>
> 	free(new_path);
> 	if (reject_tree_in_index(repo, only_to_die, ce, stage, prefix, cp))
Nicely described and ...
Show 24 quoted lines
> diff --git a/object-name.c b/object-name.c
> index 83efba0ba6..026ff8c6dd 100644
> --- a/object-name.c
> +++ b/object-name.c
> @@ -1803,13 +1803,15 @@ static enum get_oid_result get_oid_with_context_1(struct repository *repo,
>  			    memcmp(ce->name, cp, namelen))
>  				break;
>  			if (ce_stage(ce) == stage) {
> +				int ret = reject_tree_in_index(repo, only_to_die, ce,
> +							       stage, prefix, cp);
> +
> +				if (!ret) {
> +					oidcpy(oid, &ce->oid);
> +					oc->mode = ce->ce_mode;
> +				}
>  				free(new_path);
> -				if (reject_tree_in_index(repo, only_to_die, ce,
> -							 stage, prefix, cp))
> -					return -1;
> -				oidcpy(oid, &ce->oid);
> -				oc->mode = ce->ce_mode;
> -				return 0;
> +				return ret;
>  			}

... the fix matches exactly what anybody would expect from the problem description, i.e., "Do not free new_path before we are done with using cp".

Will queue.  Thanks.
Previous: Shlok KulshreshthaNext: Shlok Kulshreshtha
Message 7 of 8 in “object-name: avoid use-after-free in get_oid_with_context_1()”
  1. object-name: avoid use-after-free in get_oid_with_context_1()Shlok Kulshreshtha, Aug 7, 2026
  2. René ScharfeAug 8, 2026
  3. Shlok KulshreshthaAug 8, 2026
  4. object-name: avoid use-after-free in get_oid_with_context_1()Shlok Kulshreshtha, Aug 9, 2026
  5. Patrick SteinhardtAug 10, 2026
  6. object-name: avoid use-after-free in get_oid_with_context_1()Shlok Kulshreshtha, Aug 17, 2026
  7. Junio C HamanoAug 17, 2026
  8. Shlok KulshreshthaAug 17, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.