builtin/ls-remote: fix leaking `pattern` strings

Users can pass patterns to git-ls-remote(1), which allows them to filter the list of printed references. We assemble those patterns into an array and prefix them with "*/", but never free either the array nor the allocated strings. Refactor the code to use a `struct strvec` instead of manually tracking the strings in an array. Like this, we can easily use `strvec_clear()` to release both the vector and the contained string for us, plugging the leak. Helped-by: Taylor Blau <me@ttaylorr.com> Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Aug 1, 2024 at 12:40 UTC 4119fc08e2ed5611c21de9162b3ab61ef0014ada
2 files changed +11 -14
builtin/ls-remote.c
+10 -14
@@ -19,17 +19,16 @@ static const char * const ls_remote_usage[] = {
19 * Is there one among the list of patterns that match the tail part
20 * of the path?
21 */
22 -static int tail_match(const char **pattern, const char *path)
22 +static int tail_match(const struct strvec *pattern, const char *path)
23 {
24 - const char *p;
24 char *pathbuf;
25
27 - if (!pattern)
26 + if (!pattern->nr)
27 return 1; /* no restriction */
28
29 pathbuf = xstrfmt("/%s", path);
31 - while ((p = *(pattern++)) != NULL) {
32 - if (!wildmatch(p, pathbuf, 0)) {
30 + for (size_t i = 0; i < pattern->nr; i++) {
31 + if (!wildmatch(pattern->v[i], pathbuf, 0)) {
32 free(pathbuf);
33 return 1;
34 }
@@ -47,7 +46,7 @@ int cmd_ls_remote(int argc, const char **argv, const char *prefix)
46 int status = 0;
47 int show_symref_target = 0;
48 const char *uploadpack = NULL;
50 - const char **pattern = NULL;
49 + struct strvec pattern = STRVEC_INIT;
50 struct transport_ls_refs_options transport_options =
51 TRANSPORT_LS_REFS_OPTIONS_INIT;
52 int i;
@@ -93,13 +92,8 @@ int cmd_ls_remote(int argc, const char **argv, const char *prefix)
92
93 packet_trace_identity("ls-remote");
94
96 - if (argc > 1) {
97 - int i;
98 - CALLOC_ARRAY(pattern, argc);
99 - for (i = 1; i < argc; i++) {
100 - pattern[i - 1] = xstrfmt("*/%s", argv[i]);
101 - }
102 - }
95 + for (int i = 1; i < argc; i++)
96 + strvec_pushf(&pattern, "*/%s", argv[i]);
97
98 if (flags & REF_TAGS)
99 strvec_push(&transport_options.ref_prefixes, "refs/tags/");
@@ -136,7 +130,7 @@ int cmd_ls_remote(int argc, const char **argv, const char *prefix)
130 struct ref_array_item *item;
131 if (!check_ref_type(ref, flags))
132 continue;
139 - if (!tail_match(pattern, ref->name))
133 + if (!tail_match(&pattern, ref->name))
134 continue;
135 item = ref_array_push(&ref_array, ref->name, &ref->old_oid);
136 item->symref = xstrdup_or_null(ref->symref);
@@ -158,5 +152,7 @@ int cmd_ls_remote(int argc, const char **argv, const char *prefix)
152 if (transport_disconnect(transport))
153 status = 1;
154 transport_ls_refs_options_release(&transport_options);
155 +
156 + strvec_clear(&pattern);
157 return status;
158 }
t/t5535-fetch-push-symref.sh
+1
@@ -2,6 +2,7 @@
2
3 test_description='avoiding conflicting update through symref aliasing'
4
5 +TEST_PASSES_SANITIZE_LEAK=true
6 . ./test-lib.sh
7
8 test_expect_success 'setup' '