]> gitweb.ps.run Git - ps-cgit/commitdiff
shared: fix bad free in cgit_diff_tree
authorJune McEnroe <june@causal.agency>
Tue, 17 May 2022 21:50:53 +0000 (21:50 +0000)
committerJason A. Donenfeld <Jason@zx2c4.com>
Mon, 19 Dec 2022 14:09:34 +0000 (15:09 +0100)
Since git commit 244c27242f44e6b88e3a381c90bde08d134c274b,

> diff.[ch]: have diff_free() call clear_pathspec(opts.pathspec)

calling diff_flush calls free(3) on opts.pathspec.items, so it can't
be a pointer to a stack variable.

Signed-off-by: Christian Hesse <mail@eworm.de>
shared.c

index 8115469a7cec4280e6bf4ccccf73563a5807568d..0bceb98912280ac50f8f58dc9219e006e165e280 100644 (file)
--- a/shared.c
+++ b/shared.c
@@ -341,9 +341,8 @@ void cgit_diff_tree(const struct object_id *old_oid,
                    filepair_fn fn, const char *prefix, int ignorews)
 {
        struct diff_options opt;
-       struct pathspec_item item;
+       struct pathspec_item *item;
 
-       memset(&item, 0, sizeof(item));
        diff_setup(&opt);
        opt.output_format = DIFF_FORMAT_CALLBACK;
        opt.detect_rename = 1;
@@ -354,10 +353,11 @@ void cgit_diff_tree(const struct object_id *old_oid,
        opt.format_callback = cgit_diff_tree_cb;
        opt.format_callback_data = fn;
        if (prefix) {
-               item.match = xstrdup(prefix);
-               item.len = strlen(prefix);
+               item = xcalloc(1, sizeof(*item));
+               item->match = xstrdup(prefix);
+               item->len = strlen(prefix);
                opt.pathspec.nr = 1;
-               opt.pathspec.items = &item;
+               opt.pathspec.items = item;
        }
        diff_setup_done(&opt);
 
@@ -367,8 +367,6 @@ void cgit_diff_tree(const struct object_id *old_oid,
                diff_root_tree_oid(new_oid, "", &opt);
        diffcore_std(&opt);
        diff_flush(&opt);
-
-       free(item.match);
 }
 
 void cgit_diff_commit(struct commit *commit, filepair_fn fn, const char *prefix)