builtin/help: fix dangling reference to `html_path`

In `get_html_page_path()` we may end up assigning the return value of `system_path()` to the global `html_path` variable. But as we also assign the returned value to `to_free`, we will deallocate its memory upon returning from the function. Consequently, `html_path` will now point to deallocated memory. Fix this issue by instead assigning the value to a separate local variable. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Sep 26, 2024 at 13:46 UTC 02e36f9ffaf1f2395a19dc10c15423883c7b2817
1 file changed +7 -6
builtin/help.c
+7 -6
@@ -513,23 +513,24 @@ static void show_info_page(const char *page)
513 static void get_html_page_path(struct strbuf *page_path, const char *page)
514 {
515 struct stat st;
516 + const char *path = html_path;
517 char *to_free = NULL;
518
518 - if (!html_path)
519 - html_path = to_free = system_path(GIT_HTML_PATH);
519 + if (!path)
520 + path = to_free = system_path(GIT_HTML_PATH);
521
522 /*
523 * Check that the page we're looking for exists.
524 */
524 - if (!strstr(html_path, "://")) {
525 - if (stat(mkpath("%s/%s.html", html_path, page), &st)
525 + if (!strstr(path, "://")) {
526 + if (stat(mkpath("%s/%s.html", path, page), &st)
527 || !S_ISREG(st.st_mode))
528 die("'%s/%s.html': documentation file not found.",
528 - html_path, page);
529 + path, page);
530 }
531
532 strbuf_init(page_path, 0);
532 - strbuf_addf(page_path, "%s/%s.html", html_path, page);
533 + strbuf_addf(page_path, "%s/%s.html", path, page);
534 free(to_free);
535 }
536