Re: [PATCH 0/4] plugging some mmap() leaks
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Mar 6, 2026, 18:37 UTC
- Message-ID
- <xmqq5x78249v.fsf@gitster.g>
- In-Reply-To
- <9137fd66-9ac3-42ff-a892-1b6f20b49972@ramsayjones.plus.com>
Ramsay Jones <ramsay@ramsayjones.plus.com> writes:
Show 7 quoted lines
> When compiling with the NO_MMAP build variable set, the built-in > 'git_mmap()' and 'git_munmap()' compatability routines use simple > memory allocation and file I/O to emulate the required behaviour. > The current implementation is vunerable to the "double-delete" bug > (where the pointer returned by malloc() is passed to free() two or > more times), should the mapped memory block address be passed to > munmap() multiple times.
Sorry if I am missing something glaringly obvious, but quite honestly I am confused. Wouldn't it be a bug to call munmap() again on the same region of memory obtained from mmap() and then already unmapped by calling munmap()?
Or can the emulation layer cause such a second free() even if the munmap() is done once and only once per memory region obtained from a single mmap()?