sha1_name: fix uninitialized memory errors

During abbreviation checks, we navigate to the position within a pack-index that an OID would be inserted and check surrounding OIDs for the maximum matching prefix. This position may be beyond the last position, because the given OID is lexicographically larger than every OID in the pack. Then nth_packed_object_oid() does not initialize "oid". Use the return value of nth_packed_object_oid() to prevent these errors. Also the comment about checking near-by objects miscounts the neighbours. If we have a hit at "first", we check "first-1" and "first+1" to make sure we have sufficiently long abbreviation not to match either. If we do not have a hit, "first" is the smallest among the objects that are larger than what we want to name, so we check that and "first-1" to make sure we have sufficiently long abbreviation not to match either. In either case, we only check up to two near-by objects. Reported-by: Christian Couder <christian.couder@gmail.com> Signed-off-by: Derrick Stolee <dstolee@microsoft.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Derrick Stolee committed Feb 27, 2018 at 06:47 UTC 21abed500cb06bc54247cbc11def92739259bb70
1 file changed +7 -7
sha1_name.c
+7 -7
@@ -542,20 +542,20 @@ static void find_abbrev_len_for_pack(struct packed_git *p,
542 /*
543 * first is now the position in the packfile where we would insert
544 * mad->hash if it does not exist (or the position of mad->hash if
545 - * it does exist). Hence, we consider a maximum of three objects
545 + * it does exist). Hence, we consider a maximum of two objects
546 * nearby for the abbreviation length.
547 */
548 mad->init_len = 0;
549 if (!match) {
550 - nth_packed_object_oid(&oid, p, first);
551 - extend_abbrev_len(&oid, mad);
550 + if (nth_packed_object_oid(&oid, p, first))
551 + extend_abbrev_len(&oid, mad);
552 } else if (first < num - 1) {
553 - nth_packed_object_oid(&oid, p, first + 1);
554 - extend_abbrev_len(&oid, mad);
553 + if (nth_packed_object_oid(&oid, p, first + 1))
554 + extend_abbrev_len(&oid, mad);
555 }
556 if (first > 0) {
557 - nth_packed_object_oid(&oid, p, first - 1);
558 - extend_abbrev_len(&oid, mad);
557 + if (nth_packed_object_oid(&oid, p, first - 1))
558 + extend_abbrev_len(&oid, mad);
559 }
560 mad->init_len = mad->cur_len;
561 }