Skip to content

Commit

Permalink
parse_object_buffer: correct freeing the buffer
Browse files Browse the repository at this point in the history
If we exit early in the function parse_object_buffer, we did not
write to *eaten_p. Then the calling function parse_object, which looks
like the following with respect to the eaten variable, cannot rely on a
proper value set in eaten, hence the freeing of the buffer depends
on random values in memory.

	struct object *parse_object(const unsigned char *sha1)
	{
		int eaten;
		...
		obj = parse_object_buffer(sha1, type, size, buffer, &eaten);
		if (!eaten)
			free(buffer);
	}

This change makes sure, the buffer freeing condition is deterministic.

Signed-off-by: Stefan Beller <stefanbeller@googlemail.com>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
  • Loading branch information
Stefan Beller authored and Junio C Hamano committed Jul 18, 2013
1 parent 1599999 commit 8e92e8f
Showing 1 changed file with 3 additions and 4 deletions.
7 changes: 3 additions & 4 deletions object.c
Original file line number Diff line number Diff line change
Expand Up @@ -135,7 +135,7 @@ struct object *lookup_unknown_object(const unsigned char *sha1)
struct object *parse_object_buffer(const unsigned char *sha1, enum object_type type, unsigned long size, void *buffer, int *eaten_p)
{
struct object *obj;
int eaten = 0;
*eaten_p = 0;

obj = NULL;
if (type == OBJ_BLOB) {
Expand All @@ -154,7 +154,7 @@ struct object *parse_object_buffer(const unsigned char *sha1, enum object_type t
if (!tree->object.parsed) {
if (parse_tree_buffer(tree, buffer, size))
return NULL;
eaten = 1;
*eaten_p = 1;
}
}
} else if (type == OBJ_COMMIT) {
Expand All @@ -164,7 +164,7 @@ struct object *parse_object_buffer(const unsigned char *sha1, enum object_type t
return NULL;
if (!commit->buffer) {
commit->buffer = buffer;
eaten = 1;
*eaten_p = 1;
}
obj = &commit->object;
}
Expand All @@ -181,7 +181,6 @@ struct object *parse_object_buffer(const unsigned char *sha1, enum object_type t
}
if (obj && obj->type == OBJ_NONE)
obj->type = type;
*eaten_p = eaten;
return obj;
}

Expand Down

0 comments on commit 8e92e8f

Please sign in to comment.