git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] reflog-walk: don't segfault on non-commit sha1's in the reflog

From
Junio C Hamano <gitster@pobox.com>
Date
Dec 30, 2015, 21:41 UTC
Message-ID
<xmqq1ta3ehr1.fsf@gitster.mtv.corp.google.com>
In-Reply-To
<1451511208.9251.21.camel@kaarsemaker.net>
Dennis Kaarsemaker <dennis@kaarsemaker.net> writes:
Show 45 quoted lines
> On wo, 2015-12-30 at 13:20 -0800, Junio C Hamano wrote:
>> Dennis Kaarsemaker <dennis@kaarsemaker.net> writes:
>> 
>> > diff --git a/reflog-walk.c b/reflog-walk.c
>> > index 85b8a54..b85c8e8 100644
>> > --- a/reflog-walk.c
>> > +++ b/reflog-walk.c
>> > @@ -236,8 +236,8 @@ void fake_reflog_parent(struct reflog_walk_info
>> > *info, struct commit *commit)
>> >  	reflog = &commit_reflog->reflogs->items[commit_reflog
>> > ->recno];
>> >  	info->last_commit_reflog = commit_reflog;
>> >  	commit_reflog->recno--;
>> > -	commit_info->commit = (struct commit *)parse_object(reflog
>> > ->osha1);
>> > -	if (!commit_info->commit) {
>> > +	commit_info->commit = lookup_commit(reflog->osha1);
>> > +	if (!commit_info->commit || parse_commit(commit_info
>> > ->commit)) {
>> >  		commit->parents = NULL;
>> >  		return;
>> 
>> This looks somewhat roundabout and illogical.  The original was bad
>> because it blindly assumed reflgo->osha1 refers to a commit without
>> making sure that assumption holds.  Calling lookup_commit() blindly
>> is not much better, even though you are helped that the function
>> happens not to barf if the given object is not a commit.
>> 
>> Also this changes semantics, no?  Trace the original flow and think
>> what happens, when we see a commit object that cannot be parsed in
>> parse_commit_buffer().  parse_object() calls parse_object_buffer()
>> which in turn calls parse_commit_buffer() and the entire callchain
>> returns NULL.  commit_info->commit will become NULL in such a case.
>> 
>> With your code, lookup_commit() will store a non NULL in
>> commit_info->commit, and parse_commit() calls parse_commit_buffer()
>> and that would fail, so you clear commit->parents to NULL but fail
>> to set commit_info->commit to NULL.
>>
>> Why not keep the parse_object() as-is and make sure we error out
>> unless the result is a commit with a more explicit check, perhaps
>> like this, instead?
>
> lookup_commit actually returns NULL (via object_as_type) for objects
> that are not commits, so I don't think the above is true.

I think you did not read what you are responding to. I was talking about the error case where the object _is_ a commit (hence lookup returns it), but parse_commit_buffer() does not like its contents.

> The code below also loses the diagnostic message about the object
> not being a commit.
Giving such a diagnostic message is a BUG.

A ref can legitimately point at any type of object (only refs under refs/heads/, aka "branches", must point at commits), so you MUST NOT complain about seeing a non-commit in a reflog in general.

Previous: Dennis KaarsemakerNext: Dennis Kaarsemaker
Message 11 of 25 in “Segfault in git reflog”
  1. Dennis KaarsemakerDec 30, 2015
  2. Duy NguyenDec 30, 2015
  3. Dennis KaarsemakerDec 30, 2015
  4. Duy NguyenDec 30, 2015
  5. Duy NguyenDec 30, 2015
  6. Dennis KaarsemakerDec 30, 2015
  7. Duy NguyenDec 30, 2015
  8. reflog-walk: don't segfault on non-commit sha1's in the reflogDennis Kaarsemaker, Dec 30, 2015
  9. Junio C HamanoDec 30, 2015
  10. Dennis KaarsemakerDec 30, 2015
  11. Junio C HamanoDec 30, 2015
  12. Dennis KaarsemakerDec 30, 2015
  13. reflog-walk: don't segfault on non-commit sha1's in the reflogDennis Kaarsemaker, Dec 30, 2015
  14. Junio C HamanoDec 30, 2015
  15. reflog-walk: don't segfault on non-commit sha1's in the reflogDennis Kaarsemaker, Dec 30, 2015
  16. Junio C HamanoDec 31, 2015
  17. Dennis KaarsemakerDec 31, 2015
  18. Dennis KaarsemakerDec 31, 2015
  19. reflog-walk: don't segfault on non-commit sha1's in the reflogDennis Kaarsemaker, Jan 5, 2016
  20. Eric SunshineJan 6, 2016
  21. Dennis KaarsemakerJan 6, 2016
  22. Eric SunshineJan 6, 2016
  23. Eric SunshineJan 6, 2016
  24. Dennis KaarsemakerJan 6, 2016
  25. Duy NguyenJan 6, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.