cache-tree: detect mismatching number of index entries

In t4058 we have some tests that exercise git-read-tree(1) when used with a tree that contains duplicate entries. While the expectation is that we fail, we ideally should fail gracefully without a segfault. But that is not the case: we never check that the number of entries in the cache-tree is less than or equal to the number of entries in the index. This can lead to an out-of-bounds read as we unconditionally access `istate->cache[idx]`, where `idx` is controlled by the number of cache-tree entries and the current position therein. The result is a segfault. Fix this segfault by adding a sanity check for the number of index entries before dereferencing them. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Oct 7, 2024 at 06:38 UTC 2be7fc012e6747160b4b6586a1ec209598581ade
2 files changed +11 -6
cache-tree.c
+5
@@ -933,6 +933,11 @@ static int verify_one(struct repository *r,
933 pos = 0;
934 }
935
936 + if (it->entry_count + pos > istate->cache_nr) {
937 + ret = error(_("corrupted cache-tree has entries not present in index"));
938 + goto out;
939 + }
940 +
941 i = 0;
942 while (i < it->entry_count) {
943 struct cache_entry *ce = istate->cache[pos + i];
t/t4058-diff-duplicates.sh
+6 -6
@@ -132,15 +132,15 @@ test_expect_success 'create a few commits' '
132 rm commit_id up final
133 '
134
135 -test_expect_failure 'git read-tree does not segfault' '
136 - test_when_finished rm .git/index.lock &&
137 - test_might_fail git read-tree --reset base
135 +test_expect_success 'git read-tree does not segfault' '
136 + test_must_fail git read-tree --reset base 2>err &&
137 + test_grep "error: corrupted cache-tree has entries not present in index" err
138 '
139
140 -test_expect_failure 'reset --hard does not segfault' '
141 - test_when_finished rm .git/index.lock &&
140 +test_expect_success 'reset --hard does not segfault' '
141 git checkout base &&
143 - test_might_fail git reset --hard
142 + test_must_fail git reset --hard 2>err &&
143 + test_grep "error: corrupted cache-tree has entries not present in index" err
144 '
145
146 test_expect_failure 'git diff HEAD does not segfault' '