@leroysheep / LeeRoySheep / commits / 83e717ee38

shallow: fix NULL dereference

After `write_one_shallow()` calls `lookup_commit()` to find the commit object for a shallow graft entry, it then checks `if (!c || ...)`. Inside that block, when the VERBOSE flag is set, it prints the OID being removed, via `c->object.oid`. But `c` can be NULL (the first condition in the `||` check). This happens when a shallow graft entry references a commit object that is not in the object store (e.g., after a partial fetch or in a corrupted repository). In that case, `lookup_commit()` returns NULL because the object cannot be found, the SEEN_ONLY check correctly decides to remove this entry from .git/shallow, but the verbose message crashes before the removal can complete. Use `graft->oid` instead of `c->object.oid` for the message. The graft entry's OID is the same value (it was used as the lookup key) and is always available regardless of whether the commit object exists. Pointed out by Coverity. Assisted-by: Claude Opus 4.6 Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Johannes Schindelin committed Jul 10, 2026 at 11:39 UTC 83e717ee38e5c0ba43cc55762012a0c5da2a84f6
1 file changed +1 -2
shallow.c
+1 -2
index 07cae44ae5..2f96db5170 100644 --- a/shallow.c +++ b/shallow.c @@ -370,8 +370,7 @@ static int write_one_shallow(const struct commit_graft *graft, void *cb_data) struct commit *c = lookup_commit(the_repository, &graft->oid); if (!c || !(c->object.flags & SEEN)) { if (data->flags & VERBOSE) - printf("Removing %s from .git/shallow\n", - oid_to_hex(&c->object.oid)); + printf("Removing %s from .git/shallow\n", hex); return 0; } }