From: Junio C Hamano Date: Sun, 15 Mar 2026 05:05:50 GMT Subject: Re: [PATCH v3 1/9] repository: fix repo_init() memleak due to missing _clear() Message-ID: In-Reply-To: <20260309133739.294555-2-adrian.ratiu@collabora.com> Adrian Ratiu writes: > There is an old pre-existing memory leak in repo_init() due to failing > to call clear_repository_format() in the error case. > > It went undetected because a specific bug is required to trigger it: > enable a v1 extension in a repository with format v0. Obviously this > can only happen in a development environment, so it does not trigger > in normal usage, however the memleak is real and needs fixing. > > Fix it by also calling clear_repository_format() in the error case. > > Signed-off-by: Adrian Ratiu > --- > repository.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/repository.c b/repository.c > index 0b8f7ec200..fb4356ca55 100644 > --- a/repository.c > +++ b/repository.c > @@ -322,6 +322,7 @@ int repo_init(struct repository *repo, > return 0; > > error: > + clear_repository_format(&format); > repo_clear(repo); > return -1; > } It is arguable if the fault is on the caller, or the callee which is read_and_verify_repository_format() that answers the caller "hey, you do not have a valid format to work with" without releasing the thing *it* sample-read. As you said, this only triggers in a broken environment, and there is just a single caller-callee involved, so I am fine fixing it on the caller side like this patch does. Thanks.