git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 16:09 UTC

Re: [PATCH 1/3] pretty.c: fix null pointer dereference

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 24, 2026, 06:25 UTC
Message-ID
<xmqqcy1uk69o.fsf@gitster.g>
In-Reply-To
<20260224040400.751247-2-mroik@delayed.space>
Mirko Faina <mroik@delayed.space> writes:
Show 12 quoted lines
> commit_format_is_empty() is used to check whether "user_format" is set
> to a value. Unfortunately this function crashes the program if no
> user_format is set. This is because instead of checking for the pointer
> value it checks for its dereferenced value, this being NULL if
> user_format is not set.
>
> Teach the proper condition to check if user_format is set.
>
> Signed-off-by: Mirko Faina <mroik@delayed.space>
> ---
>  pretty.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
Interesting.

Are any of the existing calls to this function that passes CMIT_FMT_USERFORMAT trigger a segfault with certain condition?

For example, there are only two places where CMIT_FMT_USERFORMAT is assigned to something. One is save_user_format() where user_format gets a non NULL string before rev->commit_format gets assigned CMIT_FMT_USERFORMAT. Another is git_pretty_formats_config() that parses configuration variables "pretty.*" and populate commit_formats map. This is later used in get_commit_format() and that function always calls save_user_format() we just saw when the format used is CMIT_FMT_USERFORMAT. So the existing code paths seem to be safe by design.

What I am wondering is if a NULL user_format should be flagged as a programming error, instead of getting swept under the rug like this patch does. IOW,

	int commit_format_is_empty(enum cmit_fmt fmt)
	{
		if (fmt != CMIT_FMT_USERFORMAT)
			return 0;
		if (!user_format)
			BUG("never called save_user_format() and using USERFORMAT?");
		return !*user_format;
	}
Show 14 quoted lines
>
> diff --git a/pretty.c b/pretty.c
> index e0646bbc5d..cdb8bf559d 100644
> --- a/pretty.c
> +++ b/pretty.c
> @@ -47,7 +47,7 @@ static struct cmt_fmt_map *find_commit_format(const char *sought);
>  
>  int commit_format_is_empty(enum cmit_fmt fmt)
>  {
> -	return fmt == CMIT_FMT_USERFORMAT && !*user_format;
> +	return fmt == CMIT_FMT_USERFORMAT && !user_format;
>  }
>  
>  static void save_user_format(struct rev_info *rev, const char *cp, int is_tformat)
Previous: Mirko FainaNext: Mirko Faina
Message 16 of 113 in “format-patch: better commit list for cover letter”
  1. format-patch: better commit list for cover letterMirko Faina, Feb 20, 2026
  2. format-patch: better commit list for cover letterMirko Faina, Feb 20, 2026
  3. Mirko FainaFeb 21, 2026
  4. Junio C HamanoFeb 21, 2026
  5. Mirko FainaFeb 21, 2026
  6. Junio C HamanoFeb 21, 2026
  7. Junio C HamanoFeb 21, 2026
  8. Mirko FainaFeb 21, 2026
  9. Junio C HamanoFeb 21, 2026
  10. Mirko FainaFeb 21, 2026
  11. 0/3 format-patch: add cover-letter-format optionMirko Faina, Feb 24, 2026
  12. 1/3 pretty.c: fix null pointer dereferenceMirko Faina, Feb 24, 2026
  13. 2/3 format-patch: add ability to use alt cover formatMirko Faina, Feb 24, 2026
  14. 3/3 format-patch: add commitListFormat configMirko Faina, Feb 24, 2026
  15. Mirko FainaFeb 24, 2026
  16. Junio C HamanoFeb 24, 2026
  17. Mirko FainaFeb 24, 2026
  18. Mirko FainaFeb 24, 2026
  19. Jeff KingFeb 24, 2026
  20. Jeff KingFeb 24, 2026
  21. Mirko FainaFeb 24, 2026
  22. Jeff KingFeb 24, 2026
  23. 0/2 format-patch: add cover-letter-format optionMirko Faina, Feb 24, 2026
  24. 1/2 format-patch: add ability to use alt cover formatMirko Faina, Feb 24, 2026
  25. 2/2 format-patch: add commitListFormat configMirko Faina, Feb 24, 2026
  26. Junio C HamanoFeb 24, 2026
  27. Junio C HamanoFeb 24, 2026
  28. Junio C HamanoFeb 24, 2026
  29. Junio C HamanoFeb 24, 2026
  30. Junio C HamanoFeb 24, 2026
  31. Mirko FainaFeb 24, 2026
  32. Mirko FainaFeb 25, 2026
  33. Mirko FainaFeb 25, 2026
  34. Junio C HamanoFeb 25, 2026
  35. Junio C HamanoFeb 25, 2026
  36. Jeff KingFeb 25, 2026
  37. Jeff KingFeb 25, 2026
  38. Junio C HamanoFeb 25, 2026
  39. Mirko FainaFeb 25, 2026
  40. Mirko FainaFeb 26, 2026
  41. Junio C HamanoFeb 26, 2026
  42. 1/4 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Feb 27, 2026
  43. 0/4 format-patch: add cover-letter-format optionMirko Faina, Feb 27, 2026
  44. 2/4 format-patch: move cover letter summary generationMirko Faina, Feb 27, 2026
  45. 4/4 format-patch: add commitListFormat configMirko Faina, Feb 27, 2026
  46. 3/4 format-patch: add ability to use alt cover formatMirko Faina, Feb 27, 2026
  47. Junio C HamanoFeb 27, 2026
  48. Mirko FainaFeb 27, 2026
  49. 0/4 format-patch: add cover-letter-format optionMirko Faina, Feb 27, 2026
  50. 1/4 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Feb 27, 2026
  51. 3/4 format-patch: add ability to use alt cover formatMirko Faina, Feb 27, 2026
  52. 2/4 format-patch: move cover letter summary generationMirko Faina, Feb 27, 2026
  53. 4/4 format-patch: add commitListFormat configMirko Faina, Feb 27, 2026
  54. 5/4 docs: add usage for the cover-letter fmt featureMirko Faina, Feb 27, 2026
  55. Junio C HamanoFeb 27, 2026
  56. Mirko FainaFeb 27, 2026
  57. Junio C HamanoFeb 27, 2026
  58. 0/5 format-patch: add cover-letter-format optionMirko Faina, Feb 27, 2026
  59. 1/5 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Feb 27, 2026
  60. 2/5 format-patch: move cover letter summary generationMirko Faina, Feb 27, 2026
  61. 3/5 format-patch: add ability to use alt cover formatMirko Faina, Feb 27, 2026
  62. 4/5 format-patch: add commitListFormat configMirko Faina, Feb 27, 2026
  63. 5/5 docs: add usage for the cover-letter fmt featureMirko Faina, Feb 27, 2026
  64. Junio C HamanoMar 6, 2026
  65. Mirko FainaMar 6, 2026
  66. 1/5 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Mar 6, 2026
  67. 0/5 format-patch: add cover-letter-format optionMirko Faina, Mar 6, 2026
  68. 2/5 format-patch: move cover letter summary generationMirko Faina, Mar 6, 2026
  69. 3/5 format-patch: add ability to use alt cover formatMirko Faina, Mar 6, 2026
  70. 4/5 format-patch: add commitListFormat configMirko Faina, Mar 6, 2026
  71. 5/5 docs: add usage for the cover-letter fmt featureMirko Faina, Mar 6, 2026
  72. Junio C HamanoMar 6, 2026
  73. 0/5 format-patch: add cover-letter-format optionMirko Faina, Mar 6, 2026
  74. 1/5 pretty.c: add %(count) and %(total) placeholdersMirko Faina, Mar 6, 2026
  75. 2/5 format-patch: move cover letter summary generationMirko Faina, Mar 6, 2026
  76. 3/5 format-patch: add ability to use alt cover formatMirko Faina, Mar 6, 2026
  77. 4/5 format-patch: add commitListFormat configMirko Faina, Mar 6, 2026
  78. 5/5 docs: add usage for the cover-letter fmt featureMirko Faina, Mar 6, 2026
  79. Bert WesargMar 10, 2026
  80. Phillip WoodMar 10, 2026
  81. Phillip WoodMar 10, 2026
  82. Phillip WoodMar 10, 2026
  83. Phillip WoodMar 10, 2026
  84. Junio C HamanoMar 10, 2026
  85. Mirko FainaMar 10, 2026
  86. MroikMar 10, 2026
  87. Mirko FainaMar 10, 2026
  88. Mirko FainaMar 10, 2026
  89. Junio C HamanoMar 10, 2026
  90. Mirko FainaMar 10, 2026
  91. Phillip WoodMar 11, 2026
  92. Phillip WoodMar 11, 2026
  93. Junio C HamanoMar 11, 2026
  94. Junio C HamanoMar 11, 2026
  95. 0/4 format-patch: add cover-letter-format optionMirko Faina, Mar 12, 2026
  96. 1/4 format-patch: move cover letter summary generationMirko Faina, Mar 12, 2026
  97. 2/4 format-patch: add ability to use alt cover formatMirko Faina, Mar 12, 2026
  98. 3/4 format-patch: add "chronological" format for coverMirko Faina, Mar 12, 2026
  99. 4/4 format-patch: add commitListFormat configMirko Faina, Mar 12, 2026
  100. Junio C HamanoMar 12, 2026
  101. Junio C HamanoMar 12, 2026
  102. Junio C HamanoMar 12, 2026
  103. Junio C HamanoMar 12, 2026
  104. Mirko FainaMar 12, 2026
  105. Junio C HamanoMar 12, 2026
  106. Junio C HamanoMar 12, 2026
  107. Junio C HamanoMar 12, 2026
  108. Mirko FainaMar 12, 2026
  109. Junio C HamanoMar 12, 2026
  110. Phillip WoodMar 13, 2026
  111. Junio C HamanoMar 13, 2026
  112. Mirko FainaMar 13, 2026
  113. Junio C HamanoMar 13, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.