diff-lib: add idx/tree sanity check to oneway_diff
When looking just at the code in oneway_diff(), it seems possible for both "idx" and "tree" to be NULL, in which case we'd potentially segfault while checking the relative prefix. But if you consider what these items actually mean, it shouldn't be possible for both to be NULL. Let's add an assertion and a comment documenting this. It might help human readers, but should also silence static analyzers like Coverity which complain about the potential segfault. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Jul 28, 2026 at 11:14 UTC
447126ed7df66b396235766547a57649f925aac2
1 file changed
+10
diff-lib.c
+10
@@ -530,6 +530,16 @@ static int oneway_diff(const struct cache_entry * const *src,
530
if (tree == o->df_conflict_entry)
531
tree = NULL;
532
533
+ /*
534
+ * We should only see a NULL idx when the entry was present in the tree
535
+ * but deleted in the idx. In which case it should be impossible
536
+ * that a NULL tree was passed in (there would have been no entry at
537
+ * all) or that we got a df conflict above (you need a directory and a
538
+ * file to get such a conflict, which implies both sides are present).
539
+ */
540
+ if (!idx && !tree)
541
+ BUG("oneway_diff with neither idx nor tree");
542
+
543
if (ce_path_match(revs->diffopt.repo->index,
544
idx ? idx : tree,
545
&revs->prune_data, NULL)) {