transport: fix leak with transport helper URLs

Transport URLs can be prefixed with "foo::", which would tell us that the transport uses a remote helper called "foo". We extract the helper name by `xstrndup()`ing the prefix before the double-colons, but never free that string. Fix this leak by assigning the result to a separate local variable that we can then free upon returning. Helped-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Junio C Hamano committed Aug 7, 2024 at 17:32 UTC 448d51d549179bafe47e07e9434210d48fdf55c6
1 file changed +3 -1
transport.c
+3 -1
@@ -1115,6 +1115,7 @@ static struct transport_vtable builtin_smart_vtable = {
1115 struct transport *transport_get(struct remote *remote, const char *url)
1116 {
1117 const char *helper;
1118 + char *helper_to_free = NULL;
1119 const char *p;
1120 struct transport *ret = xcalloc(1, sizeof(*ret));
1121
@@ -1139,10 +1140,11 @@ struct transport *transport_get(struct remote *remote, const char *url)
1140 while (is_urlschemechar(p == url, *p))
1141 p++;
1142 if (starts_with(p, "::"))
1142 - helper = xstrndup(url, p - url);
1143 + helper = helper_to_free = xstrndup(url, p - url);
1144
1145 if (helper) {
1146 transport_helper_init(ret, helper);
1147 + free(helper_to_free);
1148 } else if (starts_with(url, "rsync:")) {
1149 die(_("git-over-rsync is no longer supported"));
1150 } else if (url_is_local_not_ssh(url) && is_file(url) && is_bundle(url, 1)) {