threads / discuss / 43555

Re: SEGV when lookup_* returns NULL

Subject: Re: SEGV when lookup_* returns NULL

## tl;dr

5 messages between Nov 27, 2006 and Nov 28, 2006.

replies: 4people: 4as markdown or json

Martin Waitz· Nov 27, 2006, 21:13 UTC · lore

SEGV when lookup_* returns NULL

hoi :)

When trying to an unmodified GIT on a repository with submodules it segfaults a lot.

All the lookup_{blob,tree,commit} functions check that the object really is of the requested type and return NULL otherwise. However this NULL pointer is not checked in the calling functions.

Should we make lookup_* to just die when invoked on another object-type? Or modify all the callers? Is there a sane error-handling strategy besides dying in this case? Really checking all the return values in the whole chain would be a lot of work.

-- 
Martin Waitz
Junio C Hamano· Nov 27, 2006, 21:55 UTC · re: Martin Waitz · lore
Martin Waitz <tali@admingilde.org> writes:
Show 5 quoted lines
> All the lookup_{blob,tree,commit} functions check that the object
> really is of the requested type and return NULL otherwise.
> However this NULL pointer is not checked in the calling functions.
>
> Should we make lookup_* to just die when invoked on another object-type?

Making lookup_{specific type} die when they see unexpected type would not hurt that much, I think, aside from the possibility that some callers may check NULL to see if object already exists, but they should be using has_sha1_file() instead.

Johannes Schindelin· Nov 27, 2006, 23:33 UTC · re: Junio C Hamano · lore
Hi,
On Mon, 27 Nov 2006, Junio C Hamano wrote:
Show 12 quoted lines
> Martin Waitz <tali@admingilde.org> writes:
> 
> > All the lookup_{blob,tree,commit} functions check that the object
> > really is of the requested type and return NULL otherwise.
> > However this NULL pointer is not checked in the calling functions.
> >
> > Should we make lookup_* to just die when invoked on another object-type?
> 
> Making lookup_{specific type} die when they see unexpected type
> would not hurt that much, I think, aside from the possibility
> that some callers may check NULL to see if object already
> exists, but they should be using has_sha1_file() instead.
And it would totally clobber the long term goal of libifying git.

Ciao, Dscho

Morten Welinder· Nov 28, 2006, 02:23 UTC · re: Junio C Hamano · lore
> Why?  You would certainly install your own die() handler by that
> time I presume?

Likely, but short of exiting or using longjmp/setjmp what can you do in such a "die"? Not much. And most GUI users will be unhappy with the exit approach.

If there is any chance that the error is not the programmer's fault, a nice library ought to pass the error back somehow.

← back to recent threads