From: Junio C Hamano Date: Sun, 28 Dec 2025 14:57:45 GMT Subject: Re: [PATCH] receive-pack: fix crash on out-of-namespace symref Message-ID: In-Reply-To: "Troels Thomsen via GitGitGadget" writes: > From: Troels Thomsen > > `check_aliased_update_internal()` detects when a symbolic ref and its > target are being updated in the same push. It does this by building a > list of ref names without the optional namespace prefix. When a symbolic > ref within a namespace points to a ref outside the namespace, > `strip_namespace()` returns NULL which leads to a segfault. > > A NULL check preventing this particular issue was repurposed in > ded8393610. Rather than reintroducing it, we can instead build a list of > fully qualified ref names. This prevents the crash, preserves the > consistency check from da3efdb17b, and allows updates to all symbolic > refs. > > Signed-off-by: Troels Thomsen > --- > receive-pack: fix crash on out-of-namespace symref Fixing crash is certainly a good thing, but when the namespace is segregated and receive-pack wants to get updates only within the given namespace, would presence of such a cross namespace symref cause updates outside the namespace through the symref, defeating the point of setting up a namespace in the first place? I am not objecting to the new behaviour, but am not sure if it is a sensible one. You _might_ be able to argue that an attempt to update underlying refs outside the namespace through such a symbolic ref should result in an error (i.e., a fix to the current crashing behaviour is to die in a controlled way). Thoughts?