Re: [PATCH 4/6] strbuf-safe: add sstrbuf_grow()
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Sep 21, 2026, 21:29 UTC
- Message-ID
- <xmqqv77yl2cq.fsf@gitster.g>
- In-Reply-To
- <ebd91b95209d778727dca1bfcce17dcb76b3151f.1789736540.git.gitgitgadget@gmail.com>
"Derrick Stolee via GitGitGadget" <gitgitgadget@gmail.com> writes:
Show 16 quoted lines
> +int srealloc(void **ptr, size_t size)
> {
> if (!size) {
> + free(*ptr);
> + if ((*ptr = malloc(1)))
> + return 0;
> + return -1;
> }
>
> + if (safe_memory_limit_check(size, 0))
> + return -1;
> + if ((*ptr = realloc(*ptr, size)))
> + return 0;
> +
> + return -1;
> +}This overrites *ptr with whatever realloc() returns, and then checks if we had an error, thereby losing whatever pointer *ptr originally had. When realloc() does fail, we have already clobbered *ptr, and very likely have robbed our caller the pointer it had to the region of memory. Aren't we leaking that piece of memory as the result?